Skip to content
The first ADA Title II deadline is April 26, 2027. See what changedTitle II deadline: April 26, 2027

Built for student data.

School documents carry student names, grades, and support plans. Here is how Clearlinks handles them, including what we don't have yet.

  • NY Ed Law § 2-d
  • TLS in transit
  • AES-256 at rest
  • Stored in AWS us-east-2
  • No training on your files
  • Deleted files restorable for 30 days, then purged

Compliance

Where we stand today.

FERPA

Your school stays in control of its education records. We process documents only to make them accessible, at your direction. We don't sell the data or use it for advertising.

NY Education Law § 2-d

We comply with New York's student data privacy law. Agreements with New York schools include the Parents' Bill of Rights for Data Privacy and Security.

No student accounts

Clearlinks accounts are for school staff. Students never sign in or give us information directly.

SOC 2

We haven't completed a SOC 2 audit. We'll answer your security questionnaire directly and walk your team through how the system works.

Engineering practices

How the system is built.

Encrypted everywhere

Every connection uses TLS. Files are stored in a private Amazon S3 bucket in us-east-2 with AES-256 encryption at rest.

Expiring file links

No file has a public URL. Downloads use signed links that expire after 15 minutes.

Organization isolation

Every document belongs to one organization, and every lookup is scoped to it. People only see the organizations they've been added to.

Roles

Owner, admin, member, and client roles control who can invite people, manage API keys, and set up webhooks.

API keys and webhooks

We store partner API keys only as SHA-256 hashes. Webhooks are signed with HMAC-SHA256 so you can verify they came from us.

No training on your files

We don't train models on your documents. Our AI provider, Anthropic, doesn't train on API inputs under its commercial terms.

Data lifecycle

From upload to delete.

Every file moves through the same four stages, and each one is scoped to your organization.

  1. 1

    Upload

    Files go straight to storage over TLS through a signed upload link. Each one is tied to your organization from the start.

  2. 2

    Process

    Our own engine tags the PDF and runs OCR. Page images go to our self-hosted layout model and to Anthropic's Claude for alt text and structure review.

  3. 3

    Deliver

    Download the remediated file from the app or fetch it through the API. A signed webhook can tell your system when it's ready. The original is kept alongside it.

  4. 4

    Delete

    Files stay until you delete them. A deleted document moves to Recently deleted, where a workspace owner or admin can restore it for 30 days. Once that window closes, it is queued for permanent removal: its files from storage and its records from our database. An upload you remove before its file arrives is deleted right away.

Documents

Paperwork for your review.

Security questions? We've got answers.

Send us your questionnaire or data privacy agreement and we'll work through it with you.