Security & student data privacy

Security and student data privacy at Voxento

Voxento follows FERPA-aligned privacy practices, encrypts data in transit and at rest, scopes access by role, and publishes a school data protection addendum you can read before you talk to us. Student data is never sold and never used for advertising.

In short

Everything a district needs for a security review is on this page or linked from it, readable before you talk to anyone. Where a question has a straight answer — who owns the data, what happens on termination, which certifications we hold — you will find it below rather than in a negotiation.

FERPA-aligned privacy

Schools control their data. Student data is never sold, and is never used for targeted advertising or commercial profiling.

Encryption and access control

Encryption in transit and at rest, with role-based access so observers and administrators see only what their role covers.

Data protection addendum

A school data protection addendum is published and available for district review before any conversation about contracts.

Named reference

Cardinal Community School District is available as an approved reference for districts running their own diligence.

How is student data handled?

Student data is processed only to provide the service and only as instructed by the school. Voxento acts as a service provider; the school remains the data controller.

QuestionVoxento's position
Purpose of processingProviding the service, on the school's instructions
Targeted advertisingNever. No commercial profiling of students
Data ownershipThe school owns its data
ExportAvailable at any time, in a usable format
Deletion on terminationReturned or deleted per the school's instructions and applicable law
EncryptionIn transit and at rest
Access modelRole-based, scoped to staff groups
SubprocessorsCurrent list on request; schools notified of material changes
Demonstrating complianceVoxento cooperates with reasonable requests from schools

These commitments are contractual, not marketing copy — each one comes from the school data protection addendum.

What can we send you for a security review?

The data protection addendum, our subprocessor list, and a live walkthrough of role-based access — before you commit to an evaluation. Send your district's security questionnaire and we will complete it.

  • The school data protection addendum, published and readable right now
  • A current subprocessor list, on request
  • A live demonstration of role-based access and data export
  • Written answers to your district's own vendor security questionnaire
  • Cardinal Community School District as a reference you can call

On certifications: Voxento does not currently hold a SOC 2 Type II report or ISO 27001 certificate. Those are third-party attestations of process maturity, and they are generally held by larger vendors — what they attest to is the audit, not the security practice itself. What Voxento offers instead is direct access to the underlying practices and contractual commitments, which is the evidence an attestation is a proxy for.

If your district gates procurement on a certification, tell us on the first call. Knowing in week one is better for both of us than finding out in legal review.

What should a district ask any observation vendor?

Ask for the data protection addendum on the first call, not the last. A tool that clears every instructional requirement can still fail legal review.

  1. Do you have a school data protection addendum we can review today, or does it have to be drafted?
  2. Who owns the observation data, and what do we get back if we leave?
  3. Can access be scoped so a department head sees only their own team?
  4. How long is data retained, and can we configure it to match our evaluation agreement?
  5. Who are your subprocessors, and how are we notified when they change?
  6. Do you hold SOC 2 or ISO 27001 — and if not, say so plainly.
  7. Is student data ever used for advertising, model training, or profiling?

The full procurement list, with what a good answer sounds like and what should worry you, is in 12 questions to ask before buying observation software.

Frequently asked questions

Is Voxento FERPA compliant?
Voxento follows FERPA-aligned privacy practices and offers a school data protection addendum for district review. FERPA obligations sit with the school as the data controller; Voxento operates as a service provider acting on the school's instructions.
Is student data ever sold or used for advertising?
No. Voxento does not use student data for targeted advertising or commercial profiling, and does not sell it. Student data is processed only to provide the service and as instructed by the school.
Does Voxento have a SOC 2 report or ISO 27001 certification?
Not currently. SOC 2 and ISO 27001 are third-party attestations of process maturity, generally held by larger vendors. Voxento provides the underlying evidence directly instead: a published data protection addendum, a subprocessor list on request, role-based access you can see demonstrated, and full data export. If your district requires a certification to proceed, tell us on the first call.
Who owns our observation data?
The school does. You can export your data at any time, and on termination Voxento returns or deletes student data in accordance with the school's instructions and applicable law.
Can we see a list of subprocessors?
Yes. A current list of subprocessors is available on request, and schools are notified of material changes.
Can a department head see only their own team's observations?
Yes. Access is role-based, so observation records can be scoped to the staff groups a given user is responsible for.

Send us your security questionnaire.

We would rather answer it before you invest time in an evaluation than after.

Made in USA

Hosted in USA, GDPR compliant.

White Label Solution

Fully customizable platform with your branding and requirements.

Just start

Ready to use in minutes. No prior knowledge required.

Real support

Personal, fast and with real people.