News iT1 has acquired Nucleos, uniting enterprise technology with a mission-driven education platform. Read the announcement
Security & Trust

Security isn't a feature.
It's the foundation.

We're trusted to deliver education inside facilities where most software simply cannot operate. Here's how.

NIST 800-53
Control framework mappings
FIPS 140-2 / -3
Validated cryptography
FedRAMP-aligned
Azure High inheritance
FERPA & COPPA
Education privacy
SAML 2.0 & OAuth 2.0
Identity federation
TLS 1.2+
Encrypted in transit
ADA via Google
Built-in accessibility features
WCAG 2.1 AA
Designed-in accessibility
Architecture

Engineered for managed access

AchieveDXP doesn't leave the network to chance. Every device, every session, every byte travels a path your security team can audit.

Managed network access

All learner traffic routes through facility-approved channels with comprehensive allowlisting, content review, and audit logs.

Encryption everywhere

AES-256 at rest. TLS 1.2+ in transit. FIPS 140-2 validated cryptographic modules across the entire stack.

Total observability

Every learner action — content viewed, message sent, assessment taken — is logged with cryptographic integrity for audit and review.

Granular access control

Role-based permissions down to the content and feature level. Multi-factor authentication for staff. SSO with your existing IdP.

Content allowlisting

Every piece of content is reviewed, approved, and allowlisted. No open browsing. No surprises. No risk.

Message review & controls

Configurable communication policies — keyword filtering, manual review queues, staff oversight — that meet facility requirements.

Compliance

Built to the standards your auditors expect

From state DOC PREA standards to federal accessibility law to education-specific privacy regulations.

Privacy & data protection

  • FERPA — Family Educational Rights and Privacy Act
  • COPPA — Children's Online Privacy Protection Act
  • HIPAA-ready — health-adjacent workflows for reentry
  • State privacy laws — CCPA, VCDPA, and others as applicable
  • GDPR-aligned data handling for international deployments

Security & operational standards

  • NIST 800-53 — federal control framework
  • FedRAMP-aligned — Azure FedRAMP High inheritance
  • State-ready — assessed under State Information Security Manuals
  • FIPS 140-2/-3 validated cryptographic modules
  • SAML 2.0 / OAuth 2.0 identity federation

Accessibility & ADA compliance

  • WCAG 2.1 AA conformance across the learner experience
  • Section 508 compliance for federal procurement
  • Google ADA accessibility features built into managed devices and browsers
  • Screen reader optimized with semantic markup throughout
  • Keyboard-first navigation verified across every workflow
  • Voice control & assistive input supported via Google Chrome on managed devices
Operations

Privacy & incident response built into operations

A documented program. Run by a dedicated team. Audited annually. We take privacy and incident response as seriously as our customers do.

  • 24×7 security operations backed by iT1's MDR practice
  • Defined incident response runbook with notification SLAs
  • Quarterly tabletop exercises across engineering, ops, and legal
  • Annual third-party penetration testing

Our commitments

Data ownership

Your data is yours. We do not sell it, mine it for ads, or use it to train external models.

Transparency

Subprocessor list, system status, and policy updates are public and notified in advance.

Notification

Any incident affecting your data is reported within 24 hours, with a full root-cause analysis to follow.

Talk to our security team

Get the security & compliance brief

Detailed control mappings, architecture diagrams, and audit reports for your security and procurement teams.