Trust
Security at Provenance
Provenance handles student work and evidence of learning. Protecting that data is core to the product, not an afterthought. Here is how we approach security.
We ask institutions to weigh evidence rather than assertions — the same standard applies to how we describe our own security.
Last updated: August 4, 2026
Independent attestation
Provenance has completed a SOC 2 Type I examination. Prescient Assurance LLC, an independent audit firm, assessed the design of our security controls against the AICPA Trust Services Criteria and issued its report on July 23, 2026.
We want to be precise about what that covers. A Type I report speaks to whether controls were suitably designed at a point in time; it does not attest to how they operated over a period. That is the Type II examination, which we are working toward — see Compliance below.
Our controls are monitored continuously rather than only at audit time. Current status, the criteria we are examined against, and the documentation available to institutions are published in our Trust Center. The sections below explain in plain language what those controls protect.
Infrastructure
The Services run on Amazon Web Services (AWS), a leading cloud provider with independently audited physical and environmental controls. Production runs in isolated cloud environments, with network boundaries that separate production from development and test environments.
Encryption
Data is encrypted in transit using TLS and at rest using industry-standard AES-256 encryption. Recordings and other sensitive assessment content are protected by encryption throughout their lifecycle in our systems.
Access control
Access to production systems is restricted to authorized personnel on a least-privilege basis. Administrative access is governed by centralized single sign-on (SSO) with multi-factor authentication (MFA) required. Access is reviewed periodically and revoked promptly when no longer needed.
Application and development security
We follow secure software-development practices, including peer code review, automated testing, and continuous integration and deployment pipelines. Infrastructure is managed as code so that changes are versioned, reviewed, and auditable. We monitor our dependencies for known vulnerabilities.
Monitoring and logging
We log and monitor system and application activity to detect and respond to anomalous or potentially malicious behavior, and we maintain an incident-response process to investigate and remediate security events.
Data privacy and FERPA
Much of the data we process constitutes student education records. When we process those records on behalf of an institution, we act as a "school official" with a legitimate educational interest under FERPA and remain under the institution's control with respect to the use and maintenance of the records. We do not sell personal information or use student data for advertising. See our Privacy Policy for details.
Subprocessors
We use third-party services to operate Provenance. These process submitted student work or the records produced from it:
- Amazon Web Services — hosting, storage, and processing of submitted artifacts, audio, and transcripts.
- LiveKit — WebRTC transport carrying live review-session audio. We use LiveKit only to move audio between participants, not for any of its AI services.
- Deepgram — speech-to-text transcription of review sessions.
- ElevenLabs — speech synthesis for spoken questions.
- Anthropic — AI assistance for drafting questions and organizing evaluation evidence for faculty review.
On AI providers specifically: Anthropic and Deepgram do not train models on the content we submit through their APIs. Subprocessors may retain data for a limited period under standard commercial terms before deletion.
Other vendors support internal operations rather than the product's data path: Google Workspace for company email, documents, and staff single sign-on; GitHub for source control; and Atlassian (Jira and Confluence) for issue tracking and internal documentation.
The current, authoritative list is maintained in our Trust Center.
Compliance
We are actively pursuing SOC 2 Type II examination and continuously monitor our controls against that framework. If you are an institution evaluating Provenance and need additional security documentation, please reach out.
For a security questionnaire, a data-flow review, or a vendor-assessment form, email security@provenancelearning.ai.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in our Services, please email security@provenancelearning.ai with details so we can investigate. Please give us a reasonable opportunity to address the issue before public disclosure, and avoid accessing or modifying data that is not your own.
Contact
For security questions or to request documentation, contact security@provenancelearning.ai.