EssayGrader Trust Center
How we protect student work, teacher accounts, and institutional data — the controls we run, the documents we can share, and answers to the questions schools ask most.
Need something that isn’t here?
security@essaygrader.ai
Compliance
Frameworks we align to and documents we can share. Items under NDA are available on request through your account contact or security@essaygrader.ai.
NIST SP 800-53 Rev. 5
Our primary security and privacy controls baseline. Monitored continuously and reported by Aikido Security.
FERPA
We act as a school official under the direct control of the institution. All student work is treated as an educational record.
COPPA
No student accounts and no direct collection from children. Teachers control what is uploaded.
State privacy laws
CCPA, SOPPA, and comparable state statutes. Student data is never sold and never used for targeted advertising.
HECVAT 4.1.5
Full Higher Education Community Vendor Assessment Toolkit response covering organization, product, infrastructure, AI, and privacy.
SOC 2 Type 1
Audit program underway with internal audits and automated evidence collection already running. Our hosting provider holds SOC 2 Type II.
GDPR
We serve primarily US institutions and store data in the US. Standard Contractual Clauses are available, and EEA data subject rights are honored.
WCAG 2.1 Level AA
Accessibility Conformance Report completed May 2026. Known gaps are tracked with a published remediation roadmap.
NIST AI RMF 1.0
Our AI risk model follows the Map, Measure, Manage, and Govern functions. All staff complete responsible AI training.
Penetration test
Third-party assessment with no critical or high severity findings. Medium and low findings are tracked to closure.
HIPAA
EssayGrader does not process protected health information. Do not upload PHI to the platform.
PCI DSS
Card data never touches our systems. Payments are handled entirely by Stripe.
Infrastructure security
Continuously monitored controls across our cloud, network, and application stack. Findings are produced by Aikido Security in real time and mapped to NIST SP 800-53 controls.
AES-256 across databases, persistent volumes, and object storage.
TLS 1.2/1.3 for all client, service-to-service, and third-party traffic.
Unencrypted HTTP is rejected and redirected to HTTPS.
Legacy ciphers and protocol versions are disabled.
Cryptographic modules used for transit and secret storage are FIPS-validated.
Crypto dependencies are monitored for CVEs and kept current.
Secure, HttpOnly, and SameSite attributes enforced on session cookies.
Cloudflare WAF covering the OWASP Top 10, DDoS mitigation, and bot filtering.
DigitalOcean managed firewalls at the perimeter plus Cloudflare filtering at the edge.
Databases and storage sit inside a private VPC with RFC 1918 addresses and no public routing.
Cloudflare inspects and blocks known attack patterns before traffic reaches the cluster.
Aikido Firewall blocks SQL injection, command injection, and path traversal in real time.
No plaintext ingress paths to application infrastructure.
DNS responses are signed and origin-verified.
Rate limiting and alerting on repeated failed authentication attempts.
Controls prevent our infrastructure being used to attack other systems.
Two application roles — Teacher and School Administrator — each scoped to their own data.
TOTP-enforced for the cloud control panel and all internal systems.
Production and raw institutional data are reachable only by the CTO and CEO.
Continuous identification of over-privileged users, roles, and service accounts.
Alerts fire on changes to roles, users, and policies.
Escalation paths in roles and users are detected and remediated.
Secrets are injected at runtime from AWS Secrets Manager and verified by code scanning.
SSH key pairs and scoped API tokens only; access from unknown networks is limited.
Authentication, session, and application events stream to central logging in real time.
Login, logout, failed attempts, MFA events, and source IP are captured.
Each grading action records user, timestamp, action, and institution. Retained 1 year.
Control-plane actions including firewall rule changes are recorded.
Access patterns are analyzed for unusual activity and exfiltration attempts.
Aikido Security and Cloudflare monitor around the clock, with critical alerts paging on-call staff immediately.
Retained 60 days with point-in-time recovery inside the window.
Backups replicate from NYC3 to SFO3 daily over encrypted transport.
Multiple replicas per deployment on DigitalOcean Kubernetes behind a managed load balancer.
Guards against accidental destruction of production infrastructure.
Terraform and Helm definitions allow a full environment rebuild.
Spend and capacity thresholds are alerted on.
Aikido scans code, dependencies, and container images for CVEs and license risk.
Functional, regression, and security scenarios run on every code change.
Client and server-side validation; errors reveal no stack traces or internals.
Guards against SQL injection and cross-site scripting.
Dependencies are tracked for end-of-life status; base images are rebuilt on a schedule.
Changes are verified in staging before reaching production.
The application does not request device location.
Known CVEs, misconfigurations, and exposed attack surface are monitored from outside the perimeter.
Code, dependencies, and images are scanned and remediated before deployment.
Regular scanning for injection, XSS, CSRF, and related classes.
Completed February 2026. All findings medium or low severity; none critical or high.
Institutions may scan or test our systems at a mutually agreed time and scope.
Critical and high findings are prioritized ahead of scheduled work.
Organizational security
How the company itself is structured and governed — who we are, who works here, and how we manage the vendors that sit behind our service.
Privately held Delaware C-Corp, incorporated 2024, founder-led with no parent or subsidiary entities.
No physical office or company-operated data center; all infrastructure is cloud-hosted.
Security is led by the CTO, with the CEO serving as Data Protection Officer.
Nine-person software and systems team under the CTO, split across defined functional roles.
No material unplanned disruptions or outages in that period.
Cyber Liability, Errors & Omissions, and Media Liability coverage.
Background and/or reference checks are completed prior to joining.
Confidentiality/NDA and policy acknowledgements are required before work begins.
Required for all employees and contractors, covering FERPA, GDPR, and internal handling rules.
Responsible AI training aligned to the NIST AI Risk Management Framework (AI RMF 1.0).
Access is provisioned by role and revoked on role change or departure.
Full-disk encryption, MFA via SSO, VPN for sensitive systems, and current OS patching.
DigitalOcean, AWS, OpenAI and similar, each with independent third-party attestations.
Including OpenAI, with breach liability addressed contractually.
Repeated annually against our internal security baseline.
Applied to any vendor that collects, processes, or can access personal data.
Handled at the infrastructure layer by DigitalOcean under their SOC 2 Type II program.
Documented, owned, and tested annually.
Documented recovery procedures, responsibilities, and escalation paths; tested annually.
Owned by the CTO and DPO, supported by automated alerting and external counsel.
Critical alerts page on-call personnel at any hour.
In the event of closure or discontinuation, institutions keep full data access throughout.
Internal security procedures
The day-to-day practices behind the controls: how changes ship, how patches land, how access is reviewed, and what happens when something goes wrong.
Agile lifecycle with security considerations at design, build, review, and release.
Security requirements are defined before implementation begins.
OWASP guidance is embedded throughout development.
Any change touching personal data triggers a privacy impact review before release.
Aikido and Dependabot track third-party libraries continuously.
Severity-based prioritization across application, container, and infrastructure layers.
Prioritized ahead of planned work.
Cloudflare rules and runtime blocking cover the gap until a fix ships.
Unsupported libraries are flagged for replacement.
All privileged accounts are reviewed on a documented interval.
Enforced through the RBAC model between security administration, system administration, and user functions.
Conducted annually as part of the SOC 2 audit program.
Generation, storage, and rotation handled via AWS Secrets Manager and provider-managed KMS.
Led by the DPO, including the CTO, Chief Data Scientist, and external legal counsel.
Initial privacy impact assessment is performed on every incident.
Or sooner where the law or the institution’s agreement requires it.
A feature flag or full deployment rollback disables AI processing, and reverses it once resolved.
No reportable breach and no privacy policy or privacy law violation in the past 36 months.
Legal
Public agreements and the contracts institutions most often ask us to sign. We routinely sign district and university data privacy agreements.
Standard DPA for institutions, including GDPR Standard Contractual Clauses.
By request
Current third parties that process institutional data, and what each one does.
By request
We sign district and state SDPA templates, including NDPA-style agreements.
By request
Which models we use, what is sent to them, and what they may not do with it.
By request
Accessibility Conformance Report against WCAG 2.0 and 2.1 Level A and AA.
By request
Written notice within 72 hours of confirming a breach, or sooner where required.
By request
Cyber Liability, Errors & Omissions, and Media Liability coverage.
By request
FAQ for teachers
Practical answers about what happens to your students’ work and how much control you keep over grading.
Does EssayGrader use the real AP Lit rubric?
Yes! the official 6-point analytic rubric for all three FRQs: thesis (0–1), evidence & commentary (0–4), sophistication (0–1). You can also upload your own modified version.
Can it handle essays about any poem or novel?
Yes. The grader evaluates the essay’s argument and use of textual evidence against the rubric — it doesn’t need the work pre-loaded, and it handles both released FRQs and your own prompts.
How accurate is EssayGrader compared to my own scoring?
Whatever the AP course, we benchmark against experienced teachers and EssayGrader scores matched or landed within 1 point of teacher scores 94% of the time. To explore all the accuracy studies, visit our AI Grading Accuracy Center.
Is my student data safe?
Yes, papers are never used to train AI models. You can find more information about how we protect student data and privacy by visiting our trust center.
FAQ for schools
For IT, security, procurement, and privacy reviewers. A completed HECVAT 4.1.5 is available and answers most of this in more depth.
Does EssayGrader use the real AP Lit rubric?
Yes! the official 6-point analytic rubric for all three FRQs: thesis (0–1), evidence & commentary (0–4), sophistication (0–1). You can also upload your own modified version.
Can it handle essays about any poem or novel?
Yes. The grader evaluates the essay’s argument and use of textual evidence against the rubric — it doesn’t need the work pre-loaded, and it handles both released FRQs and your own prompts.
How accurate is EssayGrader compared to my own scoring?
Whatever the AP course, we benchmark against experienced teachers and EssayGrader scores matched or landed within 1 point of teacher scores 94% of the time. To explore all the accuracy studies, visit our AI Grading Accuracy Center.
Is my student data safe?
Yes, papers are never used to train AI models. You can find more information about how we protect student data and privacy by visiting our trust center.