Showing results for type2

1. Service Overview

As a provider of technology solutions to schools, Amplify’s commitment to data privacy and security is essential to our organization. This overview of Amplify’s Information Security Program describes physical, technical and administrative safeguards Amplify implements to protect student data in our care.

Company profile

Amplify Education, Inc. (Amplify) is a privately held company founded in 2000 as Wireless Generation. Amplify’s products include curriculum and instruction, assessment and intervention, professional development services and consulting services for K-12 education.

Service hosting

Amplify leverages Amazon Web Services (AWS) as its cloud hosting provider. Within AWS, Amplify utilizes Virtual Private Clouds (VPCs), which provide an isolated cloud environment within the AWS infrastructure. External network traffic to a VPC is managed via gateway and firewall rules, which are maintained in source code control to ensure that the configuration remains in compliance with Amplify security policy. In addition, the production VPCs and the development VPCs are isolated from each other and maintained in separate AWS accounts.

2. Policies & standards

Information security program

Amplify maintains a comprehensive information security program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the NIST SP 800-53 Rev. 5 family of information security controls. These provide a robust framework of best practices from which an organization can build its security policies and protocols based on identified risks, compliance requirements, and business needs. They cover critical practice areas, including access control, configuration management, incident response, security training, and other information security domains.

Governance

Amplify’s Information Security Committee has primary responsibility for the development, maintenance, and implementation of the Amplify information security program. The Information Security Committee is responsible for all information risk management activities within the company and is composed of technology, business and legal leaders from the organization. The Committee meets weekly and includes a dedicated VP of Information Security and a program manager to oversee, direct and coordinate its activities.

Policy execution

Adherence to the internal Amplify information security policy is an obligation of every Amplify employee. Amplify conducts a series of internal monitoring procedures to verify compliance with internal information security policies, and all Amplify employees undergo annual criminal background checks. In addition, any third-party contractors who come into contact with systems that may contain student data are contractually bound to maintain security and privacy of the data.

3. Data access controls

Access control

Amplify’s access control principles dictate that all student data we store on behalf of customers is only accessible to district-authorized users and to a limited set of internal Amplify users who may only access the data for purposes authorized by the district. Districts maintain control over their internal users and may grant or revoke access.

In limited circumstances and strictly for the purposes of supporting school districts and maintaining the functionality of systems, certain Amplify users may access Amplify systems with student data. All such access to student data by Amplify technicians or customer support requires both authentication and authorization to view the information.

Encryption

Data encryption is an important element of our protection of sensitive data at rest and in transit, and is reviewed and updated as appropriate annually, based on the latest standards and guidelines published by OWASP and NIST.

  • In transit: Amplify encrypts all student data in transit over public connections, using Transport Layer Security (TLS), commonly known as SSL, using industry-standard protocols, ciphers, algorithms, and key sizes.
  • At rest: Amplify encrypts student data at rest using the industry-standard AES-256 encryption algorithm.

4. Application security by design

Building the right roles into applications

Permissions within Amplify applications are designed on the principle that school districts control access to all student data. To facilitate this, Amplify applications are designed so that roles and permissions flow from the district to the individual user. For example, applications that offer schools a way to collect and report on assessment results have a web interface that requires district administrators to authorize individuals to view student data.

Security controls within applications are used to ensure that the desired privacy protections are technically enforced within the system. For example, if a principal is supposed to see only the data related to his or her school, Amplify ensures that, throughout the design and development process, our products restrict principals from seeing records for any students outside his or her school.

To make sure Amplify applications properly enforce permissions and roles, our development teams conduct reviews early in the design process to ensure roles and permissions are an essential component of the design of new applications.

Building security controls into applications

Amplify applications are also developed to minimize security vulnerabilities and ensure industry-standard application security controls are in place.

As part of the development process, Amplify has a set of application security standards that all applications handling student data are required to follow, including:

  • Student data is secured using industry standard encryption when in transit between end-users and Amplify systems.
  • Applications are built with password brute-force attack prevention.
  • User sessions expire after a fixed period of time.

We also conduct manual and automated static code analysis as well as dynamic application security testing to preemptively identify vulnerabilities published by industry leaders such as OWASP (Open Web Application Security Project)

5. Proactive security

Risk assessments

Amplify periodically engages a security consulting firm to conduct risk assessments, aimed at identifying and prioritizing security vulnerabilities. The Information Security Committee coordinates remediation of the vulnerabilities. The security consulting firm also provides ongoing advice on current risks and advises on remediation of vulnerabilities and incident response.

Penetration testing

Amplify engages third-party firms to continually conduct application penetration testing.  The purpose of this testing is to test for application security vulnerabilities in the production environment.  We work with third party penetration testing program partners. Third-party testing involves a combination of automated and manual testing.

Vulnerability management

Amplify ensures that its systems are free of known vulnerabilities in several ways. Every production server runs vulnerability detection software that compares the installed software against a global database of known vulnerabilities. Secondly, we employ real time network monitoring that reports on any potentially malicious traffic. In addition, a third-party security firm continually reviews all of our system logs for potential security breaches. Lastly we continually test our applications against common malicious internet traffic. Violations in any of these areas will alert one of our operations teams, who are available around the clock.

In addition, Amplify participates in a private bug bounty program through HackerOne, working with the security community to find security vulnerabilities and support our efforts to keep our data and systems safe and secure.

Endpoint security

Access to production systems at Amplify is restricted to a limited set of internal Amplify users to support technical infrastructure, troubleshoot customer issues, or other purposes authorized by the district. In addition, Amplify requires multi-factor (MFA) authentication methods for access to all production systems. MFA involves a combination of something only the user knows and something only the user can access. For example, MFA for administrative access could involve entering a password as well as entering a one-time passcode sent via text message to the administrator’s mobile phone. The use of MFA reduces the possibility that an unauthorized individual could use a compromised password to access a system.

Infrastructure security

Network filtering technologies are used to ensure that production environments with student data are properly segmented from the rest of the network. Production environments only have limited external access to enable customers to use our web interfaces and other services. In addition, Amplify uses firewalls to ensure that development servers have no access to production environments.

Other measures that Amplify takes to secure its operational environment include system monitoring to detect anomalous activity that could indicate potential attacks and breaches.

Security training

At Amplify, we believe that protecting student data is the responsibility of all employees. We implemented a comprehensive information security awareness training program that all employees  undergo upon initial hire, with an annual refresher training. We also provide information security training and annual social engineering tests for specific departments based on role.

6. Reactive security

Monitoring

Intrusion detection and prevention systems (IDS/IPS) are in place to analyze the network device logs, monitor the network and report anomalous activity for appropriate resolution.

Incident response

Amplify maintains a comprehensive Security Incident Response Policy Plan, which sets out roles, responsibilities and procedures for reporting, investigation, containment, remediation and notification of security incidents. Amplify works with reputable firms for incident response and digital forensics support, as well as annual table-top exercises in coordination with cybersecurity experts.

Business Continuity Planning and Disaster Recovery

Amplify maintains a comprehensive Business Continuity Planning and Disaster Recovery Plan (BCP/DR), to guide personnel in procedures to protect against business disruptions caused by an unexpected event. The plans and related operations processes are tested on a semiannual basis, with ensuing operations improvement and remediation work.

7. Compliance

Audits

In addition to penetration testing and other proactive security testing and monitoring outlined above, Amplify undergoes annual SOC 2 Type 2 examinations of controls relevant to security. The examination is formally known as a Type 2 Independent Service Auditor’s Report on Controls Relevant to Security. The most recent examination was conducted by Schellman & Company, LLC and covers the period from April 1, 2024–March 31, 2025. The report states that Amplify’s systems meet the criteria for the security principle and opine on management’s description of the organization’s system and the suitability of the design of controls to protect against unauthorized access, use, or modification.

The Type 2 report also opines on the operating effectiveness of controls over the review period. This means that our auditors confirmed that we have continued to follow established security controls over the period of time of the review.

Certifications

SOC 2: Amplify successfully completed the SOC 2 Type 2 examination of controls relevant to security (see above, under “Audits”).

Privacy

Amplify’s products are built to facilitate district compliance with applicable data privacy laws, including FERPA and state laws related to the collection, access and review and disclosure of student data. Amplify’s Customer Privacy Policy describes the types of information collected and maintained on behalf of our school district customers and limitations on use and sharing of that data.

8. Supporting documentation

In the course of customer security assessment, the following documentation can be provided by Amplify upon customers’ request:

  • Penetration Testing Report
  • Risk Assessment Report
  • SOC 2 Type 2 Report

9. Report a vulnerability

To report a security vulnerability, click here.

Core Principles:

These core principles guide our operations, employee behavior and product development:

  • Customer Control: We help school districts securely manage their personally identifiable student information. The districts direct our use of the data, and control who has access to that data and with whom it is shared.
  • Educational Purpose: Personal student information can only be used for customer-authorized purposes to support student learning through the secure and effective operation of our educational tools. 
  • Transparency: School districts, teachers, parents and students have the right to know what information is collected by school technology, how it is used and by whom, as clearly described in our privacy policy.
  • Commitment: Privacy and security are thoroughly embedded into our organizational practices. We dedicate substantial resources to systems, processes and personnel required to protect student information.

Amplify Data Privacy and Security Practices:

Amplify maintains a customer data privacy policy that explains our data collection, handling and use practices. 

Amplify also maintains a data security policy that explains how student data is protected from unauthorized access.  Data security practices at Amplify are developed and maintained in accordance with the internationally recognized ISO27002 security standards.  In addition, Amplify has successfully completed the SOC 2 Type 2 examination of controls relevant to security and conducts such examination on an annual basis. 

For more information, please review our customer privacy policy and security practices. If you have additional questions, please contact us at privacy@amplify.com.  

State Law Compliance

Amplify has entered into Data Privacy Agreements (DPAs) with districts across the country to facilitate compliance with applicable laws governing student data privacy. These DPAs can be applied to any Amplify product.

Unless otherwise noted, the DPAs are based on the Student Data Privacy Consortium’s (SDPC) model agreement which was created to simplify the contracting process between providers and local education agencies (LEAs) while ensuring LEAs have the necessary data protection obligations in place with providers. For additional information please visit the SDPC website and select your state.

General Offer of Privacy Terms:
To expedite your district’s need for a DPA and streamline the contracting process, we have compiled the following DPAs, listed by state.

By executing the General Offer of Privacy Terms, your LEA can “piggy back” off an existing DPA that other LEAs in your state have already agreed to. If you do not see your state below, please contact privacy@amplify.com.

Instructions: 
(i) Please download the General Offer of Privacy Terms, (ii) sign and send the executed copy to your Amplify account representative, and (iii) retain a copy for your records. If you have any questions please reach out to privacy@amplify.com.

*Please note, states marked with an asterisk do not have a General Offer of Privacy Terms; however, please review the instructions below on how to quickly implement a DPA in compliance with your LEA’s state law.

Arizona: To enter into Amplify’s AZ-NDPA-V1, please sign the General Offer of Privacy Terms

Arkansas: To enter into Amplify’s AR-NDPA-V1, please sign the and General Offer of Privacy Terms

California: To enter into Amplify’s CA-NDPA, Version 1.5, please sign the General Offer of Privacy Terms

Connecticut*
To facilitate your district’s compliance with the requirements of Connecticut’s student data privacy law (Connecticut General Statutes §§ 10-234aa through 10-234dd), Amplify is proud to offer our “Connecticut Terms of Service Addendum” linked below. This Addendum supplements Amplify’s Terms and Conditions for use of Amplify products licensed by the district available at https://amplify.com/customer-terms.
Addendum: Connecticut Terms of Service Addendum
Instructions: Please retain a copy for your records – no further action is required.

Florida: To enter into Amplify’s FL-NDPA, Version 1.0, please sign the General Offer of Privacy Terms

Hawaii*
Amplify has entered into a Data Sharing Agreement with the Hawaii State Department of Education (HIDOE) which applies to any LEA associated with HIDOE. If your LEA is not a part of the HIDOE and you require a data privacy agreement, please reach out to privacy@amplify.com.

Illinois: To enter into Amplify’s IL-NDPA (which includes the IL State Supplemental Terms), please sign the General Offer of Privacy Terms

Iowa: To enter into Amplify’s IA-NDPA (which includes the IA State Supplemental Terms), please sign the General Offer of Privacy Terms

Maine: To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the ME State Supplemental Terms), please sign the General Offer of Privacy Terms 

Massachusetts: To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the MA State Supplemental Terms), please sign the General Offer of Privacy Terms

Missouri: To enter into Amplify’s MO-NDPA, Version 1.0, please sign the General Offer of Privacy Terms

Montana: To enter into Amplify’s MT DPA, Version 3, please sign the General Offer of Privacy Terms

Nebraska: To enter into Amplify’s NE NDPA (which includes the NE State Supplemental Terms), please sign the General Offer of Privacy Terms

New York*
Option 1:
To facilitate your district’s compliance with the requirements of New York State Education Law § 2-D and regulations promulgated thereunder, Amplify is proud to offer our “New York Data Privacy and Security Addendum” linked below. This Addendum supplements Amplify’s Terms and Conditions for use of Amplify products licensed by the educational agency available at https://amplify.com/customer-terms.
Addendum: New York Data Privacy and Security Addendum
Instructions: Please retain a copy for your records- no further action is required.
Option 2:
To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the NY State Supplemental Terms), please sign the General Offer of Privacy Terms

New Hampshire: To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the NH State Supplemental Terms), please sign the General Offer of Privacy Terms

North Carolina*
The Data Confidentiality and Security Agreement issued by the North Carolina Department of Public Instruction (NCDPI) is not applicable to Amplify’s services given Amplify does not have a direct integration to any state system via API/plugin. You can review the NCDPI guidance here: https://www.dpi.nc.gov/about-dpi/technology-services/third-party-data-integration. However, Amplify can sign this form with some revisions. As such, we have prepared an Addendum which supplements the Data Confidentiality and Security Agreement.
Instructions: Please download a copy of the Data Confidentiality and Security Agreement with Amplify Addendum, return an executed copy to your account executive, and retain a copy for your records.

Ohio: To enter into Amplify’s OH-NDPA Version 1.0, please sign the General Offer of Privacy Terms

Oregon: To enter into Amplify’s OR-NDPA-V1, please sign the General Offer of Privacy Terms

Rhode Island: To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the RI State Supplemental Terms), please sign the General Offer of Privacy Terms

Tennessee: To enter into Amplify’s TN-NDPA-V1, please sign the General Offer of Privacy Terms

Texas: To enter into Amplify’s TX-NDPA-V1R6, please sign the General Offer of Privacy Terms

Utah: To enter into Amplify’s UT-NDPA, Version 1, please sign the General Offer of Privacy Terms

Vermont: To enter into Amplify’s MA-ME-MO-NH-NY-OH-RI-VT DPA, Version 1 (which includes the VT State Supplemental Terms), please sign the General Offer of Privacy Terms

Virginia: To enter into Amplify’s VA-DPA, please sign the General Offer of Privacy Terms

Washington: To enter into Amplify’s WA-NDPA, Version 1, please sign the General Offer of Privacy Terms

Wisconsin: To enter into Amplify’s WI SDPA, Version 1, please sign the General Offer of Privacy Terms

Wyoming: To enter into Amplify’s WY-NDPA-V1, please sign the General Offer of Privacy Terms