Key takeaways
- Settle who can see which students before any roster import.
- Ask whether the vendor will sign your data agreement, and read the subprocessor list.
- Ask exactly what student text is sent to AI services and whether names are removed first.
- Confirm export and permanent deletion work before you sign, not when you leave.
- Bring technology staff and a teacher to the review; the district still owns its obligations.
A compliance review for student-support software should cover ten areas: where data is stored, what agreement the vendor will sign, who can see which students, how family sharing works, what is sent to AI services, what is logged, how single sign-on and account removal work, which exports become records, how edge cases like transfers are handled, and how you get your data out. The table below lists the questions for each area and what a complete answer includes.
The questions, by area
| Area | Ask | A complete answer includes |
|---|---|---|
| Storage and encryption | Where is student data stored, and is it encrypted? | The hosting region, encryption in transit and at rest, and any option for data residency outside the US |
| Agreements | Will you sign our data privacy agreement or state addendum? Who are your subprocessors? | A yes or a redline, plus a current, named subprocessor list and how you will be notified of changes |
| Access and roles | What can a teacher, a case manager, a counselor, a school admin, and a district leader each see? | A role-by-role description, confirmation that teachers cannot browse students outside their caseload, and how confidential notes are restricted |
| Family sharing | How are family links created, scoped, revoked, and logged? What can a family see? | Per-student links, immediate revocation, a record of link activity, and which notes are excluded from family views |
| AI features | Which features send student text to an AI service, and what is removed first? | The feature list, the provider, whether names are removed before sending, human review before family delivery, and an org-wide off switch |
| Audit logging | What actions are logged, and who can see the log? | Logged reads and exports of sensitive records, changes to confidential notes, and how an admin retrieves the log |
| Accounts and SSO | Do you support single sign-on? How is access removed when staff leave? | Supported sign-in methods, provisioning options, and the steps and timing for removing a departed user |
| Records and exports | Which exports (PDF reports, packets, logs) would count as student records under our policy? | What each export contains, and acknowledgement that the district defines records and retention |
| Edge cases | What happens when a student transfers schools, a custody arrangement limits a parent's access, or a log entry was a mistake? | How records move or are archived, how a family link is scoped or revoked for one guardian, and whether corrections leave an audit trail |
| Exit | Can we export everything, and will you permanently delete it on request? | Export formats, retention after cancellation, and written confirmation of deletion |
Questions to settle before any roster import
Broad access is hard to walk back once a roster is loaded, so answer these first:
- Who creates student records, and from what source? A CSV from the student information system, a sync, or teacher entry.
- Who can see each student? Map every role you plan to use to the students it can see.
- Who can transfer or archive a student? And what the previous teacher can still see afterward.
- Who sees school and district rollups? And whether rollups show student-level detail or counts.
- Who owns family links? And who can revoke one if a guardian's access changes.
Who should be in the room
A technology or privacy lead should cover storage, access, single sign-on, and the security documentation. Someone who owns records policy should decide which exports become records and how long they are kept. And a teacher who will use the tool should be there, because a review that does not understand the daily workflow misses where data actually moves: a parent link shared at pickup, a PDF printed for a meeting, a note typed on a phone.
How Evident answers these questions
For teams reviewing Evident specifically, here is where each answer lives:
- Storage: US-hosted infrastructure, encrypted in transit and at rest. Schools that need EU residency can be onboarded to a dedicated EU deployment in Frankfurt.
- Agreements: a signed Data Processing Agreement is available. Evident does not claim a GDPR certification.
- Access: role-based access with row-level security. Teachers see their own students; admins see coverage rollups and per-teacher logging status. Counselor-confidential notes are masked at the database layer and excluded from family and MTSS packets.
- Family sharing: no-app family links per student, with link activity recorded.
- AI features: student names are removed before text is sent for translation and before AI progress narrative requests. Narratives are teacher-reviewed before export, and schools can turn narratives off org-wide.
- Audit logging: confidential note changes, confidential exports, and reads of colleagues' confidential narratives are audited.
- Exit: teachers can export, and permanent deletion is available.
The security overview, the help article on how Evident handles school data, and what administrators can see have the details. Single sign-on and provisioning are arranged at the school or district plan level; the SSO and account provisioning article covers that conversation. Schools remain responsible for their own FERPA and data-protection obligations.
Related planning
A compliance review usually runs alongside a pilot and a procurement decision. The district pilot plan puts the privacy review inside the pilot timeline, and the procurement and ROI checklist covers the purchasing paperwork a business office asks for.
Common questions
Is this checklist legal advice?
No. It is a planning list of questions. District policy, your privacy officer, and legal counsel make the final compliance decisions, and schools remain responsible for their own FERPA and data-protection obligations.
Who should be in a vendor compliance review?
A technology or privacy lead for storage, access, and single sign-on; someone who owns records policy; and at least one teacher who will use the tool, so the review reflects the real classroom workflow.
What is the minimum a vendor should clear?
A signed data agreement, encryption in transit and at rest, role-based access that keeps teachers within their own caseload, a named subprocessor list, audit logging, and working export and deletion. Judge the product on what it does above that floor.
What should we ask about AI features?
Which features send student text to an AI service, which provider, whether student names are removed before sending, whether output is reviewed by a person before it reaches a family, and whether the district can turn the features off.
What happens to our data if we stop using the product?
Ask before signing: can you export all records in a usable format, how long data is kept after cancellation, and whether permanent deletion is available on request with confirmation.