Privacy engineering
Role-scoped access, guardian boundaries, audit events, and privacy-minimized AI review records are covered by automated tests. District policy and contract review remain deployment-specific.
Read the privacy policyThis page separates implemented controls from external validation and customer outcomes. If evidence is still missing, we say so plainly.
Assurance ledger
Implementation is not certification. Automated checks are not an independent audit. A pilot target is not a measured customer result.
Role-scoped access, guardian boundaries, audit events, and privacy-minimized AI review records are covered by automated tests. District policy and contract review remain deployment-specific.
Read the privacy policyCore journeys receive automated accessibility and responsive checks. Ember targets WCAG 2.2 AA; a third-party audit and formal VPAT are still open launch gates.
See current conformanceLTI 1.3 launch, Deep Linking, AGS, and NRPS paths exist in the product. Ember is not claiming 1EdTech certification until it appears in the official directory.
Review deployment endpointsAuthentication, authorization, security headers, rate limits, request tracing, and incident procedures have code and test evidence. Ember has not completed a SOC 2 audit.
Review security practicesOpen gates
These are not buried in fine print. They are the work required before broad production rollout.
Our implementation targets are informed by official FERPA vendor guidance, the FTC's education-technology privacy policy, WCAG 2.2, and 1EdTech's LTI certification process.
Start in 2 minutes. Create a course, generate a lesson plan, and feel the difference.