Security

Security at AmplifyED.

Schools trust AmplifyED with sensitive student information. Here's what we do to keep it safe.

Security commitments

AmplifyED maintains administrative, technical, and organizational safeguards designed to protect Customer Data and support school privacy obligations. No system can guarantee absolute security; AmplifyED employs commercially reasonable safeguards but does not guarantee that unauthorized access, cyberattacks, or other security incidents will never occur.

Controls in place today

Encryption in transit & at rest

TLS 1.2+ for all traffic. AES-256 at rest in our managed Postgres database.

Role-based access

Access to student records is governed by role, organization, and authorized student relationships. Users may only access information permitted by their assigned permissions.

Comprehensive audit log

Views, edits, exports, role changes, AI generations, and purges are logged with actor, timestamp, and IP.

Re-authentication for sensitive actions

Exports, deletions, and role changes require fresh password entry even within an active session.

Automatic idle sign-out

Staff sessions expire after 30 minutes of inactivity, with a warning 60 seconds before sign-out.

Tenant isolation

Row-level security policies are designed to enforce organization scoping on every read and write so users only see data from their own organization.

AI privacy guardrails

By default, identifying student information is removed or minimized before content is processed by AI services. Student data is never used to train public AI models, and our subprocessors are contractually prohibited from doing so.

Vetted subprocessors

We use a short, vetted list of subprocessors (hosting, email, payments, AI gateway). Full list available on request.

Incident response

Upon confirmation of unauthorized access to Customer Data, AmplifyED will investigate, contain, remediate, and notify affected Customer administrators without unreasonable delay, consistent with contractual obligations and applicable law. Schools remain responsible for downstream notifications to parents and regulators under their own policies.

Report a vulnerability

Found a security issue? Please email security@amplifyed.app with reproduction steps. We acknowledge reports within one business day and will keep you updated through remediation. We do not pursue legal action against good-faith researchers who follow coordinated disclosure.

See also: FERPA & Student Privacy · Privacy Policy · Data Retention