How we protect your data

We take care of student and staff data with the same seriousness you do. IDP is built on secure third-party data and AI infrastructure, with encrypted connections, role-based permissions, customer-specific environments, and human-reviewable AI workflows.

What this means for you

Individualized access

Users receive personal, passkey-enabled sign-in credentials with role-based access to the data and workflows the school has authorized. IDP AI follows those permissions, so users do not receive answers based on data they are not allowed to see. We can also facilitate your current SSO process.

Data residency & retention

Customer data remains customer-owned. Hosting, retention, return, and deletion expectations are documented in the school agreement and implementation plan. US-hosted by default; other arrangements may be available by agreement.

Encryption

All data is encrypted in transit and at rest. Connections to school systems use secure API-based methods where available, and read-only access is preferred whenever it supports the use case.

Compliance & accreditation

All of our software is built upon infrastructure that is certified to comply with SOC 2 Type II, FedRAMP High, the ISO/IEC 27001 family, HIPAA and more.

Privacy

IDP uses customer data to provide contracted services. We do not independently collect customer data, sell customer data or use identifiable school data for unrelated product purposes or model training. Our agreements and implementation practices are structured to align with FERPA, COPPA, applicable state student privacy laws, and school-specific data protection requirements

Learn more

Security and privacy questions are not a side issue for IDP. They are part of the product. We are happy to discuss data ownership, permissions, retention, subprocessors, AI review, and implementation practices with your leadership, technology, and legal teams.

We encourage you to learn more by contacting us here or emailing us.