Student data is sacred. OralExam.ai is built around the security, privacy, and compliance requirements that universities and school districts demand. Where we have not finished something, this page says so.
These are the regulatory and accessibility standards educational institutions ask us about. For each one we say plainly what is in place, what is in progress, and what we have not started.
Designated as a School Official with legitimate educational interest. A data processing agreement is signed with every institution before a deployment begins. FERPA has no certifying body, so nobody can hand you a FERPA certificate, including us.
We are scoping SOC 2 Type I attestation as the first step toward Type II. We can share our current security posture and roadmap upon request.
OralExam.ai is used in high schools as well as in higher education. The service is not directed at children under 13, and we do not knowingly collect data from them. We have completed the compliance and privacy assessments required for K-12 deployment, and approved high school pilots are running now. Requirements vary by district and by state, so talk to us before deploying and we will share the documentation set that applies to your jurisdiction.
We self-attest conformance in a VPAT 2.5 Rev 508, available on request. Our marketing pages conform. Conformance inside the application is in progress and has not been audited by a third party, and we will not claim otherwise until it has.
We apply defense-in-depth principles to ensure student and institutional data is protected from ingestion to deletion.
All data is encrypted with AES-256 at rest and TLS 1.2+ in transit. No exceptions.
Student data is stored in US infrastructure, and every sub-processor that touches it operates in US regions. The current list goes out with the data processing agreement, and on request before that.
Granular permissions ensure users only access the data they need. Administrators control who sees what.
Authentication events and application-tier access to Education Records are logged. Coverage of every database-tier event is still being expanded. Logs for your institution are available on request, not yet through a self-service view.
Our infrastructure is designed for the reliability and security that institutions expect from critical educational technology.
Hosted on major cloud providers whose data centers hold SOC 2 and ISO 27001 certifications. Those certifications belong to the providers. Ours is described above.
We have not commissioned a third-party penetration test. The first engagement is sequenced with our SOC 2 audit window, and we will share the report with institutions under NDA once one exists.
Static analysis and dependency scanning run in CI on every change, so known vulnerabilities are caught before they reach production. Authenticated dynamic scanning begins alongside the first penetration test.
A written incident response plan with named roles, a four-tier severity rubric, and runbooks for the scenarios most relevant to our stack. Affected institutions are notified within 72 hours of confirming a reportable breach of Education Records. The plan is available to institutional counsel on request under NDA.
The application and the API both expose health endpoints. External uptime monitoring and paging against them is being set up and is not live yet, so treat this as work in progress rather than a control you can rely on today. We do not yet offer a contractual uptime SLA. If your institution needs one, raise it during contracting.
We believe student data belongs to students and their institutions, not to us. Our data handling practices reflect that principle.
We only collect the data necessary to conduct assessments. Nothing more.
Exam video carries a 90 day retention window, and submissions, transcripts and results are purged 12 months after the end of the academic term. Both purges are run by an administrator today. Neither is on an automatic schedule yet, and we would rather tell you than imply otherwise.
Institutions can request full data removal at any time. We honor deletion requests promptly and completely.
We will never sell, share, or monetize student data. Ever. This is non-negotiable.
Student submissions and conversations are never used to train AI models. Your data stays yours.
Any aggregated analytics are fully anonymized. Individual students can never be identified from analytics data.
We give institutions the tools to manage OralExam.ai on their terms, with the administrative controls IT departments expect.
Today we authenticate via Supabase Auth with email and password, and TOTP multi-factor is enforced on administrative accounts. There is no federated login yet. SAML 2.0 and OIDC institutional SSO are on the roadmap.
Defined roles for students, instructors, program directors, and administrators, each with its own visibility. Access is enforced on the server, not in the browser.
Instructors export roster results as CSV from the results page. A full export of your institution's records is available on request, and we return or destroy everything on termination.
Administrative actions and authentication events are recorded and retrievable for your institution on request. There is no administrator-facing audit dashboard yet.
12 months after the end of the academic term for submissions, transcripts and results, and 90 days for exam video. Those windows are the same for every institution today: there is no settings panel and no per-institution override. If your policy needs a different one, raise it during contracting.
Our team is ready to discuss your institution's security requirements, provide documentation, or schedule a technical review.