For Enterprise customers only: Learn about Superhuman Docs' FERPA compliance, including requirements, product use considerations, restrictions, and more.
Superhuman's security and privacy strategy is built on well-established principles that guide how we secure Docs and keep your Customer Data safe. For customers subject to the Family Educational Rights and Privacy Act ("FERPA") who intend to upload, transmit, or communicate education records, Superhuman can assist with FERPA compliance through our Enterprise plan.
This article provides guidance on important configuration factors, product restrictions, and customer obligations necessary to maintain FERPA compliance. Prospective customers should read this article in its entirety to ensure their intended use of the Docs platform is aligned with FERPA requirements.
Capitalized terms used in this article that are not defined herein have the meanings given to them in your agreement with Superhuman.
Requirements for enabling FERPA compliance
- Enterprise-level Superhuman Docs plan: FERPA compliance support is available only to customers on Superhuman's Enterprise plan.
- Signed agreement identifying Superhuman's school official role: Your Order Form or other agreement governing your use of Docs must include language that identifies Superhuman as a "school official," as that term is used in FERPA. If you will be submitting FERPA-protected education records to Docs, please let your sales contact know.
- Configurations and product use considerations: See the table below.
If you're interested in upgrading to an Enterprise plan or would like to discuss any of the above requirements with our team, please contact us here.
Configuration and product use considerations
The following table provides Docs features and configurations to support your FERPA compliance obligations.
| FERPA Security & Access Measures | How Docs Supports Compliance |
|
Access Control Implement technical policies and procedures for electronic information systems that maintain student data to allow access only to authorized persons or software programs. |
Enable SAML SSO: Superhuman Docs supports open standard SAML 2.0 and can work with your Identity Provider (IdP) of choice. For organizations managing multiple workspaces, Doc's SAML implementation supports provisioning access to specified workspaces based on IdP user attributes. Packs control: All integrations and Packs can be configured to be disallowed or require admin approval prior to installation. The Packs platform also provides advanced configurations for admins to control data schemas/type allowed in Packs. Personal access tokens: Personal access tokens can be disabled at the organization level by Superhuman Support. |
|
Unique User Identification Assign a unique name and/or number for identifying and tracking user identity. |
SAML/SCIM: In addition to SAML login, Docs has a SCIM API allowing admins to provision, manage, and deprovision members directly from their IdPs. |
|
Automatic Logoff Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. |
Session period: The default session period is 30 days. Customers who require a different session period may reach out to support to set a custom session timer. |
|
Audit Controls Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use education records. |
Audit log: Superhuman Docs has an in-product Audit log dashboard that lists the audit events for your organization. Admin API: Docs offers an Admin API that can be used to integrate with your preferred SIEM (Security Information and Event Management) system. Superhuman Docs retains these audit events for a year. Customers may use the Admin API to store logs in their preferred SIEMs for longer durations. |
|
Integrity Controls Implement policies and procedures to protect education records from improper alteration or destruction. Implement electronic mechanisms to corroborate that education records have not been altered or destroyed in an unauthorized manner. Implement security measures to ensure that education records are not improperly modified without detection until disposed of. |
Audit Log: Audit logs provide an immutable record of events within an organization. Admin API: The Admin API allows users to integrate with external services for customers who require custom retention and/or backup of their logs. Sharing restrictions: Admins may set sharing restrictions and can prevent external sharing entirely. This includes the ability to enable/disable publishing of docs. Folder permissions: All folders are set to private by default upon creation. Legal holds: Available as a paid add-on. This feature allows admins to place legal holds on users and preserve their docs for a specific amount of time. Workspaces: Admins may restrict the creation of new workspaces by their users. Data Export: Admins may configure the ability for users to export their documents. Admins may export their organization's data at any time. |
|
Transmission Security Implement a mechanism to encrypt education records in transit and at rest. |
Encryption: Superhuman Docs uses the AWS Key Management Service (KMS) to create, maintain, and rotate encryption keys. Data transmitted between customers and Docs' service is protected using TLSv1.2 or higher. Data at rest is encrypted using AES-256 symmetric encryption algorithm. |
|
Data Retention and Disposal Implement policies and procedures to address the final disposition of education records, and/or the hardware or electronic media on which it is stored. |
Data retention and disposal: Deleted documents are kept in our primary storage systems for 7 days to allow for accidental deletions to be reverted. After this 7-day period, they are permanently removed from our primary storage systems. Deleted data will still be retained in backups for 35 days. Once this 35-day retention period is over, the Customer Data will no longer be present in the backups. |
Limitations and restrictions
The following limitations and restrictions apply to your use of Docs to support FERPA compliance.
- Users - Docs is not designed to be the system of record for education records.
- Packs - The Pack Gallery provides access to third-party integrations for tools that work with Docs' services. These services (including two-way sync) are not covered by your agreement with Superhuman and are not part of FERPA-compliant use of Docs. It is up to you, the customer, to 1) determine whether contractual terms (e.g., a DPA) with such a third-party tool provider are required to ensure FERPA compliance, and 2) execute an agreement with such terms directly with the third party.
- Connectors - Docs can be used as a connector or app in certain third-party products. Using Docs integrated through third-party products is not covered by your agreement with Superhuman and is not part of FERPA-compliant use of Docs.
-
Prohibited Fields - Users may not include education records in any of the following:
- Organization names
- URL domains
- Support Services - When submitting support requests, users must not include any education records in the message contents or in any file uploads, including screenshots, documents, etc. This includes all support methods (in-product widget, email, phone, chat, etc.).
- Docs AI Features - For the time being, Docs AI will be unavailable for customers requiring FERPA-compliant Docs.
Privacy, certifications, and compliance
It is important to note that there is no certification recognized by the US Department of Education for FERPA compliance and that complying with FERPA is a shared responsibility between the customer and Superhuman.
Please review our terms, privacy policy, and DPA for more information about our privacy practices.