Pearl Compliance Overview
Pearl Education (Trilogy Mentors Inc., DBA Pearl) builds student-support products for K-12 school districts, charter schools, local and state education agencies, and the programs that serve them. Because our customers are schools, Pearl’s compliance posture is built around U.S. K-12 student-privacy law and the commitments in our Master Service Agreement (MSA) and Student Data Privacy Exhibit (DPA). This page summarizes that posture and links to Pearl’s detailed compliance pages.
How Pearl Handles Student Data
Pearl processes student data only to provide the Services, at the school’s direction, and as permitted by the MSA and DPA. As bright-line commitments, Pearl will not sell student data, will not use it for targeted or behavioral advertising directed at students, and will not build or sell commercial student profiles except as needed to provide the Services (MSA §5.7; DPA §4.2). Pearl may use de-identified and aggregated data for research, benchmarking, and service improvement consistent with its agreements (MSA §6).
FERPA — School Official Model
Pearl provides its Services as a “school official” with a legitimate educational interest under FERPA (34 C.F.R. §99.31(a)(1)). The school designates Pearl as a school official, retains direct control over student data, and authorizes Pearl to use that data solely to provide the Services. Pearl follows FERPA’s limits on re-disclosure (34 C.F.R. §99.33(a)) (MSA §5.3; DPA Art. I and IV).
COPPA — Children Under 13
COPPA applies to children under 13. For those users, consent responsibility sits with the school or customer, not with Pearl. The school either provides the required disclosures and obtains parental consent, or determines that consent may be provided through the school consistent with FTC guidance, and authorizes Pearl to collect that information on the school’s behalf solely for educational purposes. At the school’s request, Pearl can make in-product mechanisms available to obtain and record verifiable parental consent (MSA §5.4–5.5).
PPRA
Pearl supports customers’ obligations under the Protection of Pupil Rights Amendment (PPRA). Both parties commit to comply with their respective obligations under FERPA, PPRA, COPPA, and applicable state student-privacy laws (MSA §5.4; DPA Art. I).
State Student-Privacy Laws
Pearl is prepared to meet state-specific student-privacy requirements and to sign state-required addenda. See State Privacy Law Posture for major laws such as New York Education Law §2-d, Illinois SOPPA, and California SOPIPA, and NDPA and State Addenda for how Pearl executes district, state, and national data-privacy agreements.
SOC 2 and Security Frameworks
Pearl maintains a written information security program with administrative, technical, and physical safeguards, including encryption in transit (TLS) and at rest (AES-256) and least-privilege access controls (MSA §4.3; DPA §6.1). Pearl has completed a SOC 2 Type I examination covering the Security (Common Criteria) trust services category; the report is available under NDA on request. A SOC 2 Type II examination is planned. Pearl’s program is also assessed against the CIS Amazon Web Services (AWS) Foundations Benchmark (monitored through AWS Security Hub) and is aligned with the NIST Cybersecurity Framework (CSF), and Pearl is pursuing the Access 4 Learning (A4L) GESS self-assessment. Pearl’s policy is to perform an annual independent third-party penetration test; the next test is scheduled for the second half of 2026. Pearl will make its then-current assurance reports and security documentation available under NDA upon a customer’s reasonable request (MSA §4.3; DPA §6.1).
How Districts Request Documentation
Districts and agencies evaluating Pearl can request, under NDA where applicable:
- Pearl’s SOC 2 Type I report and a summary of security controls, under NDA.
- The list of subprocessors that process Customer Content (MSA §4.4; DPA §2.5).
- Completed security questionnaires reasonably required by the customer’s policies or state law (DPA §6.1).
- A signed DPA, or execution of a state or national NDPA (see NDPA and State Addenda).
Submit documentation requests through your Pearl account contact. Privacy and student-data questions can be directed to privacy@poweredbypearl.com, security matters to seccom@poweredbypearl.com, and legal notices to legal@poweredbypearl.com.
Related Compliance Pages
- Privacy Commitments & Frameworks — Pearl’s NDPA commitments and the CISA K-12 Secure by Design Pledge.
- NDPA and State Addenda — Pearl’s bilateral DPA and executed NDPAs.
- State Privacy Law Posture — New York, Illinois, California, and other state laws.
