Skip to main content
← All legal documents

Security Measures Exhibit

Effective July 24, 2026

INFORMATION SECURITY REQUIREMENTS

This Information Security Exhibit ("Security Exhibit") is incorporated into and forms part of the Master Services Agreement, Order Form, or other agreement between the school, district, institution, homeschool parent, tutor, or other educational organization identified in the applicable Order Form or account registration ("Customer") and SchoolToolz, operating Proctorly ("Provider"), effective as of July 24, 2026 (collectively, the "Agreement").

This Security Exhibit describes the administrative, technical, organizational, and physical safeguards Provider will maintain when providing the Services and processing Customer Data.

Effective Date: July 24, 2026
Last Updated: July 24, 2026

1. Definitions

1.1 Customer Data

"Customer Data" means electronic data, information, files, records, or content submitted to, stored within, transmitted through, or otherwise processed by the Services on behalf of Customer.

Customer Data does not include:

  1. information that has been aggregated or de-identified so that it cannot reasonably identify Customer or any individual;
  2. Provider's administrative, operational, diagnostic, or usage data that does not contain Customer Data; or
  3. information independently obtained by Provider without violation of the Agreement.

1.2 Security Incident

"Security Incident" means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, destruction of, or loss of Customer Data while Customer Data is under Provider's control.

Security Incident does not include:

  1. unsuccessful attempts to access the Services;
  2. network scans, pings, denial-of-service attempts, or similar activities that do not result in unauthorized access to Customer Data;
  3. incidents caused solely by Customer, Customer Users, or Customer-controlled systems;
  4. access authorized by Customer; or
  5. events involving data that was encrypted and for which the encryption key was not compromised.

1.3 Customer User

"Customer User" means an employee, contractor, student, representative, administrator, or other individual authorized by Customer to access the Services.

1.4 Subprocessor

"Subprocessor" means a third party engaged by Provider to process Customer Data in connection with providing the Services.

1.5 Applicable Law

"Applicable Law" means privacy, data protection, cybersecurity, breach-notification, and information-security laws applicable to Provider's processing of Customer Data under the Agreement.

2. Information Security Program

Provider will maintain a written information security program appropriate to:

  1. the nature and scope of the Services;
  2. the size and complexity of Provider's operations;
  3. the nature and sensitivity of the Customer Data processed;
  4. reasonably foreseeable internal and external threats; and
  5. the potential risks presented by unauthorized access, use, disclosure, alteration, loss, or destruction of Customer Data.

Provider's information security program will include reasonable administrative, technical, organizational, and physical safeguards designed to:

  1. protect the confidentiality, integrity, and availability of Customer Data;
  2. protect against reasonably foreseeable threats to Customer Data;
  3. protect against unauthorized access to or use of Customer Data;
  4. detect, respond to, and recover from Security Incidents;
  5. manage security risks associated with Provider personnel and service providers; and
  6. periodically assess the effectiveness of Provider's safeguards.

Provider may update its security program and Security Measures during the term of the Agreement, provided that such updates do not materially reduce the overall protection of Customer Data.

3. Security Governance and Risk Management

Provider will:

  1. assign responsibility for its information security program to appropriately qualified personnel;
  2. maintain documented security policies and procedures;
  3. periodically review and update its security policies;
  4. conduct security risk assessments at least annually;
  5. identify and evaluate material risks affecting the confidentiality, integrity, and availability of Customer Data;
  6. implement reasonable risk-treatment and remediation activities; and
  7. maintain processes for reporting material security risks to appropriate management personnel.

Provider's security program may be based on recognized industry standards or frameworks, including, as appropriate, the NIST Cybersecurity Framework, SOC 2 Trust Services Criteria, ISO/IEC 27001, CIS Controls, or substantially similar frameworks.

For clarity, this provision does not represent that Provider holds a certification or independent audit report unless expressly stated in the Agreement or an Order Form.

4. Personnel Security

Provider will maintain reasonable personnel-security measures, including:

  1. requiring personnel with access to Customer Data to comply with confidentiality obligations;
  2. conducting background screening where appropriate, lawful, and proportionate to the individual's role;
  3. providing security and privacy awareness training at hire and periodically thereafter;
  4. providing role-specific security training to personnel with elevated security responsibilities;
  5. limiting access to Customer Data based on job responsibilities and legitimate business need;
  6. promptly reviewing and removing access following termination or material changes in responsibilities; and
  7. maintaining disciplinary procedures for violations of Provider's security policies.

5. Access Control

Provider will maintain access-control measures designed to prevent unauthorized access to Customer Data.

Such measures will include, as appropriate:

  1. unique user identifiers for Provider personnel;
  2. role-based or least-privilege access;
  3. approval procedures for privileged access;
  4. periodic review of privileged and sensitive access;
  5. prompt revocation of access that is no longer required;
  6. password controls consistent with Provider's security policies;
  7. multi-factor authentication for privileged administrative access and remote access, where the underlying identity provider and tooling support it;
  8. restrictions on the use of shared administrative accounts;
  9. session-management controls; and
  10. logging of material administrative activity.

Provider will not access Customer Data except:

  1. to provide, maintain, secure, or support the Services;
  2. as instructed or authorized by Customer;
  3. to prevent or address technical, security, fraud, or legal issues; or
  4. as required by law.

6. Encryption and Data Transmission

Provider will use industry-standard encryption or equivalent protective measures for Customer Data:

  1. in transit over public networks; and
  2. at rest within Provider-controlled production systems, where technically appropriate.

Unless otherwise stated in an Order Form, Provider's target encryption standards are:

  • TLS 1.2 or higher, or a substantially equivalent protocol, for protected network transmission; and
  • AES-256 or a substantially equivalent method for Customer Data encrypted at rest.

Encryption keys will be managed using access restrictions and key-management procedures appropriate to the nature of the Services.

Provider may use alternative safeguards where encryption is technically infeasible, provided that the alternative safeguards offer a materially comparable level of protection.

7. Application and Software Security

Provider will maintain a software-development process that incorporates reasonable security practices appropriate to the Services.

Such practices may include:

  1. security requirements during application design;
  2. peer review or automated review of material code changes;
  3. separation of development, testing, and production environments;
  4. controls restricting production deployment privileges;
  5. dependency and software-component management;
  6. testing designed to identify common application-security vulnerabilities;
  7. validation of material changes before production deployment;
  8. secure management of credentials, tokens, and secrets;
  9. restrictions on the use of live Customer Data in non-production environments; and
  10. processes for addressing security vulnerabilities.

Provider will not knowingly introduce malicious code into the Services.

8. Vulnerability Management

Provider will maintain a vulnerability-management program that includes, as appropriate:

  1. periodic vulnerability scanning;
  2. monitoring for security advisories affecting material components of the Services;
  3. risk-based classification of identified vulnerabilities;
  4. remediation or mitigation based on severity, exploitability, exposure, and business impact;
  5. patch-management procedures;
  6. penetration testing or comparable technical security testing, targeted at least annually, once the program is operational; and
  7. validation of remediation for material vulnerabilities.

Provider's target remediation timeframes are:

SeverityTarget Remediation or Mitigation
Critical15 calendar days
High30 calendar days
Medium90 calendar days
LowBased on risk and normal development cycles

These are risk-based targets rather than absolute guarantees. Provider may use compensating controls, temporary mitigations, or adjusted timelines where immediate remediation is not reasonably feasible.

Provider is not required to disclose information that could reasonably increase the risk of exploitation of the Services.

9. Infrastructure and Network Security

Provider will maintain safeguards appropriate to the infrastructure used to provide the Services, which may include:

  1. network-access restrictions;
  2. firewalls, security groups, or equivalent traffic-control mechanisms;
  3. logical separation of production and non-production environments;
  4. restrictions on direct access to production systems;
  5. malware-prevention or endpoint-protection measures;
  6. system-hardening and secure-configuration practices;
  7. monitoring for suspicious or unauthorized activity;
  8. centralized logging of material system and security events;
  9. time synchronization for security-relevant systems; and
  10. processes for reviewing material security alerts.

Where Provider uses a third-party cloud infrastructure provider, Provider may rely on that provider's physical, environmental, network, and infrastructure safeguards.

10. Customer Data Segregation

Provider will logically segregate Customer Data from the data of other customers using account controls, tenant identifiers, database controls, access restrictions, or substantially equivalent measures appropriate to the architecture of the Services.

Nothing in this Security Exhibit requires Provider to maintain physically separate hardware, servers, databases, or infrastructure exclusively for Customer unless expressly stated in an Order Form.

11. Logging and Monitoring

Provider will maintain logging and monitoring appropriate to the nature of the Services.

Provider's controls may include:

  1. logging material authentication events;
  2. logging privileged administrative activity;
  3. logging material changes to production systems;
  4. monitoring for suspicious or unauthorized access;
  5. protecting security logs from unauthorized modification;
  6. restricting access to logs;
  7. maintaining alerting processes for material security events; and
  8. retaining audit-action logs for 730 days, and other security-relevant logs according to the applicable platform or Subprocessor retention period, subject to technical, operational, and legal requirements.

Customer-facing audit logs, if available, will be provided according to the functionality and subscription level described in the applicable Order Form or Documentation.

12. Backup, Resilience, and Recovery

Provider will maintain reasonable measures designed to support the availability and recoverability of the Services and Customer Data.

Such measures may include:

  1. periodic backups of production Customer Data;
  2. access controls protecting backup systems;
  3. geographic or logical separation of backups where appropriate;
  4. monitoring of backup completion;
  5. periodic testing of restoration procedures;
  6. documented incident-response and recovery procedures;
  7. business-continuity planning; and
  8. disaster-recovery planning appropriate to the Services.

Unless otherwise stated in an Order Form, Provider's internal recovery objectives are targets and do not constitute service-level guarantees.

Any binding uptime commitment, recovery time objective, recovery point objective, or service credit must be expressly stated in the applicable Service Level Agreement or Order Form.

13. Physical and Environmental Security

Provider will maintain reasonable physical and environmental controls for facilities under its direct control.

Where the Services are hosted by third-party cloud or data-center providers, Provider may rely on the physical and environmental security controls maintained by those providers, including controls related to:

  1. facility access;
  2. visitor management;
  3. surveillance;
  4. power and environmental systems;
  5. fire detection and suppression;
  6. hardware disposal; and
  7. business continuity.

14. Subprocessor Security

Provider will take commercially reasonable steps to evaluate the security practices of Subprocessors that process Customer Data.

Provider will require such Subprocessors, by written agreement, to maintain protections for Customer Data that are materially consistent with the obligations applicable to the Subprocessor's services.

Provider will remain responsible for the performance of its Subprocessors to the extent required by the Agreement and Applicable Law.

Provider's current Subprocessor list will be available at:

https://proctorly.co/legal/subprocessors

Changes to Subprocessors will be handled in accordance with the Agreement or any applicable Data Processing Addendum.

15. Security Incident Response

Provider will maintain a documented incident-response process designed to identify, investigate, contain, remediate, and recover from Security Incidents.

Following confirmation of a Security Incident affecting Customer Data, Provider will:

  1. take reasonable steps to contain and mitigate the Security Incident;
  2. preserve relevant evidence where appropriate;
  3. investigate the nature and scope of the Security Incident;
  4. take reasonable corrective action;
  5. notify Customer without undue delay and, where contractually agreed, no later than 72 hours after Provider confirms the Security Incident;
  6. provide information reasonably available to Provider concerning the Security Incident; and
  7. reasonably cooperate with Customer regarding Customer's legally required response.

The initial notice may be provided in phases and may include, to the extent known:

  1. the nature of the Security Incident;
  2. the date or estimated date of occurrence;
  3. the date Provider discovered or confirmed the Security Incident;
  4. the categories of Customer Data affected;
  5. the known or reasonably anticipated consequences;
  6. containment and remediation measures taken or planned; and
  7. an appropriate Provider contact.

Provider's notice will not be construed as an admission of fault, liability, or violation of law.

Provider will not notify Customer Users, regulators, law enforcement, the media, or other third parties on Customer's behalf unless:

  1. Customer provides written authorization;
  2. Provider is legally required to do so; or
  3. immediate notice is reasonably necessary to prevent material harm.

Where legally permitted, Provider will notify Customer before making a required notification concerning Customer Data.

16. Security Incident Costs

Each party will bear its own costs associated with investigating and responding to a Security Incident, except:

  1. as otherwise required by Applicable Law;
  2. as expressly provided in the Agreement; or
  3. to the extent the Security Incident was directly caused by a party's breach of the Agreement.

Any liability arising from a Security Incident will be subject to the limitations, exclusions, and remedies stated in the Agreement unless expressly stated otherwise.

17. Independent Assessments and Certifications

If Provider maintains any applicable third-party security certification or independent assessment, Provider may make reasonable supporting documentation available to Customer, subject to:

  1. confidentiality obligations;
  2. restrictions imposed by the auditor or certification body;
  3. reasonable security restrictions;
  4. redaction of information unrelated to Customer; and
  5. Provider's policies for handling confidential security information.

Examples may include:

  • SOC 2 Type I or Type II reports;
  • ISO/IEC 27001 certifications;
  • penetration-test executive summaries;
  • security questionnaires;
  • vulnerability-management summaries; or
  • comparable independent assessments.

Provider does not represent that it maintains any certification or report unless Provider has expressly confirmed that fact in writing.

18. Customer Security Reviews

No more than once per twelve-month period, Customer may submit a reasonable written security questionnaire relating to the Services.

Provider may satisfy Customer's request by providing:

  1. a completed industry-standard questionnaire;
  2. existing security documentation;
  3. an independent audit report;
  4. a penetration-test executive summary;
  5. a certification;
  6. a virtual security review; or
  7. substantially equivalent evidence.

Customer may conduct additional reviews following:

  1. a confirmed Security Incident materially affecting Customer Data;
  2. a reasonable request from a governmental authority with jurisdiction over Customer; or
  3. a material change to Provider's security program that materially reduces protection of Customer Data.

Customer will not perform or commission penetration testing, vulnerability scanning, load testing, social engineering, or other technical testing of the Services without Provider's prior written authorization.

19. Audit Rights

If information provided under Section 18 is insufficient to demonstrate Provider's material compliance with this Security Exhibit, Customer may request an audit subject to the following conditions:

  1. the audit will occur no more than once annually, unless required by law or following a material Security Incident;
  2. Customer will provide at least 30 days' prior written notice;
  3. the audit will occur during normal business hours;
  4. the audit will not unreasonably interfere with Provider's operations;
  5. the audit will be limited to systems, records, and controls relevant to Customer Data;
  6. the auditor must be independent, qualified, and bound by confidentiality obligations;
  7. the audit will not provide access to information relating to other customers;
  8. the audit will not compromise the security of Provider's systems;
  9. Provider may redact confidential, privileged, or security-sensitive information; and
  10. Customer will bear the audit costs unless the audit identifies a material breach of this Security Exhibit by Provider.

Provider may require the parties to agree on a reasonable audit plan before the audit begins.

20. Security Findings

If an authorized assessment identifies a material deficiency in Provider's compliance with this Security Exhibit, Provider will:

  1. evaluate the finding;
  2. develop a reasonable remediation or mitigation plan;
  3. prioritize remediation based on risk; and
  4. provide Customer with a reasonable status update upon request.

Provider is not required to implement a proposed remediation where Provider reasonably determines that:

  1. the finding is inaccurate;
  2. the risk is already addressed by compensating controls;
  3. the remediation would materially impair the Services;
  4. the remediation would create a greater security risk; or
  5. an alternative measure provides materially equivalent protection.

21. Data Retention and Secure Disposal

Provider will retain Customer Data only for the period necessary to:

  1. provide the Services;
  2. fulfill the purposes described in the Agreement;
  3. comply with Customer's documented instructions;
  4. maintain legitimate records;
  5. prevent fraud or abuse; or
  6. comply with legal obligations.

Following expiration, termination, or cancellation of the Agreement, Provider will make Customer Data available for export for 30 days and will delete or render inaccessible Customer Data from active production systems within 90 days after the applicable termination or cancellation date, which period includes the 30-day export window and any applicable 30-day cancellation grace period, unless:

  1. Customer requests return or export of the data within the applicable retrieval period;
  2. Applicable Law requires continued retention;
  3. the data remains in secure backup systems awaiting normal deletion or rotation; or
  4. the Agreement provides otherwise.

Data retained in backup systems will remain protected under this Security Exhibit and will not be restored except for disaster recovery, security, legal, or continuity purposes.

Provider will securely dispose of storage media containing Customer Data using procedures appropriate to the media and sensitivity of the data.

22. Customer Responsibilities

Customer is responsible for:

  1. determining whether the Services are appropriate for Customer's intended use;
  2. configuring the Services according to Customer's security requirements;
  3. managing Customer User accounts and permissions;
  4. promptly disabling accounts that are no longer authorized;
  5. protecting Customer credentials, authentication devices, and access tokens;
  6. using available multi-factor authentication and security features;
  7. maintaining the security of Customer-controlled systems and devices;
  8. ensuring Customer Users comply with the Agreement;
  9. providing lawful instructions regarding Customer Data;
  10. maintaining appropriate backups where the applicable Service description places backup responsibility on Customer; and
  11. promptly notifying Provider of suspected unauthorized activity involving Customer's account.

Provider is not responsible for a Security Incident caused by:

  1. Customer's failure to fulfill these responsibilities;
  2. compromised Customer credentials not caused by Provider;
  3. Customer's configuration of the Services;
  4. Customer-controlled integrations, systems, devices, or networks;
  5. Customer's violation of the Agreement or Documentation; or
  6. actions Provider performs in accordance with Customer's instructions.

23. Sensitive and Regulated Data

The following categories of data are expressly authorized for processing through the Services when used for exam proctoring as described in the Documentation and the Agreement: student ID photos, webcam snapshots, and aggregate face-count data, provided that Provider does not create biometric identifiers, faceprints, facial templates, or embeddings and does not perform facial recognition or one-to-one facial matching.

Unless expressly authorized in an Order Form or other written agreement, Customer will not submit to the Services any other:

  1. payment-card information subject to PCI DSS;
  2. protected health information subject to HIPAA;
  3. government-issued identification numbers;
  4. biometric identifiers;
  5. precise geolocation information;
  6. criminal-history information;
  7. passwords for third-party services;
  8. export-controlled data;
  9. classified information;
  10. data subject to heightened government-security requirements; or
  11. other categories of highly sensitive or regulated data identified in the Documentation.

If Provider expressly agrees to process a regulated category of Customer Data, the parties will enter into any additional agreement reasonably required for that processing, such as a business associate agreement, data processing addendum, student-data agreement, or industry-specific security addendum.

24. Artificial Intelligence Systems

Provider will maintain reasonable controls governing artificial intelligence systems used to process Customer Data.

Unless expressly disclosed in the Agreement, Provider will not use Customer Data to train a publicly available or generally shared artificial intelligence model.

Provider may use:

  1. de-identified or aggregated information;
  2. operational telemetry that does not identify Customer or an individual;
  3. Customer Data where Customer has provided express authorization; or
  4. third-party artificial intelligence subprocessors identified in Provider's Subprocessor disclosures.

Provider will apply access controls, contractual protections, and data-handling restrictions appropriate to any artificial intelligence service provider that processes Customer Data.

25. Changes to the Services

Provider may modify its systems, infrastructure, hosting providers, security tools, policies, and procedures during the term of the Agreement.

Provider will not make a modification that materially reduces the overall security protections applicable to Customer Data without:

  1. implementing materially equivalent safeguards;
  2. providing notice where required by the Agreement; or
  3. obtaining Customer's agreement where required by Applicable Law.

26. Confidentiality of Security Information

All non-public security documentation provided by Provider, including security reports, questionnaires, audit materials, architecture information, testing results, and remediation information, constitutes Provider Confidential Information.

Customer will:

  1. use such information solely to evaluate Provider's security;
  2. restrict access to personnel and advisers with a legitimate need to know;
  3. protect the information using reasonable safeguards;
  4. not disclose the information to Provider's competitors;
  5. not use the information to discover or exploit vulnerabilities; and
  6. securely delete the information when it is no longer required.

27. Order of Precedence

If there is a conflict regarding information-security obligations, the following order of precedence applies:

  1. an expressly applicable industry-specific security addendum;
  2. an applicable Data Processing Addendum;
  3. this Security Exhibit;
  4. the applicable Order Form;
  5. the main body of the Agreement; and
  6. Provider's Documentation.

However, provisions concerning indemnification, damages, disclaimers, liability limitations, governing law, dispute resolution, and insurance will be governed by the main body of the Agreement unless expressly amended.

28. Survival

Provider's obligations concerning confidentiality, Security Incident cooperation, data retention, deletion, and protection of retained Customer Data will survive expiration or termination of the Agreement for as long as Provider retains Customer Data.

29. Entire Security Commitment

This Security Exhibit states Provider's contractual information-security obligations concerning the Services unless the parties expressly agree to additional obligations in a signed writing.

Marketing materials, questionnaire responses, policy summaries, security webpages, and oral statements do not create additional contractual warranties unless expressly incorporated into the Agreement.


SCHEDULE 1

SUMMARY OF SECURITY MEASURES

Provider maintains the following measures as of the Effective Date.

Control AreaProvider's Security Measure
Hosting providerVercel (edge), Supabase (database), Cloudflare (storage)
Primary hosting regionUnited States
Security frameworkInternal risk-based framework aligned with SOC 2 Trust Services Criteria
Independent assessmentNone currently
Encryption in transitTLS 1.2 or higher
Encryption at restAES-256 or equivalent
Production accessRole-based, least-privilege access
Workforce MFARequired for privileged users; available for all users where tooling supports it
Customer MFANot currently available; planned
Tenant separationLogical tenant segregation via database RLS
Security trainingAt hire and annually thereafter
Background screeningFor applicable roles where legally permitted
Vulnerability scanningContinuous
Penetration testingAnnual target; not yet completed
Dependency scanningAutomated
Backup frequencyContinuous / daily
Backup retentionProvider-managed defaults aligned with Data Retention Policy
Recovery targetNot contractually guaranteed
Recovery-point targetNot contractually guaranteed
Security-log retention730 days for audit actions; otherwise platform defaults
Incident notification72 hours following confirmation
Data deletion period90 days following termination, including a 30-day export window
Subprocessor list/legal/subprocessors
Security contactsecurity@proctorly.co
Privacy contactprivacy@proctorly.co
Incident-notice contactThe email address Customer provides in its account settings