Fairgrade

Trust

Built for student data. Assessed with candor.

Fairgrade holds grades, feedback, and student work, so we designed the platform to the standards higher education expects — FERPA, SOC 2, and HECVAT — and we audit our own implementation against them. We do not yet hold third-party attestations, and this page does not suggest otherwise. It sets out precisely what is in place, what is in progress, and what is planned.

Last reviewed September 2026 · Questions to info@fairgrade.com

Where we stand

Our current standing.

In place today

  • Encryption at rest and in transit
  • Signed, short-lived tokens on every request
  • Role-based permissions enforced server-side
  • Workspace-scoped data isolation
  • Anonymized peer review
  • Automated daily backups with point-in-time recovery
  • Documented deletion and retention lifecycle
  • Signed LTI 1.3 integration with LMS platforms
  • Personal information masked in operational logs

In progress

  • Single sign-on (SAML / OIDC) and SCIM provisioning for institutions
  • Formal data-processing terms with every subprocessor
  • Published incident-response commitments
  • Workspace-level data export

Planned

  • SOC 2 Type I audit
  • Independent penetration test
  • WCAG 2.1 AA audit and VPAT
  • Multi-factor authentication for all users
  • HECVAT questionnaire for higher-ed procurement

FERPA compliance is not conferred by certification; it is demonstrated through architecture, access controls, and contractual commitments — the substance of this page. SOC 2, by contrast, is an independent third-party audit, and it is listed above as planned rather than achieved.

How your data is protected

Encrypted, isolated, and verified on every request.

Your browserstudents · instructorsTLS 1.2+PRIVATE NETWORK · AWSFairgrade applicationverifies every requestEncrypted databaseEncrypted file storageSecrets vaultnot reachable from the internet

Identity and sessions

Sign-in is handled by Auth0. Every request to Fairgrade carries a cryptographically signed, short-lived token that is verified on our servers — identity is verified on every request rather than asserted by the client. Sessions expire on inactivity and have a hard maximum lifetime.

Encryption

Databases, file storage, and backups are encrypted at rest with AWS-managed keys. Traffic between your browser and Fairgrade is encrypted with TLS 1.2 or higher, and browsers are instructed never to connect insecurely.

Network

Application services and databases run inside a private network. The database is not reachable from the internet; only the application tier can open a connection to it, and only the load balancer can reach the application tier.

Secrets

Credentials and keys are never stored in source code or container images. They live in a managed, encrypted secrets vault and are provided to services only at runtime. Production services will not start without them.

Deletion and retention

Closing an account or workspace starts a documented lifecycle: a 30-day grace period during which the request may be withdrawn, then anonymization of personal identity so that academic records remain coherent, then scheduled purge. Every step is recorded.

Payments

Card details are never transmitted to or stored by Fairgrade. Billing is handled entirely by Stripe, so no cardholder data is stored or processed on our systems.

Who can see what

Access follows role, and the server checks.

Peer assessment depends on boundaries that hold — between students, between classes, and between institutions. Those boundaries are enforced on the server, where they cannot be bypassed.

Roles and permissions

Instructors, teaching assistants, students, and administrators each hold a distinct role with fine-grained permissions. Checks run on the server for every action — interface controls are never the sole safeguard.

Workspace isolation

Every record belongs to exactly one workspace, and a session is bound to the workspace it was issued for. A token from one institution cannot read another's data.

Anonymized peer review

Reviewers and authors are anonymous to each other, and that anonymity is enforced by the API — not merely by the interface.

Fairgrade staff access

Our own staff reach administrative tools only with multi-factor authentication, through a separate identity boundary, and every administrative action is logged.

FERPA-ready

What “FERPA-ready” means here, concretely.

  • Your institution owns its educational records; Fairgrade processes them only to deliver the service.
  • Access is scoped to legitimate educational roles — a student sees their own work and anonymized reviews, an instructor sees their classes, an administrator sees their workspace.
  • Personal information in operational logs is masked; identity is anonymized rather than left behind when an account is deleted.
  • We work with institutional procurement and legal teams on data-processing terms.

A note on AI

Fairgrade is built on original research in collective intelligence: grades are produced by credibility-weighted human judgment through the Marciano Method, algorithms of our own invention. AI-assisted scoring is a minor, optional feature that an instructor may enable for an individual assignment as a second opinion. It never determines a grade, and when it is not enabled, no student work is sent to an AI provider.

Subprocessors

Third parties that process data on our behalf.

ProviderPurposeLocation
Amazon Web ServicesHosting, storage, and backupsUnited States
Auth0 (Okta)Authentication and single sign-onUnited States
StripeBilling and paymentsUnited States
AnthropicOptional AI-assisted scoring, only when an instructor enables itUnited States
OpenAIOptional AI-assisted scoring, only when an instructor enables itUnited States
Customer support platformIn-app support messagingUnited States

This list is updated before any new provider is engaged.

Reliability

Hosted on AWS in the United States. Automated daily backups with point-in-time recovery, infrastructure defined as code, and production changes that require an explicit approval before they ship. We will publish measured uptime history before committing to availability figures.

Accessibility

The interface is built on accessible component foundations with keyboard navigation and screen-reader semantics. A formal WCAG 2.1 AA audit and a published VPAT are on the roadmap; we will state our conformance level once it has been independently measured.

Responsible disclosure

If you believe you have identified a security vulnerability, please contact info@fairgrade.com. We acknowledge reports promptly, coordinate remediation with the reporter, and credit responsible disclosure. Please refrain from accessing data that is not your own in the course of testing.

Conducting a security review? We will walk your team through the architecture, complete your questionnaire, and share our internal readiness assessments under NDA.

Talk to us

Ready to transform your classroom learning experience?

Start for free — no credit card required. Talk to us when your department is ready.

Are you a student? Join a class →