---
title: Procurement FAQ
category: procurement
order: 9
lastUpdated: 2026-06-08
featureAvailability: GA
roles: [district-admin, admin]
relatedArticles: [procurement/ferpa-overview, procurement/security-overview, procurement/identity-sso, procurement/data-ownership-exports, procurement/data-retention-deletion, procurement/subprocessors, procurement/ai-student-data]
---

## At a glance

- **Who uses it:** Procurement, legal, IT security, and DPO reviewers.
- **Purpose:** Fast answers to the most common procurement questions in one page, with links to the detailed articles.

## Compliance & data

**Is AmplifyED FERPA-conscious?**
Yes — see [FERPA overview](/help/procurement/ferpa-overview). The school remains the data controller; AmplifyED is the processor.

**Where is data hosted?**
Production data is hosted in the United States. No student data is transferred outside the US.

**Will you sign a Data Privacy Agreement (DPA / NDPA)?**
Yes. Email security@amplifyed.app for the current signed templates.

**Who are your subprocessors?**
See [Subprocessors](/help/procurement/subprocessors). 30-day advance notice on changes.

**Do you support customer-managed encryption keys (BYOK)?**
Not today. All keys are managed by AmplifyED's KMS.

## Authentication & access

**Do you support SSO?**
Yes — Google Workspace, Microsoft Entra ID, Okta, OneLogin, ADFS, and generic SAML 2.0. See [Identity & SSO](/help/procurement/identity-sso).

**Do you support SCIM provisioning?**
SCIM 2.0 is on the roadmap. Today: JIT provisioning on verified domains plus direct admin deactivation.

**Do you support MFA?**
MFA is enforced by your IdP for SSO sign-ins. Native MFA for email + password is on the roadmap.

**How are sessions secured?**
HTTP-only cookies, tokens rotate on sign-in, configurable session length, idle timeout, account lockout after 3 failed sign-ins.

## Security & audit

**Do you have an audit log?**
Yes — every sensitive action is recorded with actor, timestamp, IP, user agent. Retained 7 years. See [Audit logging](/help/procurement/audit-logging).

**Do you have SOC 2?**
SOC 2 Type II is in progress; status available under NDA.

**Where do I report a vulnerability?**
security@amplifyed.app — see [Vulnerability reporting](/help/security/vulnerability-reporting).

**Do you have an incident response process with notification SLAs?**
Yes — 24-hour customer notification for incidents affecting customer data. See [Incident response](/help/security/incident-response).

## AI

**Do you use AI? With student data?**
AI features are opt-in. When opted in, case text is sent to a managed AI gateway (US region, Google Gemini 3 Flash Preview). No customer data is used to train the underlying model. Every AI output is a draft until a human accepts it. See [AI & student data](/help/procurement/ai-student-data).

## Data ownership & exit

**Do we own our data?**
Yes. See [Data ownership & exports](/help/procurement/data-ownership-exports).

**Can we export everything if we leave?**
Yes — a bulk export package is delivered during the grace period of the contract. Retention deletion follows your configured policy or the termination addendum, whichever is shorter. See [Data retention & deletion](/help/procurement/data-retention-deletion).

## Pricing & contracting

**How is pricing structured?**
Per-school subscription with optional add-ons for additional students-receiving-support, teacher portal seats, facilitator seats, and AI drafts. Annual plans include a multi-month discount. See [Billing & plans](/help/administration/billing).

**Do you accept purchase orders?**
Yes, on annual plans. Contact billing@amplifyed.app.

## Related articles

- [FERPA overview](/help/procurement/ferpa-overview)
- [Security overview](/help/procurement/security-overview)
- [Identity & SSO](/help/procurement/identity-sso)
- [Audit logging](/help/procurement/audit-logging)
- [Data ownership & exports](/help/procurement/data-ownership-exports)
- [Data retention & deletion](/help/procurement/data-retention-deletion)
- [Subprocessors](/help/procurement/subprocessors)
- [AI & student data](/help/procurement/ai-student-data)
