Compliance
Documentation your district's legal, privacy, and IT teams can use to evaluate Evident for a pilot or school license: DPA/NDPA information, security assessment materials, an incident response summary, and procurement packet links. For the underlying controls, encryption, and infrastructure, see our Security page.
Student privacy documentation
Family Educational Rights & Privacy Act
Children's Online Privacy Protection Act
Cybersecurity review structure
Compliance Frameworks
Evident's school privacy review is structured around the frameworks district legal, privacy, and IT teams expect to see during procurement:
- DPA/NDPA: Student privacy documentation
- FERPA: Family Educational Rights & Privacy Act
- COPPA: Children's Online Privacy Protection Act
- NIST-informed: Cybersecurity review structure
Documentation your district's legal, privacy, and IT teams can use to evaluate Evident for a pilot or school license.
Compliance Documents
These documents are available upon request for any school district evaluating or currently using Evident.
School Procurement Packet
Self-Serve School Review. A single packet covering security overview, privacy summary, DPA/NDPA information, subprocessors, retention/deletion, accessibility readiness, implementation FAQ, rostering options, and support contacts.
- Designed for privacy, IT, and school leadership review
- Links to DPA, security, accessibility, and school plan surfaces
- Cautious claims language for early procurement conversations
Annual Security & Privacy Assessment
SOC 2 Trust Services Criteria structure. An annual assessment of Evident's security controls, infrastructure, identity management, vulnerability management, and EdTech-specific privacy workflows (FERPA/COPPA). Includes our full subprocessor inventory, data classification matrix, and encryption standards. This assessment is structured to align with the SOC 2 Trust Services Criteria; it is Evident's own assessment and is not a third-party SOC 2 certification of Evident.
- SOC 2 TSC-aligned structure
- Full infrastructure & subprocessor inventory
- Vulnerability scanning & testing results
- FERPA/COPPA-related audit logging evidence
- Data retention & disposal documentation
Management's Assertion Letter
CEO-signed security & privacy attestation. Formal attestation from Evident's CEO summarizing security and privacy controls. Covers authorized use, security safeguards, regulatory documentation, data sovereignty, data minimization, and disposal protocols.
- CEO-signed on company letterhead
- Summarizes DPA/NDPA-aligned controls
- Attached as cover to the Security Assessment
- NIST-informed cybersecurity framework mapping
Incident Response Plan Summary
NIST-informed incident response process. Summary of Evident's written data breach response plan, provided for school privacy review. Covers our incident classification matrix, NIST-informed response process, 72-hour notification target, and post-incident review procedures.
- NIST-informed response structure
- 4-phase response process documented
- 72-hour LEA notification target
- Post-incident review & remediation process
- Annual tabletop exercise commitment
Data Processing Agreement (DPA)
DPA/NDPA documentation for school districts. Evident provides DPA/NDPA documentation for school privacy review, based on common student data privacy agreement structures. Review DPA information or contact us to discuss district-specific terms.
- DPA/NDPA documentation available for review
- Data elements documented
- Subprocessor list with all 7 vendors
- Data disposition workflow documented
- District-specific terms can be discussed
Security at a Glance
Key security metrics and controls that protect your student data.
- 520+ (Integration Tests): Run on every deployment
- AES-256 (Encryption at Rest): All student data
- TLS 1.3 (Encryption in Transit): Every connection
- 72hr (Breach Notification Target): Aligned to common DPA timelines
- 60 day (Data Disposition): On DPA termination
- RLS (Tenant Isolation): Database-level enforcement
How to Request Compliance Documents
- 1. Contact Us: Email us at your convenience or use the contact form. Include your district name, your role, and which documents you need.
- 2. Verification: We verify your identity as an authorized representative of the school district. For existing DPA partners, we respond within 2 business days.
- 3. Document Delivery: Documents are delivered via secure email. DPA/NDPA information and request paths are available on the DPA page. Assessment reports and the IRP Summary are provided within 5 business days.
Our 72-Hour Notification Commitment
In the event of a confirmed data breach involving Student Data, Evident will notify your district within 72 hours of confirmation, aligned to common DPA timelines.
Our notification includes:
- Provider identification and direct contact information
- Incident timeline with date of breach and date of discovery
- Plain-language description of what happened
- Specific Student Data elements affected (referencing Exhibit B)
- Identification of impacted individuals
- Corrective actions taken and ongoing remediation steps
Ready to Partner with Evident?
Start with the procurement packet, review DPA/NDPA documentation and security materials, then contact us for school-specific review needs.