About AgenTeach
AgenTeach is an educational technology platform dedicated to empowering teachers with intelligent, AI-driven tools that streamline lesson planning, enhance student feedback, and reduce administrative overhead. Built by educators for educators, AgenTeach is designed as a school-controlled, teacher-reviewed documentation and workflow assistant: it prepares drafts and records for authorized users, while educators and districts remain in control.
Trust posture
AgenTeach's near-term trust posture is to be designed for FERPA/COPPA-aligned, DPA-ready K-12 workflows. We do not claim SOC 2, ISO 27001, 1EdTech, SDPC registry, or iKeepSafe badge completion unless and until the relevant third-party process is complete. Our formal policy set — Privacy Policy, Terms of Service, Subprocessor List, and Retention & Deletion Schedule — is published on this site. For pilots, the priority is a signed district data/privacy agreement, no-training AI commitments, least privilege, deletion/export support, and incident-response readiness.
Signed DPA/DSA, data dictionary, subprocessor list, no-sale/no-ads/no-training commitments, MFA, token encryption, no raw student-content logs, deletion/export process, and incident-response plan.
SDPC/NDPA-style packet, vendor-risk packet, AI-use statement, Google OAuth least-privilege posture, US residency commitment, admin-visible data inventory, and audit export.
SOC 2 readiness then Type I/II, external penetration testing cadence, 1EdTech TrustEd Apps preparation, and iKeepSafe-style FERPA/COPPA review if the product scope requires it.
Part 1
AgenTeach is a helper. It can organize notes, draft messages, and prepare work for you to review. You stay in charge.
01 · You approveIt does not automatically send messages, submit records, grade students, discipline students, diagnose students, or confirm IEP/504 service delivery. It prepares drafts. A teacher or authorized staff member reviews and decides what happens next.
02 · Less dataFor roster-light workflows, that may mean a student name, class/course, and guardian contact only when a parent draft is enabled. We do not need student web-browsing history, precise location, social media profiles, or extra demographic data.
03 · School controlDistricts approve the service, integrations, retention settings, exports, deletion, and subprocessors through a DPA/NDPA or similar agreement. Access is scoped by district, school, class, role, and student relationship.
04 · Safe AI useAI can help summarize, extract, classify, rewrite, or draft from teacher-selected context. It must not invent facts, make final decisions, or train on student data. Teachers review outputs before anything is sent, exported, routed, or saved as an official-looking record.
Simple promise
AgenTeach is for school work only. We do not sell student data, rent it, target ads, build commercial profiles, or use student data to train AI models. The MVP is teacher-only; if student-facing features are added later, they will require additional COPPA and district consent controls.
Part 2
AgenTeach uses a district-authorized, teacher-reviewed architecture: React/Next.js for the interface, a policy-enforcing backend for authorization and audit, and encrypted, US-hosted infrastructure as the system of record for district data — with Google Classroom as a read-only, teacher-authorized source for rosters and coursework.
AgenTeach's encrypted US cloud environment — database and file storage — is the system of record for district data, used under a DPA/NDPA or similar agreement. Every record is scoped to its district and school, uploaded files are linked to students so erasure reaches file content too, and automated retention windows purge data on schedule.
Every sensitive request is checked server-side by role, district, school, student relationship, data category, and record state. Role alone is not enough — and notes, evidence, and communication inputs carry a sensitivity classification that gates what can leave the workspace, with explicit teacher confirmation required for the most sensitive records.
Traffic uses HTTPS/TLS, security headers, CDN/WAF controls, rate limits, upload size/type limits, and backend-issued short-lived upload URLs. Sensitive student data is not stored in browser localStorage, sessionStorage, or IndexedDB.
Databases, object storage, backups, OAuth tokens, transcripts, exports, and temporary processing artifacts use encryption, scoped access, lifecycle deletion, and district-tagged metadata where applicable.
Teacher sign-in
District identity, no extra passwords
Teachers and admins sign in through their district's Google or Microsoft identity. AgenTeach keeps no separate passwords, so the district's MFA policy applies to every sign-in.
Production PII
Scoped, audited access
There is no support tier with standing access to district data. Infrastructure access is limited to named engineering founders, and in-product access to sensitive records is captured in an append-only audit trail.
District identity
OAuth 2.0, least privilege
Google Classroom access is read-only by design. Clever, ClassLink, OneRoster, SAML/OIDC, LMS, SIS, and IEP integrations are added only through district-approved, least-privilege scopes.
Privacy governance
Student-linked behavior notes, attendance nuance, grades, observations, parent communication drafts, and IEP/504 or accommodation logs are treated as education records when tied to identifiable students. Governance is designed to align with FERPA school-official workflows, COPPA school-consent structures where under-13 data is in scope, SDPC/NDPA expectations, and comparable state student privacy obligations.
Default retention windows are published in our Retention & Deletion Schedule and enforced by an automated daily purge; windows are configurable by district, record type, data class, and contract/state requirement. Student erasure, full export, and legal-hold tooling is live in the product for district administrators. On contract termination or authorized LEA request, data is returned/exported and then deleted within 60 days; records under legal hold are preserved until the hold is released.
AI calls go through a backend safety layer, not directly from the browser. The system minimizes prompts, detects sensitive content before AI/export, records provider/model/redaction metadata in audit logs, and uses DPA/subprocessor terms with no-training and no-retention commitments where available.
Subprocessors needed to deliver AgenTeach — currently hosting, transactional email, and AI processing, per our published Subprocessor List — are bound by DPAs or equivalent terms. We maintain a minimized subprocessor list, review vendor controls before use, and flow down privacy, security, deletion, confidentiality, and breach-response obligations.
District-ready MVP guardrails
For early district use, AgenTeach focuses on evidence capture, observation notes, draft communications, grade-to-review-grid workflows, teacher tasks, field-level data transparency, and admin-visible privacy controls — while deferring autonomous actions and direct official-system writeback.
- • Teacher identity, tenant model, secure access, and admin-managed domains.
- • Roster-light student picker with minimal fields.
- • Evidence inbox with extraction, warnings, and teacher confirmation.
- • Parent communication drafts that teachers edit and explicitly send.
- • Admin console for data rights — student erasure with preview, full student export, legal holds, and audit-log review.
- • Direct attendance, SIS, LMS, gradebook, or IEP writeback until contracts, rollback/correction, and audit are mature.
- • Student accounts or student chatbot features in the MVP.
- • Auto-send parent/admin messages or automated escalation.
- • AI discipline, mental health, special education, or service-delivery conclusions.
- • Background Gmail scanning, full-drive scanning, broad mailbox access, session replay, ad trackers, unnecessary telemetry on student-data pages, or raw student content in application logs.
Static-analysis and dependency scanning run in CI on every change in both application repositories, cloud workloads are monitored by Microsoft Defender for Cloud, traffic passes a managed web application firewall, and penetration testing is on the pre-pilot roadmap.
In the event of a suspected breach, our response procedures call for immediate isolation of affected systems, investigation and preservation of audit evidence, and notice to impacted LEAs within contractually and legally required timelines — 72 hours or less for district notice under our standard DPA commitments.
Need district review materials?
For security questionnaires, DPA/NDPA or DSA review, data-dictionary review, HECVAT/CAIQ-style diligence, subprocessor review, AI policy review, or pilot planning, contact AgenTeach and we’ll share the appropriate supporting materials.