Ember
    For TeachersFor StudentsFor ParentsPricingCompany
    Sign inGet started
    Security & compliance
    Compliance documentation

    SOC 2 Controls Overview

    Audience: Security reviewers, procurement, and district IT leadership
    Status: SOC 2 Type II readiness — formal audit scheduled per customer contract

    Overview

    Ember LMS is designed around the AICPA Trust Services Criteria (TSC) that underpin SOC 2 Type II reports. This overview describes what we control and how districts can verify it — without exposing internal implementation details.

    For auditor-ready evidence packages (policies, screenshots, sample exports), contact security@ember.edu.

    Trust Services Criteria mapping

    TSCControl areaHow Ember addresses it
    CC6.1Logical accessOrganization-scoped roles, course enrollments, and quarterly access review exports for admins
    CC6.2Credential managementStrong password policy, account lockout, and optional SSO for district identity providers
    CC6.3Role-based accessTeachers, students, parents, and admins see only data their role permits (FERPA-aligned)
    CC6.6System boundariesAuthenticated API access, TLS in transit, and tenant isolation between districts
    CC6.7Data access loggingAudit trail when student education records are viewed, exported, or changed
    CC7.2Security monitoringCompliance dashboard for org admins with activity summaries
    CC8.1Change managementPeer-reviewed releases, automated test gates, and documented deployment process
    CC9.2Vendor riskThird-party AI, email, and storage providers are contractually bounded; student PII is not used to train models

    FERPA-aligned audit logging

    Ember logs access to student education records so districts can investigate who viewed grades, submissions, or exports. Administrators can review activity from the Compliance Center in the Ember admin dashboard and export reports for their records retention policy.

    Typical logged actions include read access to gradebooks and submissions, bulk exports, and record deletions governed by district policy.

    Encryption

    LayerCommitment
    In transitTLS 1.2+ for all web and API traffic
    At restAES-256 for databases and object storage in production
    SecretsManaged through secure environment configuration — never embedded in client apps

    Administrator MFA

    Organization administrators are required to enable multi-factor authentication before accessing sensitive admin functions. Teachers and students may use district SSO where configured.

    Incident response

    Security events follow our documented Incident Response process, including FERPA breach assessment and district notification timelines aligned with your DPA.

    Related resources

    • Incident Response
    • Go-Live Guide
    • Security & compliance
    Free for teachers · No credit card

    Give teachers
    their time back.

    Start in 2 minutes. Create a course, generate a lesson plan, and feel the difference.

    Start freeBook a demo
    Privacy controls tested Human approval boundaries Open Trust Center
    Ember

    The AI-native learning platform.

    A Molar Labs product

    Courses, quizzes, tutoring, and analytics for K–12 and higher ed — in one warm workspace teachers actually enjoy.

    View launch evidence and open gates
    Privacy controls testedAudit pendingLTI implemented
    Get started free

    Product

    • Features
    • AI Agents
    • Learning Catalog
    • Integrations
    • Trust Center
    • Pricing
    • Plans & upgrades
    • Security practices

    Solutions

    • For Teachers
    • For Students
    • For Parents

    Company

    • About
    • Pricing
    • Contact

    Legal

    • Legal hub
    • Privacy
    • Terms
    • Accessibility

    Student data privacy · Security

    © 2026 Molar Labs. All rights reserved.
    pratik@molar.it·Legal·Privacy·Terms·Security·GitHub
    Ember — from the house of Molar