Security without unsupported badges
Know what protects school data and what still requires review.
This page describes implemented safeguards, data handling, retention controls, incident responsibilities, and the evidence a school should request. It does not turn privacy laws or security frameworks into marketing certifications.
Implemented controls
Security boundaries a school can test.
Data lifecycle and retention
Capture, access, retention, and deletion are different decisions.
Retention values below describe current application controls. A signed agreement and school configuration may impose additional requirements.
Only for enabled school features and managed activity.
Limit records and actions by role, school, district, class, and plan.
Apply policy, show classroom context, produce reports, or support human review.
Apply automatic cleanup, school action, and contractual requirements.
FERPA, COPPA, and school obligations
Compliance is a shared operating model, not a logo.
Classroom Guardian does not publish a blanket legal certification. The school should review the product, privacy policy, configuration, and signed data terms against its own obligations.
School-controlled education records
The service is designed for school-authorized educational use with role-scoped access, school and district boundaries, access and export workflows, and school-directed deletion review.
- Confirm the school's legal basis and school-official criteria
- Define legitimate educational interest and authorized roles
- Review the signed data agreement, retention, redisclosure, and record-request process
Notice, consent, and limited use
The public privacy policy states that student information is not used for targeted advertising and is not sold for advertising or data-broker purposes. Schools control participating accounts and features.
- Determine whether school authorization or parent consent applies
- Provide required notices and limit collection to approved educational purposes
- Review access, deletion, operator contact, and feature configuration
Filtering supports a school program
Managed Chrome and Edge filtering, Safe YouTube, categories, custom policy, activity evidence, and human review can support a school's internet-safety program.
- The school remains responsible for its policy and required measures
- Test both overblocking and missed content
- Do not treat software purchase as automatic compliance
Procurement note: Ask for the current data agreement, subprocessor information, security answers, breach-notification terms, deletion obligations, and any required state-specific student-privacy terms before production use.
Incident response
A visible process from detection to follow-up.
- 1Detect and triage
Use service monitoring, errors, school reports, request identifiers, audit records, and component health to identify scope and severity.
- 2Contain
Pause affected rollout paths, revoke or rotate credentials, restrict access, or isolate a failing component while preserving evidence.
- 3Recover
Restore healthy service, verify policy, command, event, and screen behavior, and monitor for recurrence.
- 4Communicate
Publish service incidents where appropriate and follow applicable law and signed notification commitments for verified data incidents.
- 5Review
Document cause, impact, corrective actions, evidence preservation, and follow-up ownership.
Assurance limits
Evidence still required before production.
No SOC 2 or equivalent certification is currently claimed on the public site.
No current independent penetration-test report is published for unrestricted public download.
No general public uptime or response-time guarantee should be assumed.
No independently validated large-district deployment or concurrency benchmark is publicly claimed.
Last reviewed July 30, 2026. Public documentation supports an initial review but does not replace a signed agreement, school legal review, or technical pilot.
