Security & Compliance

Built to meet the bar schools require.

FERPA- and COPPA-conscious by design. Encrypted in transit and at rest. Hosted in the US. Here's exactly how we protect your school and your families.

FERPA & COPPA Compliance

  • Ebby is designed from the ground up to comply with FERPA (Family Educational Rights and Privacy Act) and COPPA (Children's Online Privacy Protection Act).
  • We do not collect, store, or process student education records. Ebby operates at the prospective-family and admissions inquiry level — not the enrolled-student level — so FERPA obligations do not apply to the data Ebby handles.
  • Ebby does not knowingly collect personal information from children under 13. Our guided flows are designed for parents and guardians, not minor students.

Data Encryption

  • All data transmitted between families, Ebby, and your school is encrypted in transit using TLS 1.2+.
  • Data at rest is encrypted using AES-256, the same standard used by banks and healthcare providers.
  • API keys and credentials are stored in a secrets manager — never in plaintext or version control.

Hosting & Infrastructure

  • Ebby is hosted on AWS infrastructure in the United States, with redundancy across multiple availability zones.
  • We do not sell, share, or license your school's data or your families' data to any third party.
  • Your school's content and conversation data are logically isolated from other schools' data.

Data Retention & Access

  • Conversation data is retained to power your lead dashboard and analytics. You can request deletion of any record at any time.
  • Only your authorized school staff (and Ebby support staff under NDA) can access your school's conversation data.
  • We provide a Data Processing Agreement (DPA) upon request for schools that require one.

Incident Response

  • We maintain a written incident response plan and will notify affected schools within 72 hours of a confirmed data breach.
  • Our platform is monitored 24/7 for anomalous access patterns, and we perform regular third-party security reviews.

Have a specific compliance question?

We're happy to provide a Data Processing Agreement, answer IT security questionnaires, or walk your team through our architecture.

Contact us