District procurement
Trust Center
A verifiable account of how IEP Casemate handles student data, secures access, governs AI, and supports school and district review. Last updated: September 13, 2026.
Control summary
Student data
Initials and minimized caseload fields; no full names, SSNs, full birth dates, or home addresses. Birth month is optional, for transition timelines only.
Access
Authenticated educator accounts with server-enforced teacher, school, and district scopes. No cross-district access.
Student experiences
Educator-created links are limited to the assigned experience and may expire or be closed. Students do not receive accounts.
AI
Google Vertex AI by default, in a configured region. Google does not use customer data to train or fine-tune models without permission.
Encryption
TLS 1.2+ in transit; application data encrypted at rest by Google Cloud.
Contract controls
NDPA-based DPA, purpose limits, subprocessor terms, breach terms, and return or deletion requirements.
Data minimization
Casemate is built to hold as little student data as possible. Teachers enter initials, grade level, IEP goals, services, and schedules. When IEP or assessment PDFs are uploaded, personally identifiable information is stripped before results are stored — names are reduced to initials, and SSNs, dates of birth, phone numbers, emails, and addresses are removed.
FERPA & state student-data-privacy laws
When a school or district uses Casemate, we operate as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)): we use student data only to provide the contracted service under the agency's direction, we do not re-disclose it, and we do not use it for our own purposes. We sign Data Privacy Agreements, including the SDPC National Data Privacy Agreement (NDPA) and state-specific exhibits (e.g., NY Education Law § 2-d, Illinois SOPPA, California). Contact us for an executed agreement.
Contracted educational use and COPPA
In a contracted school or district deployment, student-facing experiences are provided only for a school-authorized educational purpose and not for advertising, profiling, or another independent commercial purpose. The school or district receives notice of the data involved and can request access, correction, return, or deletion under the agreement. Educators should launch experiences for children under 13 only when their school or district has authorized the use.
AI data governance
Generative AI is used for document extraction, present levels and progress drafts, practice generation, and AI tutor sessions. The default path runs through Google Vertex AI on Google Cloud:
- Covered by the Google Cloud Data Processing Addendum — content is not used to train Google's models.
- Processed within a configured Google Cloud region.
- Authenticated by our service account — no API key is transmitted on the default path.
- Prompts are built from de-identified data and pass an additional PII-scrubbing step before being sent.
- For AI tutor sessions, prompts may include the selected goal, recent progress, relevant assessment summaries, and prior tutor lesson history for that goal — still without full student names.
- Educator-facing AI output is a draft; a qualified educator reviews and finalizes AI-assisted IEP documentation. Tutor sessions are instructional tools under educator direction, with prompt-level topic constraints; they are not a guarantee against all model errors.
A district or organization may optionally use its own AI key (BYOK), in which case those requests use that customer's own provider relationship.
Share links (practice, AI tutor, and related)
Case managers create unique, unguessable links for limited experiences such as interactive practice and AI tutor sessions. Students do not create accounts. Possession of a valid, non-expired link grants access to that experience only. Links may expire automatically; authorized users can close sessions. Public link endpoints are rate-limited. Practice answer keys stay server-side and are omitted from student-facing responses.
Treat active links like session credentials. Schools decide how links are distributed under their own policies.
Access control
Access to educator accounts follows your organization's structure and is enforced server-side: teachers see their own caseload; same-school teachers may share caseloads where enabled; principals see their school; district administrators see their district. There is no access across unrelated schools or districts. Share-link recipients see only the linked experience, not the educator account.
Application security baseline
Casemate uses Firebase Authentication, server-enforced Firestore authorization rules, and App Check on protected Cloud Functions. Public link endpoints are rate-limited. The web application sends a restrictive Content Security Policy, HTTP Strict Transport Security, clickjacking protection, content-type protections, and a limited browser permissions policy. Sensitive provider credentials are kept in managed secrets and are not shipped to the browser.
Audit logging
A server-side audit record is written for student-record changes, deletions, and transfers; delivery-evidence exports; student audit-folder views; gap status changes; and access to leadership reports, forecasts, and analyst answers. Audit records cannot be written or altered from the browser.
Sign-in, SSO, and certifications
Staff sign in with Google or email and password. With district Google Workspace accounts, your MFA and offboarding policies apply. SAML, Clever, and ClassLink single sign-on are on the roadmap and not available today. Casemate does not currently hold a SOC 2 report; we complete security questionnaires for district review.
Subprocessors
- Google Cloud — Firebase Authentication, Firestore, Cloud Functions, Vertex AI, Document AI, Secret Manager
- Netlify — application hosting / CDN
- Stripe — payment processing
- Resend — transactional invitation email (staff addresses only)
Procurement review package
District teams can review these materials before a product call. We also respond to security questionnaires and district agreement terms.
Common questions
Do you sell or share student data?
No. We never sell student data and never share it for advertising or marketing.
Is our data used to train AI models?
The default Vertex AI path is covered by Google Cloud terms that prohibit using customer data to train or fine-tune AI models without permission or instruction. We do not train our own models on student data.
Do students create accounts?
No. Educators create share links for practice, AI tutor sessions, and certain other features. Anyone with a valid link can use that limited experience until it expires or is closed.
What does the AI tutor know about a student?
For the goal the educator selected: goal text/objectives, recent progress statements, relevant assessment summaries, prior tutor lesson history for that goal, grade level, and accommodations — after PII scrubbing. It is not an open general-purpose chatbot; sessions are scoped to that instructional target.
Will you sign our DPA?
Yes. We sign the SDPC NDPA and state exhibits, and can review a district's own agreement. Email privacy@iepcasemate.com.
Where is data stored and processed?
In Google Cloud, with AI processing pinned to a configured region. Encrypted in transit and at rest.
What happens to data when we stop using Casemate?
Student data is deleted or returned per your agreement; account data is deleted within 30 days of a valid request.
Contact
For DPAs, security questionnaires, or compliance inquiries: privacy@iepcasemate.com
See also our Privacy Policy, Security & Data Practices, and Terms of Service.