Security Evidence
Ready to packageCentral checklist, audit integrity checks, admin allowlists, and backup controls are available.
District Readiness
A district-facing view of the controls, evidence, and next steps needed for K-12 review.
Readiness Score
63%
5 of 8 controls ready or configured
Policy Version
1.0
Updated 2026-05-28
Saved Work Retention
365 days
Auto deletion enabled
Central checklist, audit integrity checks, admin allowlists, and backup controls are available.
Public privacy, terms, retention settings, and FERPA/COPPA alignment notes are linked for review.
District admins can filter events, save export views, and download CSV evidence for reviews.
District rollout notes cover Google, Microsoft, Clever, ClassLink, and role assignment controls.
WCAG and VPAT workflow is captured for internal review and third-party validation.
Incident response, support posture, disaster recovery, and external validation steps are outlined.
Current implementation evidence and remaining district launch actions.
| Control | Status | Evidence | Next Step |
|---|---|---|---|
District admin access Engineering | Configured | District-admin routes fail closed unless the user has role metadata and an explicit ID/email allowlist match. | Populate DISTRICT_ADMIN_USER_ID_ALLOWLIST or DISTRICT_ADMIN_EMAIL_ALLOWLIST for each district launch. |
Retention policy Compliance | Ready | Policy 1.0; saved work 365 days; grading records 365 days. | Confirm values match the signed DPA and district-specific retention schedule. |
Auditability Engineering | Ready | District dashboard includes audit events, CSV export views, and hash-chain integrity verification. | Export a current pilot CSV and attach it to the district evidence folder. |
Browser security Engineering | Ready | Security headers disable Next powered-by header and set HSTS, nosniff, frame, referrer, and permissions policies. | Validate headers in staging with the district hostname before procurement review. |
School data requests Support | Configured | Published data request route: compliance@classxl.com. | Map district escalation contacts and response SLA in the support runbook. |
SSO + rostering Implementation | Needs review | Implementation plan covers Google, Microsoft, Clever, ClassLink, and role assignment controls. | Select launch identity provider and run a scoped roster import pilot. |
Accessibility Product | External required | WCAG 2.1 AA and VPAT workflow are documented for validation. | Complete manual accessibility pass and attach third-party VPAT or internal conformance report. |
External security validation Security | External required | Penetration test / external validation process is documented. | Schedule external assessment and attach final report or remediation letter. |