Security
The controls, encryption, and infrastructure that protect student data inside Evident. Looking for compliance frameworks or request-able review documents? See the Compliance Center.
We use Row-Level Security (RLS) on every database table. This ensures that a teacher can never access data belonging to another classroom, enforced at the database engine level.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. We do not store sensitive PII like Social Security Numbers or dates of birth.
Every critical action (creating charts, modifying students, or viewing logs) is recorded in an immutable audit log accessible to school administrators.
Our platform supports deletion requests, data access controls, and documentation workflows used in FERPA and GDPR programs. We provide Data Processing Agreements (DPAs) for schools and districts.
Security Controls
Evident uses a defense-in-depth approach: several independent layers protect student data so that no single failure exposes it. The controls below apply automatically to every account and are designed around FERPA requirements and GDPR-aligned practices.
Encryption
Student data is encrypted at rest using AES-256 and in transit using TLS 1.3. We also minimize what we hold: Evident does not store sensitive PII such as Social Security Numbers or dates of birth.
Tenant Isolation
Row-Level Security (RLS) is applied on every database table, so isolation is enforced by the database engine itself. A teacher cannot read data from another classroom even if application code is bypassed, because the rule lives in the database rather than in the app.
Audit Logging
Critical actions, such as creating charts, modifying students, or viewing logs, are recorded in an immutable audit log that school administrators can access. Audit entries are retained for the life of the account so the record stays available for review and export, and they are removed with the account under the disposition timeline described in our Privacy Policy.
Testing
Evident undergoes annual penetration testing. An automated test suite also runs on every deployment, so access controls and data isolation are exercised continuously rather than only at release time.
Availability
Evident runs on high-availability cloud infrastructure and targets 99.9% availability. Uptime is tracked with automated external monitoring against a public health check. We do not offer a contractual uptime SLA at this time.
FERPA & GDPR Workflows
Evident supports the deletion requests, data access controls, and documentation workflows used in FERPA and GDPR programs, and provides Data Processing Agreements (DPAs) for schools and districts.
Breach Notification
In the event of a confirmed data breach involving Student Data, Evident will notify your district within 72 hours of confirmation, aligned to common DPA timelines. The full notification commitment, including what each notice contains, is described in the Compliance Center.
Infrastructure & Sub-processors
Evident runs on established cloud providers. Each sub-processor below handles a specific function, and this same list is documented in our DPA for district review.
- Vercel (Hosting)
- Supabase (Database)
- Stripe (Billing)
- OpenAI (AI Translation)
- Resend (Email)
- Sentry (Monitoring)
- Upstash (Rate Limiting)
Evident and its sub-processors operate in the United States. Student data is stored and processed in US-based infrastructure.
Our database provider, Supabase, maintains its own independent third-party security certification as a sub-processor. Evident's own security program is structured to align with the SOC 2 Trust Services Criteria; this is Evident's own assessment, not a third-party SOC 2 certification of Evident. For framework details and assessment materials, see the Compliance Center.
School Review Documentation
Reviewing Evident for a pilot or license? Start with the procurement packet, then use the Compliance Center and DPA for deeper privacy and IT review.
The Compliance Center is where you can request the security assessment, incident response summary, and other review documents.
Contact the Security Team
For security questions, to report a vulnerability, or to request a security review, reach out to our security team.