Production telemetry and historical uptime are published continuously on our status page.
Real-time uptime & latency: see status.pencilspaces.com
Live control evidence: see Trust Vault
No reportable downtime
All services nominal
Pen test · independent third party
The place to request our security and compliance documents. Tell us who you are and what you need, and we will share the relevant documents.
These are confidential documents, so we do not post them publicly. Fill out the short form, and we will confirm your request and send them to you. Most requests are answered within one business day.
One short form. No account needed.
Some documents are shared under NDA.
SOC 2 Type II report
✓ LiveISO 27001 status letter
✓ LivePenetration test summary
✓ LiveBAA, DPA, and NDPA
✓ LiveCertificate of insurance
✓ LiveSecurity controls summary (CAIQ-Lite)
✓ LiveSub-processor list
✓ LivePencil Spaces is audited or certified against nine regulatory and industry frameworks. Each row below maps to a specific federal regulation, attestation, or industry standard. Reports are available upon request, generally under a mutual NDA.
We operate as a school official under the school-official exception. No advertising and no student profiling under any condition.
Verifiable parental consent flows. No third-party tracking on accounts identified as belonging to a minor. K–12 safe by default.
Type II report covering Trust Services Criteria, attested annually by an independent CPA firm. Available under mutual NDA on completion.
EU data residency available on request. Pre-signed Data Processing Agreement with current Standard Contractual Clauses.
Business Associate Agreement available on request. Protected Health Information is encrypted at rest and in transit. Audit logs are retained for six years.
All California consumer rights are honored end-to-end. The verified-request portal is available within five business days.
Information Security Management System aligned to ISO 27001 controls; surveillance and certification work is in progress with our certification body.
Signatory to the National Data Privacy Agreement (NDPA) through the Student Data Privacy Consortium. Active in multiple state alliances.
Application security is independently lab-tested and lab-verified against the OWASP ASVS v4.0 standard.
We do not feed your students’ video, audio, whiteboard, or chat content into any AI model. We do not use customer data to train, fine-tune, or evaluate AI of any kind. This is contractual and survives termination.
Where AI features exist, they are clearly labeled, configurable at the account level, and disabled by default for K–12 customers.
A complete list of any AI systems with access to production is included in the Customer Assurance Package and reviewed during our SOC 2 audit cycle, including scope, controls, and audit-log paths. Material changes are published in the compliance changelog with thirty days’ notice.
If you have found a vulnerability, write to security@pencilspaces.com. We acknowledge new reports within one business day, triage within five, and treat coordinated disclosure as a partnership. Researchers acting in good faith have our full safe-harbor commitment.
Self-serve through the Trust Vault, or write to a real human.