Compliance

Is Clema SOC 2 and FERPA compliant?

Yes. Here is our audit history, certification status, and access-control model, the detail your security team will want. For where your data is hosted and how it flows during a query, see the data residency page.

The short answer

Clema holds a SOC 2 Type II certification, audited annually plus quarterly vulnerability scans and annual penetration testing, and is FERPA-ready by design. We act as a school official with a legitimate educational interest, sign BAAs with every customer, gate access with role-based controls and MFA, and commit to notifying customers within 72 hours of a security incident.

SOC 2 Type IISOC 2 Type II
FERPA CompliantFERPA

SOC 2 Type II

Certified

Audited annually for security, availability, and confidentiality, plus quarterly vulnerability scans and annual penetration testing.

FERPA

Ready by design

School-official framework, role-based access with MFA, BAAs signed with every customer, full audit trail.

Audit, access control, and incident response

This is the certification and access-control side of our program. For hosting location and how data flows during a query, see data residency.

Access controls that gate every query

Role-based access control, multi-factor authentication, unique user IDs, and session timeout policies. Access is granted on a need-to-know basis and every access event is logged and audited.

Encryption at rest and in transit

Data is encrypted at rest with AES-256 and in transit with TLS 1.3, so it is protected whether it is sitting in storage or moving between systems.

Vetted employees, monitored access

All employees undergo background checks and security training before they can touch customer data, and access is strictly limited on a need-to-know basis.

A 72-hour incident notification commitment

We maintain a documented incident response plan and notify affected customers within 72 hours of a security incident. Our team is available around the clock to respond.

What your security team can request

Most institutions ask for these during vendor review. We turn them around in one business day.

SOC 2 Type II report (under NDA)
Business Associate Agreement (BAA)
Access control and audit log overview
Incident response summary
Penetration test attestation

Compliance
FAQs

Yes. Clema holds a SOC 2 Type II certification. Our infrastructure and processes are independently audited every year against the trust service criteria for security, availability, and confidentiality, alongside quarterly vulnerability scans and annual penetration testing by independent security firms. We share the full report under NDA on request to [email protected].

Yes. Clema is built for FERPA from the ground up. We act as a school official with a legitimate educational interest, enforce role-based access controls with multi-factor authentication and unique user IDs, and sign BAAs with every customer. Every answer includes source attribution and a full query audit trail.

Role-based access control, multi-factor authentication, unique user IDs, and session timeout policies. Access is granted on a need-to-know basis tied to job responsibilities, every access event is logged, and those logs are reviewed as part of our audit trail.

We maintain an incident response plan and notify affected customers within 72 hours of a security incident. Our team is available around the clock to respond to security concerns.

No. Clema never uses your institutional data to train its models, and your data is never sold, shared, or disclosed to third parties. For how data flows during a query and where it is hosted, see the data residency page.

Email [email protected] and our security team will share the SOC 2 Type II report and BAA under NDA, usually within one business day. We can also schedule a call with your CISO or security review team.

Need the compliance pack?

Our security team will share the SOC 2 Type II report and BAA under NDA, usually within one business day.

Email security teamRead the security overview