Trust
Security at Provenance
Provenance handles student work and evidence of learning. Protecting that data is core to the product, not an afterthought. Here is how we approach security.
Last updated: July 18, 2026
Infrastructure
The Services run on Amazon Web Services (AWS), a leading cloud provider with independently audited physical and environmental controls. Production runs in isolated cloud environments, with network boundaries that separate production from development and test environments.
Encryption
Data is encrypted in transit using TLS and at rest using industry-standard AES-256 encryption. Recordings and other sensitive assessment content are protected by encryption throughout their lifecycle in our systems.
Access control
Access to production systems is restricted to authorized personnel on a least-privilege basis. Administrative access is governed by centralized single sign-on (SSO) with multi-factor authentication (MFA) required. Access is reviewed periodically and revoked promptly when no longer needed.
Application and development security
We follow secure software-development practices, including peer code review, automated testing, and continuous integration and deployment pipelines. Infrastructure is managed as code so that changes are versioned, reviewed, and auditable. We monitor our dependencies for known vulnerabilities.
Monitoring and logging
We log and monitor system and application activity to detect and respond to anomalous or potentially malicious behavior, and we maintain an incident-response process to investigate and remediate security events.
Data privacy and FERPA
Much of the data we process constitutes student education records. When we process those records on behalf of an institution, we act as a "school official" with a legitimate educational interest under FERPA and remain under the institution's control with respect to the use and maintenance of the records. We do not sell personal information or use student data for advertising. See our Privacy Policy for details.
Compliance
We are actively pursuing SOC 2 Type II examination and continuously monitor our controls against that framework. If you are an institution evaluating Provenance and need additional security documentation, please reach out.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in our Services, please emailsecurity@provenancelearning.ai with details so we can investigate. Please give us a reasonable opportunity to address the issue before public disclosure, and avoid accessing or modifying data that is not your own.
Contact
For security questions or to request documentation, contactsecurity@provenancelearning.ai.