Attendly Trust Center

Attendly provides attendance management solutions for K-12 schools. We're committed to protecting student data and maintaining the highest standards of security and privacy compliance.

Compliance

FERPA

Family Educational Rights and Privacy Act

COPPA

Children's Online Privacy Protection Act

SOPIPA

Student Online Personal Information Protection Act

AB 1584

California Education Code Section 49073.1

CA-NDPA

Signed through CITE (California IT in Education), valid through February 2028

Signatory

NIST CSF

Security controls aligned with the NIST Cybersecurity Framework

Aligned

Controls

Updated February 2026

Data Protection

  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit
  • Encrypted backup storage

Access Security

  • Role-based access controls with per-tenant isolation
  • Secure email/SMS verification with encrypted session tokens
  • Audit logging enabled

Infrastructure Security

  • Google Cloud Platform hosting
  • Web application firewall via Cloudflare
  • DDoS protection

Incident Response

  • Breach notification within 72 hours of confirmation
  • Documented response plan
  • Automated error monitoring and alerting via Sentry

Data Privacy

  • No data selling or targeted advertising
  • No student data profiling
  • 60-day data deletion after contract end

Vendor Management

  • Subprocessor vetting and data processing agreements
  • All student data stored in US-based data centers
  • Subprocessor change notification to districts