Trust Center

Built for districts.
Audited where it counts.

Capgrown protects student and family financial-aid data as part of the InfusEDU Lab portfolio — encrypted in transit and at rest, governed by row-level access, and aligned with the federal and state frameworks districts already rely on.

Security principles

Four non-negotiables.

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest across all student, family, and financial-aid data.

No training on student data

Student, parent, and counselor data is never used to train foundation models — ours or any vendor's.

Least-privilege RLS access

Row-level security on every table. Counselors see only their campus; districts see only their district.

Auditable everything

Every read, write, and AI interaction is logged with user, timestamp, and scope for audit and review.

Certifications & frameworks

The frameworks we map to.

Status reflects Capgrown's organizational posture. Underlying infrastructure is already on SOC 2 Type II providers.

FERPA-aligned

Active

COPPA-aligned

Active

WCAG 2.1 AA

Active

ADA Title II

Active

NY Ed Law 2-d

Active

TX SCOPE Act / HB 18

Active

UT HB 218

Active

SC / OK / WV / MD AI Governance

Active

NDPA / SDPC

Active

GLBA Safeguards Rule

Financial aid data

Active

SOC 2 Type I

Targeted Q2 2026

In progress

SOC 2 Type II

Targeted Q4 2026

Planned
SOC 2 roadmap

Capgrown runs on SOC 2 Type II infrastructure today.

Every layer Capgrown sits on — Supabase (AWS), Lovable, Cloudflare, and Stripe — is already audited to SOC 2 Type II. Capgrown's own organizational SOC 2 Type I report is targeted for Q2 2026, with Type II following in Q4 2026.

Districts requiring a HECVAT, NDPA, or custom DPA before then can request one directly — we turn most around within five business days.

SOC 2 Type I

Q2 2026

In progress

SOC 2 Type II

Q4 2026

Planned

Sub-processors

Who touches your data.

Supabase (AWS)
SOC 2 Type II
Database, auth, storage

SOC 2 Type II • HIPAA • ISO 27001

Cloudflare
SOC 2 Type II
Edge, CDN, DDoS protection

SOC 2 Type II • ISO 27001 • PCI DSS

Stripe
SOC 2 Type II
Payments & billing

SOC 2 Type II • PCI DSS Level 1

Lovable
SOC 2 Type II
Application hosting & build

SOC 2 Type II infra

Compliance documents

The InfusEDU Lab portfolio.

Canonical policies live on the InfusEDU Lab compliance hub and apply across all InfusEDU products, including Capgrown.

Need a DPA, NDPA, or HECVAT?

Email our team directly. We respond to district security and procurement reviews within one business day.

matt.monjan@infusedu.com