You're probably here because a vendor has burned you before — a missing BAA, a redacted SOC 2, a sub-processor change you found out about from a news headline. We've built this page so that doesn't happen with us.
Operations
Production telemetry and historical uptime are published continuously at our status page. The compliance program itself is managed through Scrut, our GRC platform — every control, every audit, every piece of evidence lives there and is independently verifiable.
Live verification
Most trust pages are static. Ours is connected directly to Scrut, the GRC platform that runs our compliance program. Every control, every piece of evidence, every audit artifact you'd want to verify — is verifiable in real time, not on a quarterly refresh.
Powered by Scrut Trust Vault
Behind every trust claim is an actual control with a status, an owner, an evidence file, and a last-tested date. The Trust Vault publishes that machine state directly — sourced from Scrut, the platform we use to run our compliance program day to day.
Procurement teams can verify the status of any framework, request access to evidence under NDA, and subscribe to alerts on changes. Your security team won't need to email us. The receipts are right there.
What's verifiable, live
Compliance
Pencil Spaces is audited or certified against eight regulatory and industry frameworks: FERPA, COPPA, SOC 2 Type II, GDPR, HIPAA, CCPA, ISO 27001, and SDPC NDPA. Each row below maps to a specific federal regulation, attestation, or industry standard. Reports are available on request, generally under mutual NDA.
Frequently asked
Procurement, IT, and parents tend to arrive with the same questions. The answers are below — short, sourced, and quotable. For anything not covered, the Trust team responds at trust@pencilspaces.com.
Yes. Pencil Spaces operates as a school official under the FERPA school-official exception (20 U.S.C. § 1232g). We do not run advertising, we do not profile students, and we do not use student data to train any model. Districts can review the full FERPA control mapping in our Customer Assurance Package.
Yes. Pencil Spaces is COPPA compliant under 16 CFR Part 312. We support verifiable parental consent flows, do not allow third-party tracking on accounts identified as belonging to a minor, and operate K-12 safe by default.
Yes. Pencil Spaces is currently in SOC 2 Type II attestation against the AICPA Trust Services Criteria. The current report is available under mutual NDA on completion. A bridge letter is available between annual reports. Request access at trust@pencilspaces.com — most requests are fulfilled within one business day.
Yes. Pencil Spaces is GDPR compliant under Reg. (EU) 2016/679. EU data residency is available on request. We provide a pre-signed Data Processing Agreement with current Standard Contractual Clauses, and right-to-erasure requests are honored within 30 days.
Yes. Pencil Spaces will sign a Business Associate Agreement under 45 CFR §§ 160, 162, 164. Protected Health Information is encrypted at rest using AES-256 and in transit using TLS 1.3. Audit logs are retained for six years per § 164.530(j). Request the BAA at trust@pencilspaces.com.
Yes. Pencil Spaces honors all California consumer rights under Cal. Civ. § 1798.100 end-to-end. Verified-request portal is staffed within five business days. For data subject requests under CCPA, write to privacy@pencilspaces.com.
Pencil Spaces' Information Security Management System is aligned to ISO/IEC 27001:2022 controls, with surveillance work in progress through our certification body. Status updates are published in the compliance changelog.
Yes. Pencil Spaces is a signatory to the SDPC National Data Privacy Agreement (NDPA v1.0) and is active in multiple state alliances. Standard-form district contracts are available — request the NDPA for your state at trust@pencilspaces.com.
Customer data is stored on multi-region cloud infrastructure pinned to the customer's chosen region. EU customers can request residency in EU data centers. All data is encrypted at rest using AES-256 and in transit using TLS 1.3. See Infrastructure for full detail.
No. Pencil Spaces does not use customer or student session content (video, audio, whiteboard, chat) to train any AI model — ours or any third-party model. No third-party AI agents are embedded in the customer experience without explicit opt-in. See our full AI Systems & Automation disclosure.
The full sub-processor list is published at trust.pencilspaces.com/#subprocessors and updated quarterly. Customers receive 30 days' notice before any new sub-processor is added. To subscribe to change notifications, email trust@pencilspaces.com.
Customers can choose Return, Delete, or Archive at termination. Data export is delivered within 14 days via signed S3 link. Cryptographic erasure is completed within 30 days. A signed deletion certificate is issued by our Head of Trust. Backups age out within an additional 60 days. Full detail at Data Lifecycle.
Pencil Spaces has had no reportable customer data breaches to date. When a production incident occurs, a full post-mortem is published in the incidents section within five business days, with root cause, customer impact, and remediation.
Email trust@pencilspaces.com with your organization name. We will return a mutual NDA via DocuSign and the SOC 2 report — typically within one business day. The report is also bundled into our Customer Assurance Package with all related artifacts.
Swati Khandelwal, Chief Operating Officer and Head of Trust, owns Pencil Spaces' compliance, security, and operational posture. Privacy reviews, audit response, customer security questionnaires, and vendor risk assessments all route through her. Direct contact: swati.khandelwal@pencilspaces.com. See the People section for full accountability.
Submit reports to security@pencilspaces.com. We acknowledge new reports within one business day, triage within five, and treat coordinated disclosure as a partnership. Researchers acting in good faith are protected from legal action. See full vulnerability disclosure policy.
Coordinated disclosure
If you have found a vulnerability, write to security@pencilspaces.com. We acknowledge new reports within one business day, triage within five, and treat coordinated disclosure as a partnership — not a legal threat. Researchers acting in good faith have our full safe-harbor commitment.
Self-serve through the Trust Vault, or write to a real human.