EdTech Data Safety & Evidence Label
Select a vendor
Choose a product to review its weighted screening signal.
Vendor representative? Select your product in the list to request access.
The score combines five weighted screening factors.
District review format
Data Safety Facts
Product profileSelect a vendor to see provisional data categories.
Unknown controls lower confidence, not maturity.
Weighted screening model
Vendor risk matrix
The five weighted risk inputs produce a raw safety score. A neutral product starts at 50. Net gains above the old 53-point neutral score are doubled; net shortfalls below it retain their previous point-for-point effect.
Unknown security controls are neutral and reduce confidence rather than the Safety Score. Verified negative findings create penalties.
Data Sensitivity rating
Show how harmful the exposed data could be.
Six components measure intrinsic sensitivity and controllable exposure. This is already a risk score, so its contribution is Data Sensitivity Score x 30%. Sensitive-purpose products are not treated as careless when they minimize and tightly manage exposure.
Intrinsic sensitivity describes the data itself; exposure management describes how narrowly it is collected, retained, identified, and shared.
Unknown inventory fields are shown as unknown and receive a conservative provisional risk value.
Security Maturity rating
Measure security capability, not just stated compliance.
Seven security domains measure underlying maturity separately from evidence coverage. The risk model converts the positive score using (100 - Security Maturity Score) x 25%. UpGuard supplies external observable evidence for one 10% security subdomain; it does not replace verified internal controls.
No security evidence has been assessed.
Unknown controls use a neutral maturity baseline and reduce evidence coverage. Only verified negative evidence creates a penalty.
Vendor progression ladder
A realistic public-evidence roadmap.
Security and privacy pages, security.txt, contacts, retention and deletion policy, subprocessors, AI-use statement, breach commitment, and a standard DPA.
Trust center, MFA and encryption summaries, vulnerability disclosure, penetration-test summary, continuity, secure-development, and incident-response overviews.
SOC 2 or ISO where feasible, current penetration testing, formal risk management, third-party posture signals, and auditable deletion controls.
SOC 2 and ISO raise confidence but are not the only route to a strong rating. Technical documentation, verified controls, credible attestations, and observable evidence can also support maturity.
Authoritative starting points
Security source library
Compliance rating
Score the quality, scope, and currency of K-12 evidence.
Compliance measures known contract and control quality. Unverified items remain neutral; reviewed positive or negative evidence changes the score. The risk model converts it using (100 - Compliance Score) x 20%.
Public references are starting evidence, not proof that the district's product and contract are in scope.
Vendor transparency rating
See the evidence behind the score.
Evidence points reward information that is available for review. Transparency risk is calculated as 100 minus evidence points, then contributes 15% of the composite vendor risk score. UpGuard can corroborate external observations but does not replace vendor-published transparency evidence.
Vendor-submitted evidence remains provisional until a district reviewer verifies it.
Incident History rating
Document events, context, and response quality.
Incident risk uses verified events, not rumors. UpGuard changes may create a review lead, but authoritative notices and corroborated records determine this score. Each event is scored for severity, scope, affected data, root cause, response, regulatory action, repeat history, and recency before contributing 10% of composite vendor risk.
Calculation backup
How incident risk is calculated
No incident records have been added for this vendor.
Official starting points
Incident source library
What supports this label
Evidence register
Select a vendor to inspect evidence and gaps.