Skip to content
Trust & Security

Security and privacy built for education

Doowii maintains a SOC 2 Type II report and designs its security and privacy controls to support institutions' applicable obligations under FERPA, COPPA, GDPR, and state privacy laws.

SOC 2 Type II reportDesigned to support FERPADesigned to support COPPADesigned to support CCPADesigned to support GDPR
Compliance

Security assurance and regulatory support

Doowii is the unified data platform for education. Security and privacy are built into the platform from the start. We continuously expand our portfolio of security and compliance reports as the K-12 districts and higher education institutions we serve request them. Here is what is independently assessed and how our practices are designed to support institutional obligations today.

SOC 2 Type II

An independent auditor's report on the design and operating effectiveness of our security, availability, and confidentiality controls over the report's coverage period, based on the AICPA Trust Service Criteria.

FERPA

The Family Educational Rights and Privacy Act protects the privacy of student education records. Doowii's controls and practices are designed to support institutions' FERPA obligations.

COPPA

The Children's Online Privacy Protection Act governs certain collection and use of data from children under 13. Doowii's controls and practices are designed to support applicable institutional obligations.

CCPA & state privacy laws

The California Consumer Privacy Act and state student data privacy laws set obligations for how personal data is handled. Doowii's privacy program is designed to support applicable requirements.

GDPR

The EU General Data Protection Regulation sets requirements for data protection and privacy. Doowii's privacy program is designed to support institutions' applicable obligations.

How we protect your data

Security built into every layer

Our SOC 2 Type II report is an independent attestation across the AICPA Trust Service Criteria that Doowii's controls are designed and operating effectively.

Security

Controls address unauthorized access, use, and modification of systems and data.

Availability

Controls address the platform's availability for operation and use as committed and agreed.

Confidentiality

Controls address how information designated as confidential is handled throughout its lifecycle.

Private deployment options

A private deployment when your policies require it

Doowii runs the platform as a managed service. For institutions with specific cloud, regional, or network requirements, enterprise deployments can place storage and compute inside approved boundaries while Doowii continues to operate the platform.

Customer-owned storage

Normalized education tables can reside in object storage owned by the institution, within the agreed cloud account and region. Identity, retention, and operating responsibilities are documented for the deployment.

Private regional compute

Dedicated DuckDB query compute can run inside the customer's VPC and selected region. Network paths, service access, and support boundaries are set during architecture review.

Permissioned open lake access

Authorized compatible engines can access open Apache Iceberg tables through the institution's storage, catalog, identity, and network controls.

Auditable data history

Each committed Apache Iceberg snapshot is immutable. Retained snapshot and transformation lineage can connect an analysis to the table version and source processing state used, subject to the agreed retention policy.

SOC 2 Type II

Independently audited controls

The SOC (System and Organization Controls) 2 Type II report is an independent auditor's attestation of the design and operating effectiveness of the security, availability, and confidentiality controls that Doowii has had in place during the report's coverage period.

The framework was created by the American Institute of Certified Public Accountants (AICPA), and a SOC 2 Type II examination evaluates controls against the AICPA Trust Service Criteria over a defined period.

Request our compliance reports

Our current security and compliance reports are available to all customers and prospects under NDA. Contact us for copies of applicable reports, or to find out whether a particular report or assessment will soon be available.

Security team
security@doowii.io

You can also reach out to your Account Manager for copies of applicable reports.

FAQ

Security & compliance FAQs

Common questions about Doowii's approach to education data security and privacy. Have another? Request a demo or email our security team.

Does Doowii maintain a SOC 2 Type II report?

Yes. Doowii maintains a SOC 2 Type II report covering the design and operating effectiveness of security, availability, and confidentiality controls during the report period, based on the AICPA Trust Service Criteria.

How does Doowii support FERPA obligations?

Doowii's controls and privacy practices are designed to support the FERPA obligations of the schools, districts, and institutions we serve. Each institution remains responsible for evaluating its own requirements and configuration.

How does Doowii protect student data?

Doowii uses layered access, encryption, monitoring, and governance controls. Its SOC 2 Type II report covers relevant security, availability, and confidentiality controls during the report period, and its privacy practices are designed to support applicable education and privacy obligations.

How does Doowii support COPPA, CCPA, and GDPR obligations?

Doowii's controls and privacy practices are designed to support institutions' applicable obligations under COPPA, CCPA, GDPR, and state student data privacy laws. Applicability depends on the institution, data, use case, and contractual role.

How can I request Doowii's security and compliance reports?

Doowii's current security and compliance reports are available to customers and prospects under NDA. Email security@doowii.io, reach out to your Account Manager, or visit the Doowii Trust Center to request copies.

What is Doowii and who is it built for?

Doowii is the unified data platform for education. It brings SIS, LMS, ERP, CRM, and other institutional data together for K-12 districts and higher education institutions, with governed access and controls designed to support applicable privacy obligations.

Can Doowii keep the data plane in our cloud environment?

A private deployment can use customer-owned object storage for normalized Apache Iceberg tables and dedicated DuckDB query compute inside the customer's VPC and selected region. The cloud services, network paths, identity model, retention, support access, and division of operating responsibility are confirmed during architecture review.

How can institutional tools access data in a private deployment?

When open lake access is included in the deployment, authorized compatible engines can query the same Doowii-normalized Apache Iceberg tables. Access remains subject to the institution's storage, catalog, identity, network, and engine configuration.

Explore the Doowii Trust Center

Review available reports, controls, and compliance information in one place.