Security Overview
Pearl Education (Trilogy Mentors Inc., DBA Pearl) maintains a written information security program designed to protect Customer Content, including Student Data, across the Pearl Products. This page summarizes that program in plain language for district, SEA, and parent evaluators. The binding commitments are in our Master Service Agreement (MSA) and Student Data Privacy Exhibit (DPA); we cite the relevant sections throughout.
Information Security Program
Pearl maintains a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of Customer Content, and commits not to materially diminish that program during a customer’s Service Period (MSA §4.3; DPA §6.1).
Frameworks and Standards
Pearl’s security program is audited against SOC 2 (Security / Common Criteria) and uses the CIS Amazon Web Services (AWS) Foundations Benchmark, monitored through AWS Security Hub. The program is aligned with the NIST Cybersecurity Framework (CSF). Pearl is also pursuing the Access 4 Learning (A4L) GESS self-assessment.
Authentication and Multi-Factor Authentication
Product authentication is available through Google single sign-on (SSO) and email and password, with roster-based sign-in through Clever and Edlink. Multi-factor authentication (MFA) operates as a shared responsibility:
- Pearl enforces MFA for its own corporate-identity, source-code, and production-system access (Google Workspace SSO and AWS IAM).
- Customer-side MFA is delivered through the customer’s own SSO identity provider (for example, Google) and is controlled by the customer.
- Accounts that sign in with email and password do not currently have native MFA; this is on Pearl’s roadmap.
Encryption
Customer Content is encrypted in transit using TLS and at rest using AES-256 (MSA §4.3; DPA §6.2). Account passwords are stored salted and hashed, and Customer Content is not stored on employee devices.
Access Controls and Tenant Isolation
Pearl applies role-based, least-privilege access controls so that personnel can access only the data they need to deliver the Services (MSA §4.3; DPA §6.2). The Products are multi-tenant, with logical isolation between customers enforced through application-level role-based access controls (RBAC).
Logging and Monitoring
Pearl monitors and logs its production systems using AWS GuardDuty, AWS Security Hub, Amazon CloudWatch, and Elastic for centralized logging (DPA §6.2).
Secure Development
Pearl follows a secure software development lifecycle (DPA §6.2). Code changes require pull-request review and approval; development, test, and production environments are kept separate; static analysis is performed with SonarCloud; dependencies are monitored with GitHub Dependabot; infrastructure is managed as code with AWS CDK; and API and infrastructure activity is recorded with AWS CloudTrail.
Vendor and Subprocessor Risk Management
Pearl operates a vendor risk-management process (DPA §6.2). Subprocessors that process Customer Content are bound by obligations no less protective than our agreements, and Pearl remains responsible for their performance; the current list is available on request (MSA §4.4; DPA §2.5). See the Subprocessors page for details.
Personnel Security and Training
Access to Student Data is limited to personnel who need it to perform the Services, who are bound by confidentiality obligations and trained on federal and state student-privacy requirements before access (DPA §4.3). Personnel also receive security training (MSA §4.3), and Pearl provides annual FERPA training to staff. Pearl conducts background screening of employees and contractors.
Independent Assessment and Testing
Pearl has completed a SOC 2 Type I examination covering the Security (Common Criteria) category; the report is available under NDA on reasonable request (MSA §4.3; DPA §6.1). A SOC 2 Type II examination is planned. Pearl’s policy is an annual independent third-party penetration test; the 2026 test, conducted by Astra, is scheduled for the second half of 2026.
Documentation Available on Request
Under NDA, Pearl will make available its then-current third-party assurance report, a summary of its security controls, and completed security questionnaires reasonably required by a customer’s policies or state law (MSA §4.3; DPA §6.1). To request security documentation, contact seccom@poweredbypearl.com.
