Trust
Built for student data. Assessed with candor.
Fairgrade holds grades, feedback, and student work, so we designed the platform to the standards higher education expects — FERPA, SOC 2, and HECVAT — and we audit our own implementation against them. We do not yet hold third-party attestations, and this page does not suggest otherwise. It sets out precisely what is in place, what is in progress, and what is planned.
Last reviewed September 2026 · Questions to info@fairgrade.com
Where we stand
Our current standing.
In place today
- Encryption at rest and in transit
- Signed, short-lived tokens on every request
- Role-based permissions enforced server-side
- Workspace-scoped data isolation
- Anonymized peer review
- Automated daily backups with point-in-time recovery
- Documented deletion and retention lifecycle
- Signed LTI 1.3 integration with LMS platforms
- Personal information masked in operational logs
In progress
- Single sign-on (SAML / OIDC) and SCIM provisioning for institutions
- Formal data-processing terms with every subprocessor
- Published incident-response commitments
- Workspace-level data export
Planned
- SOC 2 Type I audit
- Independent penetration test
- WCAG 2.1 AA audit and VPAT
- Multi-factor authentication for all users
- HECVAT questionnaire for higher-ed procurement
FERPA compliance is not conferred by certification; it is demonstrated through architecture, access controls, and contractual commitments — the substance of this page. SOC 2, by contrast, is an independent third-party audit, and it is listed above as planned rather than achieved.
How your data is protected
Encrypted, isolated, and verified on every request.
Identity and sessions
Sign-in is handled by Auth0. Every request to Fairgrade carries a cryptographically signed, short-lived token that is verified on our servers — identity is verified on every request rather than asserted by the client. Sessions expire on inactivity and have a hard maximum lifetime.
Encryption
Databases, file storage, and backups are encrypted at rest with AWS-managed keys. Traffic between your browser and Fairgrade is encrypted with TLS 1.2 or higher, and browsers are instructed never to connect insecurely.
Network
Application services and databases run inside a private network. The database is not reachable from the internet; only the application tier can open a connection to it, and only the load balancer can reach the application tier.
Secrets
Credentials and keys are never stored in source code or container images. They live in a managed, encrypted secrets vault and are provided to services only at runtime. Production services will not start without them.
Deletion and retention
Closing an account or workspace starts a documented lifecycle: a 30-day grace period during which the request may be withdrawn, then anonymization of personal identity so that academic records remain coherent, then scheduled purge. Every step is recorded.
Payments
Card details are never transmitted to or stored by Fairgrade. Billing is handled entirely by Stripe, so no cardholder data is stored or processed on our systems.
Who can see what
Access follows role, and the server checks.
Peer assessment depends on boundaries that hold — between students, between classes, and between institutions. Those boundaries are enforced on the server, where they cannot be bypassed.
Roles and permissions
Instructors, teaching assistants, students, and administrators each hold a distinct role with fine-grained permissions. Checks run on the server for every action — interface controls are never the sole safeguard.
Workspace isolation
Every record belongs to exactly one workspace, and a session is bound to the workspace it was issued for. A token from one institution cannot read another's data.
Anonymized peer review
Reviewers and authors are anonymous to each other, and that anonymity is enforced by the API — not merely by the interface.
Fairgrade staff access
Our own staff reach administrative tools only with multi-factor authentication, through a separate identity boundary, and every administrative action is logged.
FERPA-ready
What “FERPA-ready” means here, concretely.
- Your institution owns its educational records; Fairgrade processes them only to deliver the service.
- Access is scoped to legitimate educational roles — a student sees their own work and anonymized reviews, an instructor sees their classes, an administrator sees their workspace.
- Personal information in operational logs is masked; identity is anonymized rather than left behind when an account is deleted.
- We work with institutional procurement and legal teams on data-processing terms.
A note on AI
Fairgrade is built on original research in collective intelligence: grades are produced by credibility-weighted human judgment through the Marciano Method, algorithms of our own invention. AI-assisted scoring is a minor, optional feature that an instructor may enable for an individual assignment as a second opinion. It never determines a grade, and when it is not enabled, no student work is sent to an AI provider.
Subprocessors
Third parties that process data on our behalf.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, and backups | United States |
| Auth0 (Okta) | Authentication and single sign-on | United States |
| Stripe | Billing and payments | United States |
| Anthropic | Optional AI-assisted scoring, only when an instructor enables it | United States |
| OpenAI | Optional AI-assisted scoring, only when an instructor enables it | United States |
| Customer support platform | In-app support messaging | United States |
This list is updated before any new provider is engaged.
Reliability
Hosted on AWS in the United States. Automated daily backups with point-in-time recovery, infrastructure defined as code, and production changes that require an explicit approval before they ship. We will publish measured uptime history before committing to availability figures.
Accessibility
The interface is built on accessible component foundations with keyboard navigation and screen-reader semantics. A formal WCAG 2.1 AA audit and a published VPAT are on the roadmap; we will state our conformance level once it has been independently measured.
Responsible disclosure
If you believe you have identified a security vulnerability, please contact info@fairgrade.com. We acknowledge reports promptly, coordinate remediation with the reporter, and credit responsible disclosure. Please refrain from accessing data that is not your own in the course of testing.
Conducting a security review? We will walk your team through the architecture, complete your questionnaire, and share our internal readiness assessments under NDA.
Talk to usReady to transform your classroom learning experience?
Start for free — no credit card required. Talk to us when your department is ready.
Are you a student? Join a class →