Beni
SOC 2 Compliant

Privacy & Security

SOC 2 compliant. FERPA aligned. COPPA compliant. Student data is never sold, shared, or used to train AI models.

SOC 2 Compliant
Independently verified security controls
FERPA Aligned
School official designation
COPPA Compliant
Under-13 protections enforced
DPA Ready
SDPC National DPA compatible

What We Promise Every District

Six commitments that govern how Beni handles student data. These are not aspirational. They are contractual.

01
Student Data Is Never Sold

Beni does not sell, rent, or share student data with third parties for advertising, marketing, or any commercial purpose. Period.

02
No AI Model Training on Student Data

Student inputs, responses, and interactions are never used to train, fine-tune, or improve any AI model, whether ours or a third party's.

03
District Owns the Data

Your district retains full ownership of all student and staff data at all times. Beni is a data processor, not a data owner. Upon termination, all district data is returned or deleted at your direction.

04
Minimum Data Collection

We collect only the data necessary to provide the service. We do not collect student social security numbers, biometric data, or financial information.

05
SOC 2 Compliant

Beni has achieved SOC 2 compliance, independently verified. Our security controls cover data encryption, access management, availability, and incident response.

06
Transparent by Default

District administrators can see exactly what data Beni collects, who has access, and how it is used. Audit logs are available on request.

FERPA, COPPA, and State Privacy Laws

Beni is built for the regulatory environment K-12 districts operate in.

FERPA (Family Educational Rights and Privacy Act)

Beni is designed to operate as a "school official" under FERPA, meaning we access student education records only to provide the services contracted by the district. We implement role-based access controls so only authorized school personnel can view student data. We do not disclose personally identifiable information from education records to any third party without prior written consent from the district.

COPPA (Children's Online Privacy Protection Act)

For students under 13, Beni operates under the school's authorization as permitted by COPPA. We do not collect more personal information than is reasonably necessary. We do not enable public-facing profiles or communications for students under 13. Districts can review and request deletion of any student's data at any time.

State Student Privacy Laws

Beni is designed to comply with state student privacy laws including but not limited to California SOPIPA, New York Education Law 2-d, Colorado Student Data Transparency and Security Act, Illinois SOPPA, and Connecticut PA 16-189. We sign Student Data Privacy Agreements (SDPAs) aligned with the Student Data Privacy Consortium national template.

Data Privacy Agreements

Beni will sign your district's DPA, the SDPC National DPA, or a mutually agreed-upon data privacy agreement before any student data is processed. We do not access student data until a signed agreement is in place.

Contact info@benieducation.com to initiate the DPA process.

How We Protect Your Data

District data is encrypted, access-controlled, and deletable on request. Details on what we collect are in the Privacy Policy below.

Encryption

All data is encrypted in transit using TLS 1.2 or higher. All data is encrypted at rest using AES-256. Encryption keys are managed through industry-standard key management services and rotated regularly.

Access Controls

Beni employees access student data only when necessary to provide technical support, and only with the district's knowledge. All internal access is logged. Background checks are performed on all employees with data access. Access is least-privilege and reviewed quarterly.

Data Retention and Deletion

Districts control data retention periods. Upon written request, all district data is deleted within 30 calendar days. Upon contract termination, all data is deleted within 60 calendar days unless the district requests a data export first. Deletion is confirmed in writing.

Subprocessors

Beni uses a limited set of subprocessors (hosting, email delivery, error monitoring). All subprocessors meet the same data protection standards. A current list is available upon request. Districts are notified before any new subprocessor is engaged.

Security Architecture

Built for the security requirements K-12 districts demand.

Infrastructure

All infrastructure is hosted on SOC 2 compliant cloud providers within the United States. We do not store or process student data outside the US.

Testing and Monitoring

Penetration testing is conducted at least annually by a qualified third party. Vulnerability scans are run continuously. All production systems are patched within 30 days of critical security updates.

Incident Response

In the event of a data breach affecting student data, Beni will notify the affected district within 72 hours of confirmed discovery. Notification includes the nature of the breach, the data affected, steps taken to contain and remediate, and a point of contact. We maintain a documented incident response plan tested annually.

Employee Security

All employees with access to student data undergo background checks, complete security awareness training at hire and annually, and operate under confidentiality agreements.

Privacy and Security FAQ

The questions district technology directors and administrators ask most.

Yes. Beni is designed to operate as a school official under FERPA. We access student education records only to provide contracted services, implement role-based access controls, and do not disclose personally identifiable information without district consent. We sign Data Privacy Agreements before any student data is processed.
No. Beni does not sell, rent, or share student data with third parties for advertising, marketing, or any commercial purpose. Student data is never used to train AI models.
Yes. Beni has achieved SOC 2 compliance, independently verified. Our security controls cover data encryption, access management, system availability, and incident response.
Yes. Beni signs your district's DPA, the SDPC National DPA, or a mutually agreed-upon data privacy agreement before any student data is processed. Contact info@benieducation.com to start the process.
Upon contract termination, Beni provides a full data export upon request and deletes all district data within 60 calendar days. Deletion is confirmed in writing.
Yes. For students under 13, Beni operates under the school's authorization as permitted by COPPA. We do not collect more personal information than necessary, do not enable public-facing profiles for students under 13, and districts can review and request deletion of any student's data at any time.
All student data is stored on SOC 2 compliant cloud infrastructure within the United States. We do not store or process student data outside the US. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Beni notifies affected districts within 72 hours of confirmed discovery. Notification includes the nature of the breach, data affected, containment and remediation steps, and a direct point of contact. We maintain a documented incident response plan tested annually.

Ready to Start the DPA Process?

Beni signs your district's DPA, the SDPC National DPA, or a mutually agreed-upon agreement before any student data is processed.

Request a DPA Apply for Founding Partner