Security & Data Practices
For district IT directors, privacy officers, and procurement teams. Last updated: September 13, 2026. For the consolidated review package, see the Trust Center.
| Control | Status |
|---|---|
| NDPA-based DPA and FERPA school-official terms | Available now |
| Server-enforced role-based access | Available now |
| Audit log of sensitive actions | Available now |
| Encryption in transit (TLS 1.2+) and at rest | Available now |
| Sign in with Google (Workspace MFA applies) | Available now |
| Security questionnaire responses, VPAT / ACR | On request |
| SAML, Clever, and ClassLink single sign-on | Roadmap — not available today |
| SIS rostering integration | Roadmap — not available today |
| SOC 2 Type II report | Not held today |
Data minimization
Student records use initials, not names. Educators enter initials (e.g., J.M.), grade level, IEP goals, services, accommodations, and class schedules. Casemate does not store student full names, Social Security numbers, or home addresses. Birth month is an optional field used only to calculate secondary-transition timelines; full birth dates are not collected.
Uploaded documents are de-identified. When an IEP or assessment PDF is uploaded, names, SSNs, dates of birth, phone numbers, emails, and addresses are stripped before extraction results are stored, and names are reduced to initials.
Identity and access control
Staff sign in with Google or with email and password through Firebase Authentication. When staff use your district's Google Workspace accounts, your existing multi-factor authentication and account offboarding policies apply. Students never receive accounts.
Authorization is enforced on the server, not in the browser:
- Teachers and providers access their own caseloads and assigned services.
- Principals access their own school.
- District administrators access their district. District gap queues are organized by school and omit teacher identities.
- There is no access across unrelated schools or districts.
Leadership features are also gated by the district's licensed package on the server, so a changed browser request cannot unlock them.
Audit logging
Casemate writes a server-side audit record for student-record creation, changes, deletion, and transfer; delivery-evidence exports; student audit-folder views; gap status changes; and access to leadership reports, forecasts, and analyst answers. Audit records cannot be written or altered from the browser. Districts can request audit records for their organization under the DPA.
Encryption and application hardening
- HTTPS everywhere with TLS 1.2+ and HTTP Strict Transport Security.
- Application data encrypted at rest by Google Cloud.
- A restrictive Content Security Policy, clickjacking protection (frame-ancestors none), content-type sniffing protection, and a limited browser permissions policy.
- Firebase App Check enforced on every callable Cloud Function.
- Rate limits on public share-link endpoints and sensitive actions.
- Provider credentials held in Google Secret Manager and never shipped to the browser.
Artificial intelligence
AI features run by default through Google Vertex AI under the Google Cloud Data Processing Addendum: customer content is not used to train models, is processed in a configured region, and is authenticated by our service account with no API key transmitted. Prompts are built from de-identified data and pass an additional PII-scrubbing step. AI output is a draft for a qualified educator to review; Casemate does not make eligibility, placement, or legal determinations.
Infrastructure and subprocessors
- Google Cloud — Firebase Authentication, Firestore, Cloud Functions, Cloud Storage, Vertex AI, Document AI, Secret Manager
- Netlify — web application hosting and CDN
- Stripe — billing (no student data)
- Resend — transactional email (staff addresses only)
Data is not stored on local servers or personal devices. Subprocessor changes are notified under the terms of your DPA.
Retention, return, and deletion
Account deletion requests are completed within 30 days of a valid request, except where retention is required by law. When a school or district agreement ends, student data is returned or deleted as that agreement specifies. Educator-created share links can expire and be closed at any time.
Incidents and breach notification
Security incidents involving district data are handled under the breach-notification terms of your signed DPA, including notice to the district so it can meet its own obligations to families and regulators. Report a suspected vulnerability or incident to privacy@iepcasemate.com.
FERPA and student-privacy agreements
Under a signed agreement, Casemate operates as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)). We use student data only to provide the contracted service under the district's direction, do not re-disclose it, and never sell it or use it for advertising. We sign the SDPC National Data Privacy Agreement and state exhibits. Review the DPA.
Certifications
Casemate does not currently hold a SOC 2 report or other third-party security certification, and we do not display badges we have not earned. We complete district security questionnaires and will walk your team through any control on this page.
See also the student data handling flowchart, Trust Center, Privacy Policy, Accessibility Statement, and Terms of Service.