Amira Trust Center

Protected by Design.
Independently Verified.
Committed in Writing.

Amira is built to protect student information at every stage—from secure access and responsible data collection to ongoing testing and clear contractual commitments.

https://vimeo.com/11264594
https://cdn.prod.website-files.com/68905b906841085b6c846462/68a4734e6465d1a5a0147877_timeline.json
https://vimeo.com/11264594

Trust Starts with Transparency

Schools should understand how their technology partners collect, use, protect, and retain student information. Amira provides clear, accessible information about the safeguards, independent reviews, security practices, and legal commitments behind our platform.
Pete's Letter
Here is more of Pete's Letter here. Copy coming from Amy/Pete
Pete Jungwirth
Co-Founder, Chief Information Security Officer
Why Schools Trust Amira

How We Protect Student Data

Amira collects only the information needed to provide educational services and support student learning. Student information is protected through encryption, controlled access, secure infrastructure, and clearly defined data-retention practices.
Encryption at rest
Every piece of student data Amira stores — assessment scores, reading levels, audio recordings — is encrypted using the same standard (AES-256) that banks use to protect financial records. The keys that lock and unlock the data are managed by Amazon Web Services and rotated automatically so they can't become stale. An independent auditor verifies this as part of our annual security audit.
School login only — no new passwords
Amira connects to your district's existing login system (through services like Clever or ClassLink). That means no new passwords to remember, lose, or write on a sticky note. It also means the district stays in control — if a student leaves or a teacher changes roles, the district can turn off access instantly through the same system they already manage.
We only collect what we need
We collect the minimum data required: student name, grade, school, and reading performance. That's it. Every data field we collect is documented in a published data dictionary that your district can review. We don't ask for or store sensitive personal information like SSNs, addresses, phone numbers, or medical records — because we don't need them, so we don't take them.
No ads, no tracking
Amira contains no advertising of any kind. There are no tracking pixels, no behavioral profiling, and no data broker connections. You don't have to take our word for it — anyone can verify this independently by running a free scan at themarkup.org/blacklight, which checks for hidden trackers on any website.
Automatic session protection
Amira uses automatic session timeouts and security protections that prevent someone from hijacking an active session. These are the same techniques used by online banking — they work silently in the background so students don't notice them, but they keep data safe if a device is left unattended.
Data deleted on schedule
Amira maintains a published retention schedule that specifies exactly how long each type of data is kept. Deletion happens automatically — it's not dependent on someone remembering to press a button. When a district's contract ends, all student data is deleted within 60 days, and the district receives written confirmation that it's gone.
Clear voice-recording policy
Because Amira is a reading assessment, students read aloud and that audio is used to evaluate their reading ability. We understand this raises questions. Here's the short version: audio is used only for scoring, it's kept only as long as needed by the district, and it's deleted on the same schedule as all other student data. Our privacy policy spells this out in plain language, and your district's agreement with us puts it in writing.
Backed up and recoverable
All data is backed up with encryption to geographically separated locations within the United States. This means that even if a hardware failure, natural disaster, or other incident affects one location, student data can be recovered from a backup. Our disaster recovery procedures are reviewed as part of our annual independent security audit.
Attack protection
Amira uses Amazon's Web Application Firewall and Shield services, which sit in front of our application and filter out malicious traffic. Think of it like a security checkpoint — legitimate users pass through, but attacks are blocked before they ever reach the systems that hold student data.
Amazon's own security protections
The physical servers that store student data are in Amazon Web Services data centers, which maintain some of the most rigorous security certifications in the world — including their own SOC 2 audit, ISO 27001 certification, and FedRAMP authorization from the federal government. We inherit all of those physical security protections automatically.
Data stays in the United States
Amira's systems are configured to use only US-based data centers. Student data - including audio recordings, assessment scores, and roster information - is stored and processed exclusively within the United States. This is both a technical reality and a legal commitment written into every contract we sign with a district.
Background-checked employees
All Amira employees and contractors undergo background screening before they start work, including criminal history verification. This is company policy, it's documented in writing, and it's verified by our independent auditor as part of the annual SOC 2 examination.
Privacy training every year
Every Amira employee completes annual training on FERPA (the federal student privacy law) and COPPA (the federal children's online privacy law), plus general security awareness. We track who has completed training and when. Our independent auditor verifies this as part of the annual SOC 2 examination — it's not optional.
Why Schools Trust Amira

Independent Verification

Our privacy and security practices are reviewed against recognized standards so schools do not have to rely on our word alone.
SOC 2 Type II audit
A SOC 2 Type II is the gold standard for verifying that a technology company's security controls actually work — not just that they exist on paper. An independent auditor (Roy & Associates) observed Amira's security practices over a multi-month period and tested whether they were operating effectively. The resulting report covers Security, Availability, and Confidentiality. Districts can review the full report under a standard non-disclosure agreement.
TX-RAMP certified
TX-RAMP (Texas Risk and Authorization Management Program) is a mandatory security certification for cloud services used by Texas state agencies. Amira achieved TX-RAMP certification in June 2026 after a formal review of our security controls. Texas has one of the most rigorous state-level cloud security programs, and meeting its requirements demonstrates a level of security maturity that extends well beyond Texas borders.
1EdTech certified integrations
1EdTech (formerly IMS Global) is the leading standards body for education technology. Amira holds current certifications for LTI (how products connect to school systems), Data Privacy (how data is handled), and OneRoster (how student rosters are shared). When a district sees these certifications, it means an independent body has verified that Amira follows established rules for handling school data.
GDPR / EU-U.S. Data Privacy Framework
The EU-U.S. Data Privacy Framework (often referenced as GDPR compliance) is a government-backed certification that requires companies to follow a set of privacy principles and subjects them to FTC enforcement if they don't. Amira has been an active participant since July 2025, with the next renewal due July 2027. While this framework is primarily about international data transfers, the privacy commitments it requires — transparency, purpose limitation, data security, accountability — apply to how we handle all data, including student data.
Education industry membership
Amira maintains membership in 1EdTech and participates in the K-12 education privacy community. This isn't just a badge — it means we're at the table when standards evolve, we hear about emerging threats early, and we're accountable to the community of educators and technologists working to keep student data safe.
Why Schools Trust Amira

Ongoing Security Testing

Security is not a one-time assessment. Amira continuously evaluates its systems, identifies potential risks, and strengthens its safeguards as technology and cybersecurity expectations evolve.
Code scanned before deployment
Before any code change reaches the version of Amira your students use, it passes through automated security scanners that look for known vulnerability patterns. If a problem is found, the change is blocked until it's fixed. This happens on every single update — it's built into our development process, not something we do occasionally.
Application tested before every release
Dynamic Application Security Testing runs against Amira in a staging environment before every production deployment. Unlike code scanning, this tests the running application the way an attacker would — probing for weaknesses in login, data access, and input handling. Issues must be resolved before the release proceeds.
Phishing defense training
Social engineering (tricking people into giving up access) is the #1 cause of data breaches across all industries. Amira runs regular simulated phishing campaigns against our own employees using an industry-standard platform. Anyone who clicks gets immediate remedial training. We track results over time to make sure our team is getting better, not complacent.
Continuous monitoring
Amira uses automated monitoring tools that continuously check our systems against databases of known security vulnerabilities. When a new threat is discovered anywhere in the world, our monitoring tools check whether we're affected and flag it for immediate attention. This is an ongoing process, not a one-time check.
Why Schools Trust Amira

Legal Commitments in Writing

Our commitments to schools and families are supported by policies, agreements, and contractual protections—not simply marketing promises.
Standard privacy agreement
Amira uses the Student Data Privacy Consortium's National Data Privacy Agreement (NDPA) as the foundation for agreements with districts. The SDPC is a collaboration of schools, states, and vendors that developed standardized privacy language so districts don't have to evaluate custom legal terms from every vendor. When you see an SDPC agreement, you know it's been vetted by the education community.
Districts own the data
Every agreement Amira signs with a district states in black and white that all student data remains the property of the district. Amira has no independent claim to it. The district decides what data is shared with us, they can request it back at any time, and they can instruct us to delete it. We can't use it for anything the district hasn't approved.
Never sold, never used for ads
Amira's contracts and privacy policy both contain absolute prohibitions on selling student data or using it for targeted advertising. This isn't a corporate policy that can change at a board meeting — it's a legally enforceable commitment. Violations would expose Amira to liability under both contract law and federal regulations including the FTC's enforcement authority.
Data deleted when the contract ends
Districts sometimes worry about what happens to data after a contract ends. Here's our answer: it's deleted. All of it. Within 60 days of contract termination. And we don't just say it's deleted — we provide the district with a signed certificate of destruction confirming that the data has been permanently removed from all our systems, including backups.
Fast breach notification
Every contract Amira signs includes a specific breach notification timeline. If we ever discover that student data has been improperly accessed, the district will be notified with full details: what happened, what data was affected, and what we're doing about it. For states with stricter requirements (like New York), we meet those tighter deadlines.
Legal authority under FERPA
Under FERPA (the Federal Educational Rights and Privacy Act), schools can share student records with companies like Amira by designating them as a 'school official with a legitimate educational interest.' This is the same legal mechanism schools use for other essential services. It means Amira is bound by the same data protection obligations as the school itself, and the district maintains direct control over how data is used.
COPPA-compliant consent
COPPA (the Children's Online Privacy Protection Act) requires parental consent before collecting data from students under 13. Federal regulations specifically allow schools to provide this consent on behalf of parents when the data is used for educational purposes. This 'school consent exception' is the standard model used across K-12 education technology - it's not unique to Amira, and it's been upheld by the FTC.
Data used only for reading assessment
Every contract includes an explicit purpose limitation: student data may only be used to deliver the reading assessment service. We can't repurpose it for marketing, sell it to researchers, or use it to build unrelated products. The district approved a specific use, and that's the only use permitted.
Right to audit
Amira's agreements give districts the right to audit our compliance with data protection commitments. In practice, our SOC 2 Type II report — produced by an independent auditor — satisfies this requirement because it covers the same controls districts would want to verify. Districts don't have to take our word for it; they can see the auditor's findings.
Cyber insurance
Amira maintains cyber liability insurance at levels appropriate for K-12 contracts. If a district needs proof of coverage - for example, to satisfy their own risk management requirements - we can provide a Certificate of Insurance naming the district. This is standard practice and available on request.
US-only data — in the contract
Beyond configuring our systems to use only US data centers, we write the US data residency commitment into every Data Sharing Agreement. That means it's not just a technical setting that someone could quietly change - it's a contractual obligation. If we violated it, the district would have legal recourse.
Notice before privacy changes
Amira commits in writing to providing advance notice before making any material change to our privacy practices. Districts have the right to review the changes and terminate the agreement if they're unacceptable. This ensures that the privacy protections in place when a district signed up don't quietly erode over time.
State-by-state legal compliance
Student privacy laws vary significantly by state, and some states have requirements that go well beyond federal law. Amira maintains current, ready-to-sign compliance exhibits for the most demanding states: New York (Education Law 2-d, including Parents Bill of Rights), Illinois (SOPPA), California (SOPIPA/AB 1584), and Texas (SB 820/2087). These aren't afterthoughts - they're maintained and updated as regulations change.
Zero-breach track record
Since inception, Amira has had zero data breaches, zero unauthorized disclosures of student data, and zero government data requests. While past performance doesn't guarantee future results, a sustained zero-incident track record is meaningful - it reflects the effectiveness of the controls described on this page in real-world operation.
Have a Specific Trust or Compliance Question?
Our team can help your district evaluate Amira’s privacy, security, data-management, and contractual practices.

Email: trust@amiralearning.com