Our Pledge: Building the Most Secure EdTech Platform to Protect the Sensitive Data of Every IEP
Goalbook Toolkit helps build educators' instructional practice to write stronger present levels, set more measurable goals, and plan more effective specially designed instruction — the core work behind every IEP. That work also produces some of the most sensitive documentation a district keeps, so Goalbook is built with the safeguards you need to answer to your board, your state, and your families.
What Goalbook Does, Doesn't Do, and Remembers
What Goalbook Does
- Supports present-level documentation, goal development, progress monitoring, and specially designed instruction planning, using only the data your staff enters
- Encrypts all data in transit and at rest so that student data stays unreadable to unauthorized parties
- Complies with FERPA, IDEA's confidentiality-of-information requirements, COPPA, and applicable state student data privacy laws
What Goalbook Doesn't Do
- Doesn't sell, rent, or share student or staff data with third parties for marketing purposes
- Doesn't grant access to student data outside what your district's administrators have configured district-wide visibility that bypasses your access model
- Doesn't keep district data after your relationship with Goalbook ends
- No advertisements, ever
What Goalbook Remembers
- Account information for every user your district provisions — name, email, role, and school/program assignment
- IEP and progress-monitoring data your staff enters, scoped to the students each account is authorized to serve
- System activity your office may need for security and compliance, including login history and access logs across the district
Third-Party and Independently Audited and Verified
"Trust us" isn't a standard your district can put in a board report. Here's what's independently verified:
- SOC 2 Type I and Type II: audited against the AICPA Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy — Type II is the even harder bar: it confirms these controls held up in practice over months of operation, not just on paper
- A live, continuously monitored Trust Center at trust.goalbook.com, where your IT and compliance team can review our actual security controls — not a static PDF or sales presentation slide — it covers infrastructure, organizational, product, internal, and data/privacy security
Built for Special Education Data That Sits Under Three Federal Laws: FERPA, COPPA, IDEA
Most ed-tech privacy pages stop at "FERPA and COPPA compliant" — accurate but incomplete for special education records. A lot of information within an IEP is personally identifiable information that is not fully covered under FERPA. That is why IDEA requirements for confidentiality-of-information (34 CFR §§300.610-300.627), have additional disability-specific protections. Goalbook's privacy and security is built around this distinction.
Security Safeguards
The technical controls behind these commitments are documented in full on our live Trust Center at trust.goalbook.com and include:
-
Data encrypted in transit and at rest, with encryption key access restricted
-
Unique account authentication enforced, with production application access restricted to authorized personnel
-
Regular penetration testing and control self-assessments
-
Anti-malware technology in place, and portable media and asset disposal handled under documented procedures
-
Business continuity and disaster recovery plans that are established and tested, not just written down
-
A configuration management system and formal data classification policy
-
Multi-factor authentication and SSO support for district-managed logins
-
Automatic session timeouts to protect accounts left open on shared devices
Privacy Policy
Please select the applicable product below.
Have Additional Questions?
Contact: trust@goalbook.com