Compliance Status Page
About This Page
This page summarizes the compliance and assurance posture of Multi-Headed Learning Engine (MHLE). It distinguishes implemented product controls from independent certifications. Framework references describe the requirements MHLE uses to organize its program; they do not, by themselves, mean that MHLE has received a certification or regulatory endorsement.
For a current evidence package, institutional customers may contact contact details withheld pending approval. Contractual commitments are governed by the applicable agreement and Data Processing Agreement, not this public summary.
Current Status
| Area | Status | Public Summary |
|---|---|---|
| Privacy notice | Implemented | Privacy Policy v3.0 is published at /privacy. |
| FERPA support | Implemented controls | Institutional features include role-scoped access, education-record access/export functions, sharing controls, and audit records. An institution remains responsible for determining whether its use meets the FERPA school-official exception and its own annual-notice requirements. |
| COPPA support | Implemented controls | Date-of-birth-based age screening, parental-consent gating, parent notices, and access/deletion request paths are implemented for users identified as under 13. |
| Georgia student privacy | Implemented documentation and controls | A Student Data Transparency Notice and institutional DPA are available. Product controls prohibit sale and advertising use of student data. |
| GDPR and U.S. state privacy support | Program in progress | Privacy request, export, correction, deletion, and opt-out workflows exist. Applicability and controller/processor obligations depend on the customer and deployment. |
| SOC 2 | Readiness in progress | MHLE has not represented that it holds its own SOC 2 Type II report. Control mapping, evidence collection, vulnerability management, and independent testing preparation are in progress. |
| Independent penetration test | Planned | The compliance register identifies an independent engagement as planned. A report should not be represented as available until it has been completed and uploaded. |
| 1EdTech / LTI | Implemented, not listed here as certified | MHLE implements LTI integration features. This page does not claim current 1EdTech certification. |
| Accessibility / WCAG | Ongoing | Accessibility is reviewed as part of product development. No independent WCAG conformance statement is asserted on this page. |
| Responsible AI | Implemented program | Model inventory, cost attribution, safety testing, content safeguards, user feedback, and periodic AI-quality evaluation are documented. |
Privacy and Student Data Controls
MHLE maintains controls intended to support educational institutions and individual users, including:
- A public Privacy Policy and Student Data Transparency Notice.
- Data Processing Agreement and security-questionnaire materials for institutional review.
- Parental-consent controls for users identified as under 13.
- User and organization workflows for access, export, correction, and deletion requests.
- Server-side role and authorization checks for student, instructor, coach, parent, organization, partner, and administrator functions.
- Restrictions on public sharing and controls for study-group and classroom visibility.
- A public list of service providers that may process customer data.
FERPA applies directly to covered educational agencies and institutions. When a customer uses MHLE under the school-official exception, the customer must place MHLE under its direct control concerning the use and maintenance of education records and authorize only permitted uses. MHLE's DPA is designed to document those processing instructions.
Security Program
The current application includes layered technical safeguards such as password hashing, signed authentication tokens, optional administrator multi-factor authentication, rate limiting, input validation, content sanitization, security headers, encrypted transport, selected field-level encryption for sensitive values, access-control checks, vulnerability tracking, credential scanning, and restoration testing.
No online service can guarantee absolute security. Security controls and architecture are reviewed as the product changes, and remediation priorities are tracked through the internal compliance and vulnerability registers.
AI Governance
MHLE uses third-party AI services to provide analysis, generation, transcription, text-to-speech, embeddings, and factual-verification functions. Relevant customer content may be sent to the provider needed to perform the requested feature. MHLE's current policy is not to use customer or student content to train general-purpose AI models.
AI-generated material may be inaccurate and is intended to assist—not replace—student, educator, institutional, legal, medical, financial, or other professional judgment. See the AI Transparency Statement, Data & Training Policy, and AI Quality & Safety Testing Summary.
Evidence Available to Customers
Subject to confidentiality and security restrictions, institutional customers may request:
- The current DPA and service-level agreement.
- Security questionnaire or HECVAT Lite responses.
- Subprocessor inventory and vendor-review summaries.
- Vulnerability-management and restoration-test summaries.
- AI quality and safety evaluation summaries.
- Current status of SOC 2 readiness and independent testing.
Sensitive material—including credentials, detailed vulnerability reproduction steps, private infrastructure diagrams, and information that could weaken security—is not published on the public Trust Center.
Contact
| Request | Contact |
|---|---|
| Compliance or customer assurance | contact details withheld pending approval |
| Privacy or data rights | contact details withheld pending approval |
| Security issue | contact details withheld pending approval |
| Contract or DPA | contact details withheld pending approval |
Review Note
This document remains Draft until its statements, contact addresses, certification status, and effective date are approved by MHLE leadership and counsel.