Pocket IEP is committed to maintaining the highest standards of data security and regulatory compliance
Education Records Protection
Trust & Security Controls
Federal IT Standards
Health Information Privacy
The Family Educational Rights and Privacy Act protects student education records. Pocket IEP ensures full compliance through:
Row Level Security ensures student data is only accessible by authorized parents and legitimate educational staff
Only required student information fields are collected, stored, and displayed
Parents can access, review, export, and request deletion of their child's information
All data encrypted in transit and at rest. Comprehensive access logging maintained
Written data processing agreements with all vendors handling student data
SOC 2 Type II certification ensures our systems meet strict security, availability, processing integrity, confidentiality, and privacy standards:
Federal IT and defense contractor security requirements ensure government-grade protection:
Security controls aligned with federal security framework standards
Production environments isolated with controlled access and monitoring
Documented procedures for detection, reporting, and remediation of security incidents
Code reviews, dependency scanning, and security testing integrated into development
When handling Protected Health Information (PHI), Pocket IEP implements comprehensive HIPAA safeguards:
All Protected Health Information encrypted at rest and in transit using industry-standard protocols
PHI access limited to authorized users only with audit trail of all access events
BAAs in place with all third-party vendors processing PHI
Documented procedures for breach detection, assessment, and notification within required timelines
Automatic session timeouts and protections against unauthorized viewing of PHI
Our compliance and security team is available to answer questions and provide additional documentation.
Contact Compliance Team