Trust Center

EssayGrader Trust Center

How we protect student work, teacher accounts, and institutional data — the controls we run, the documents we can share, and answers to the questions schools ask most.

Hosting
DigitalOcean, US
Data residency
United States
Uptime, 12 mo.
99.9%
Last updated
September 2026

Compliance

Frameworks we align to and documents we can share. Items under NDA are available on request through your account contact or security@essaygrader.ai.

Aligned

NIST SP 800-53 Rev. 5

Our primary security and privacy controls baseline. Monitored continuously and reported by Aikido Security.

Security audit report (August 2026)
Compliant

FERPA

We act as a school official under the direct control of the institution. All student work is treated as an educational record.

FERPA statement — by request
Compliant

COPPA

No student accounts and no direct collection from children. Teachers control what is uploaded.

COPPA statement — by request
Compliant

State privacy laws

CCPA, SOPPA, and comparable state statutes. Student data is never sold and never used for targeted advertising.

State privacy addendum — by request
Completed

HECVAT 4.1.5

Full Higher Education Community Vendor Assessment Toolkit response covering organization, product, infrastructure, AI, and privacy.

HECVAT 4.1.5 (XLSX) — by request
In progress

SOC 2 Type 1

Audit program underway with internal audits and automated evidence collection already running. Our hosting provider holds SOC 2 Type II.

Status letter — by request
Supported

GDPR

We serve primarily US institutions and store data in the US. Standard Contractual Clauses are available, and EEA data subject rights are honored.

DPA with SCCs — by request
Partial

WCAG 2.1 Level AA

Accessibility Conformance Report completed May 2026. Known gaps are tracked with a published remediation roadmap.

VPAT / ACR (May 2026) — by request
Aligned

NIST AI RMF 1.0

Our AI risk model follows the Map, Measure, Manage, and Govern functions. All staff complete responsible AI training.

AI risk summary — by request
February 2026

Penetration test

Third-party assessment with no critical or high severity findings. Medium and low findings are tracked to closure.

Summary report (NDA) — by request
Not applicable

HIPAA

EssayGrader does not process protected health information. Do not upload PHI to the platform.

Not applicable

PCI DSS

Card data never touches our systems. Payments are handled entirely by Stripe.

Infrastructure security

Continuously monitored controls across our cloud, network, and application stack. Findings are produced by Aikido Security in real time and mapped to NIST SP 800-53 controls.

Encryption
NIST 1.4.22, 18.28.2
Data encrypted at rest

AES-256 across databases, persistent volumes, and object storage.

Data encrypted in transit

TLS 1.2/1.3 for all client, service-to-service, and third-party traffic.

Latest TLS version enforced

Unencrypted HTTP is rejected and redirected to HTTPS.

Safe SSL protocol usage enforced

Legacy ciphers and protocol versions are disabled.

FIPS 140-2/140-3 validated modules

Cryptographic modules used for transit and secret storage are FIPS-validated.

Up-to-date cryptography libraries

Crypto dependencies are monitored for CVEs and kept current.

Cookie abuse prevention

Secure, HttpOnly, and SameSite attributes enforced on session cookies.

Network and perimeter
NIST 18.5, 18.7
Web application firewall

Cloudflare WAF covering the OWASP Top 10, DDoS mitigation, and bot filtering.

Stateful packet inspection

DigitalOcean managed firewalls at the perimeter plus Cloudflare filtering at the edge.

Private networking only for data stores

Databases and storage sit inside a private VPC with RFC 1918 addresses and no public routing.

Network intrusion detection and prevention

Cloudflare inspects and blocks known attack patterns before traffic reaches the cluster.

Runtime application protection

Aikido Firewall blocks SQL injection, command injection, and path traversal in real time.

HTTPS enforced to cloud instances

No plaintext ingress paths to application infrastructure.

DNSSEC enabled

DNS responses are signed and origin-verified.

Brute-force protection

Rate limiting and alerting on repeated failed authentication attempts.

Restricted outbound abuse

Controls prevent our infrastructure being used to attack other systems.

Access control
NIST 1.2, 1.3.8, 1.6.2
Role-based access control

Two application roles — Teacher and School Administrator — each scoped to their own data.

MFA on all administrative accounts

TOTP-enforced for the cloud control panel and all internal systems.

Least privilege for staff

Production and raw institutional data are reachable only by the CTO and CEO.

Over-privileged account detection

Continuous identification of over-privileged users, roles, and service accounts.

IAM change notifications

Alerts fire on changes to roles, users, and policies.

Privilege-escalation detection

Escalation paths in roles and users are detected and remediated.

No hard-coded credentials

Secrets are injected at runtime from AWS Secrets Manager and verified by code scanning.

Secure remote access protocols

SSH key pairs and scoped API tokens only; access from unknown networks is limited.

Logging and monitoring
NIST 3.6.2, 3.11.2, 4.7.7
Centralized logging

Authentication, session, and application events stream to central logging in real time.

Authentication audit trail

Login, logout, failed attempts, MFA events, and source IP are captured.

AI activity logging

Each grading action records user, timestamp, action, and institution. Retained 1 year.

Firewall and network change logs

Control-plane actions including firewall rule changes are recorded.

Insider-threat and anomaly monitoring

Access patterns are analyzed for unusual activity and exfiltration attempts.

Continuous automated monitoring

Aikido Security and Cloudflare monitor around the clock, with critical alerts paging on-call staff immediately.

Resilience and backups
NIST 6.9.6, 18.5.3
Daily encrypted backups

Retained 60 days with point-in-time recovery inside the window.

Cross-region backup replication

Backups replicate from NYC3 to SFO3 daily over encrypted transport.

High-availability cluster

Multiple replicas per deployment on DigitalOcean Kubernetes behind a managed load balancer.

Deletion protection on cloud resources

Guards against accidental destruction of production infrastructure.

Infrastructure reproducible from code

Terraform and Helm definitions allow a full environment rebuild.

Budget and capacity alerting

Spend and capacity thresholds are alerted on.

Application security
NIST 17.3.2, 5.7.9
Static analysis on every change

Aikido scans code, dependencies, and container images for CVEs and license risk.

Automated tests in CI/CD

Functional, regression, and security scenarios run on every code change.

Input validation and safe error handling

Client and server-side validation; errors reveal no stack traces or internals.

Parameterized queries and output encoding

Guards against SQL injection and cross-site scripting.

Supported runtimes and libraries only

Dependencies are tracked for end-of-life status; base images are rebuilt on a schedule.

Separate preproduction environment

Changes are verified in staging before reaching production.

No location or GPS access

The application does not request device location.

Vulnerability management
NIST 5.5.2
Continuous external scanning

Known CVEs, misconfigurations, and exposed attack surface are monitored from outside the perimeter.

Pre-release authenticated scanning

Code, dependencies, and images are scanned and remediated before deployment.

OWASP Top 10 coverage

Regular scanning for injection, XSS, CSRF, and related classes.

Third-party security assessment

Completed February 2026. All findings medium or low severity; none critical or high.

Customer-run testing permitted

Institutions may scan or test our systems at a mutually agreed time and scope.

Severity-based patch SLAs

Critical and high findings are prioritized ahead of scheduled work.

Organizational security

How the company itself is structured and governed — who we are, who works here, and how we manage the vendors that sit behind our service.

Company
Tech Nest Ventures USA Corp. (DBA EssayGrader.ai)

Privately held Delaware C-Corp, incorporated 2024, founder-led with no parent or subsidiary entities.

Fully remote, US and Canada

No physical office or company-operated data center; all infrastructure is cloud-hosted.

Dedicated security leadership

Security is led by the CTO, with the CEO serving as Data Protection Officer.

Dedicated engineering team

Nine-person software and systems team under the CTO, split across defined functional roles.

99.9% uptime over the past 12 months

No material unplanned disruptions or outages in that period.

Cyber-risk insurance

Cyber Liability, Errors & Omissions, and Media Liability coverage.

People
Background checks before day one

Background and/or reference checks are completed prior to joining.

Signed agreements at onboarding

Confidentiality/NDA and policy acknowledgements are required before work begins.

Mandatory security awareness training

Required for all employees and contractors, covering FERPA, GDPR, and internal handling rules.

Mandatory AI privacy and ethics training

Responsible AI training aligned to the NIST AI Risk Management Framework (AI RMF 1.0).

Documented onboarding and offboarding

Access is provisioned by role and revoked on role change or departure.

Remote workstation policy

Full-disk encryption, MFA via SSO, VPN for sensitive systems, and current OS patching.

Vendors and third parties
Tier-1 providers only

DigitalOcean, AWS, OpenAI and similar, each with independent third-party attestations.

DPAs with all critical subprocessors

Including OpenAI, with breach liability addressed contractually.

Risk assessment before onboarding a vendor

Repeated annually against our internal security baseline.

Privacy impact assessment of third parties

Applied to any vendor that collects, processes, or can access personal data.

Hardware supply chain

Handled at the infrastructure layer by DigitalOcean under their SOC 2 Type II program.

Continuity
Business continuity plan

Documented, owned, and tested annually.

Disaster recovery plan

Documented recovery procedures, responsibilities, and escalation paths; tested annually.

Formal incident response plan

Owned by the CTO and DPO, supported by automated alerting and external counsel.

24×7 on-call rotation

Critical alerts page on-call personnel at any hour.

90 days’ notice on service retirement

In the event of closure or discontinuation, institutions keep full data access throughout.

Internal security procedures

The day-to-day practices behind the controls: how changes ship, how patches land, how access is reviewed, and what happens when something goes wrong.

Secure development
Documented SDLC

Agile lifecycle with security considerations at design, build, review, and release.

Threat modeling at design time

Security requirements are defined before implementation begins.

Secure coding practices

OWASP guidance is embedded throughout development.

Privacy review gate

Any change touching personal data triggers a privacy impact review before release.

Dependency and license monitoring

Aikido and Dependabot track third-party libraries continuously.

Patch and vulnerability handling
Documented patch management process

Severity-based prioritization across application, container, and infrastructure layers.

Critical and high patched first

Prioritized ahead of planned work.

Interim mitigations when patching must wait

Cloudflare rules and runtime blocking cover the gap until a fix ships.

End-of-life dependency checks each release cycle

Unsupported libraries are flagged for replacement.

Access and audit
Periodic privileged access review

All privileged accounts are reviewed on a documented interval.

Separation of duties

Enforced through the RBAC model between security administration, system administration, and user functions.

Internal audits

Conducted annually as part of the SOC 2 audit program.

Key management process

Generation, storage, and rotation handled via AWS Secrets Manager and provider-managed KMS.

Incident response
Multidisciplinary response team

Led by the DPO, including the CTO, Chief Data Scientist, and external legal counsel.

Privacy officer on the response team

Initial privacy impact assessment is performed on every incident.

72-hour breach notification

Or sooner where the law or the institution’s agreement requires it.

AI can be taken offline during an incident

A feature flag or full deployment rollback disables AI processing, and reverses it once resolved.

No personal data breach in the past three years

No reportable breach and no privacy policy or privacy law violation in the past 36 months.

FAQ for teachers

Practical answers about what happens to your students’ work and how much control you keep over grading.

Does EssayGrader use the real AP Lit rubric?

Yes! the official 6-point analytic rubric for all three FRQs: thesis (0–1), evidence & commentary (0–4), sophistication (0–1). You can also upload your own modified version.

Can it handle essays about any poem or novel?

Yes. The grader evaluates the essay’s argument and use of textual evidence against the rubric — it doesn’t need the work pre-loaded, and it handles both released FRQs and your own prompts.

How accurate is EssayGrader compared to my own scoring?

Whatever the AP course, we benchmark against experienced teachers and EssayGrader scores matched or landed within 1 point of teacher scores 94% of the time. To explore all the accuracy studies, visit our AI Grading Accuracy Center.

Is my student data safe?

Yes, papers are never used to train AI models. You can find more information about how we protect student data and privacy by visiting our trust center.

FAQ for schools

For IT, security, procurement, and privacy reviewers. A completed HECVAT 4.1.5 is available and answers most of this in more depth.

Does EssayGrader use the real AP Lit rubric?

Yes! the official 6-point analytic rubric for all three FRQs: thesis (0–1), evidence & commentary (0–4), sophistication (0–1). You can also upload your own modified version.

Can it handle essays about any poem or novel?

Yes. The grader evaluates the essay’s argument and use of textual evidence against the rubric — it doesn’t need the work pre-loaded, and it handles both released FRQs and your own prompts.

How accurate is EssayGrader compared to my own scoring?

Whatever the AP course, we benchmark against experienced teachers and EssayGrader scores matched or landed within 1 point of teacher scores 94% of the time. To explore all the accuracy studies, visit our AI Grading Accuracy Center.

Is my student data safe?

Yes, papers are never used to train AI models. You can find more information about how we protect student data and privacy by visiting our trust center.

EssayGrader is operated by Tech Nest Ventures USA Corp. (DBA EssayGrader.ai), Delaware, USA.