How Pathful protects student data: inside our SOC 2 Type 2 audit, Trust Center, and secure SIS integration
What our completed SOC 2 Type 2 audit actually verifies, what our public Trust Center makes available on demand, and how our student information system integrations are built to reduce risk instead of adding to it.
Every school district I talk with is running dozens of connected platforms behind a single sign-on page, and every one of those platforms touches student data in some way. That reality has made 2025 a hard year for education technology. The sector logged an average of 4,388 cyberattacks per organization every week in the second quarter alone, more than any other industry tracked, and 82 percent of K-12 schools experienced a cybersecurity incident between mid-2023 and late 2024.
The most sobering case study is the 2024 PowerSchool breach, which exposed sensitive information tied to more than 70 million students and educators through a single compromised vendor account, and then cascaded across hundreds of districts at once. It is one reason third-party vendor incidents have grown from just 4 percent of reported education breaches in 2023 to 32 percent in 2025, an almost eightfold increase.
So when a district asks a vendor like Pathful about security, they are not asking out of formality. They are asking because the answer determines how exposed their students are. This post walks through three things we believe every district evaluating a Career Readiness and Development platform should understand: what our SOC 2 Type 2 audit actually verifies, what our public Trust Center makes available to you, and how our student information system (SIS) integrations are built to reduce risk rather than add to it.
Why vendor security has become a district's problem, too
The Center for Internet Security describes schools as "target rich, cyber poor", meaning districts hold enormous volumes of sensitive data but often lack the staff and budget to defend it at the level a bank or hospital would. That gap does not disappear when a district hands data to a vendor. It just moves. Every application connected to a district's roster, whether it manages course planning, work-based learning, or career exploration, becomes part of that district's overall attack surface.
That is exactly why procurement and IT teams increasingly build vendor security review into every purchase, and why that review can no longer be a five-minute conversation. It should include specific, verifiable questions: What compliance frameworks does this vendor hold, and who audited them? How is student data encrypted, backed up, and accessed internally? How does the vendor connect to our SIS, and does that connection reduce manual data handling or increase it?
- Education is now the single most attacked sector globally, ahead of healthcare and finance.
- Third-party and vendor-related breaches rose from 4% of incidents in 2023 to 32% in 2025.
- Only about 13% of K-12 students have multi-factor authentication coverage, compared with 93% of teachers and 97% of IT staff, leaving a real identity gap for vendors to help close.
What our SOC 2 Type 2 audit actually verifies

Pathful has completed a SOC 2 Type 2 audit, independently conducted by Sensiba, a licensed CPA firm. One clarification worth making up front: SOC 2 is an attestation report, not a certification. There is no certificate issued and no pass or fail badge in the way ISO 27001 works. Instead, an independent auditor examines a company's actual controls and issues a signed opinion on how well those controls are designed and how well they operate. That distinction matters because it changes what districts should expect to see and ask for.
SOC 2 audits are built around the Trust Services Criteria, a framework from the American Institute of CPAs (AICPA) that covers five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the only category required for every SOC 2 audit, and it forms the baseline for everything else an auditor reviews.
Here is the distinction that matters most for a district evaluating any software vendor. A SOC 2 Type 1 report only confirms that a vendor's controls were designed correctly on a single day. A SOC 2 Type 2 report goes further: the auditor observes those controls operating over a sustained review period, typically several months, and confirms they held up in real, everyday operation, not just on paper. That is the level of assurance districts should expect from any vendor handling student records, and it is the level Pathful's audit, completed with Sensiba, was built to meet.
It is also worth noting that SOC 2 is not a one-time achievement. Like most attestation frameworks, it is an ongoing obligation, and districts should expect to see a refreshed report from any vendor roughly once every twelve months as part of their annual vendor review cycle.
Introducing the Pathful Trust Center
Completing an audit only matters if districts can actually see the results. That is why we built the Pathful Trust Center, a public, self-service hub powered by SafeBase where any district can review our security and compliance posture without waiting on a back-and-forth email chain or a lengthy vendor questionnaire.
From the Trust Center, a district technology director or purchasing officer can independently verify:
- Audit attestation: our completed SOC 2 Type 2 audit, conducted by Sensiba
- Compliance frameworks: CCPA, COPPA, and FERPA
- Accessibility standards: VPAT and WCAG 2.2 AA
- Product security features: audit logging, multi-factor authentication, and role-based access control
- Data security practices: encryption at rest, data backup procedures, and a documented data asset classification approach
- Subprocessors: the full list of vendors Pathful relies on for infrastructure, including AWS, Google Cloud Platform, Salesforce, SendGrid, and Sentry
- Incident response: designated response personnel and a documented incident reporting process
- Policies: a full library of security and privacy policies, including data retention, password, encryption, acceptable use, incident response, and vendor risk management, each with a plain-language summary so a reviewer can get answers to specific questions, for example what encryption methods are used or what the password requirements are, without having to read the full policy document
This transparency matters because a district's security review should not depend on how quickly a sales team can track down a PDF. It should be available on demand, updated continuously, and easy to hand off to a district's own compliance or legal team. For stakeholders who need more than a badge but do not require the full report, Pathful can also provide an attestation status confirmation summarizing the key details, with the complete SOC 2 Type 2 report available to customers under an NDA.

Why secure SIS integration matters just as much as the audit
An attestation report covers how Pathful handles data once it is inside our systems. But for most districts, the more immediate question is how student data gets to Pathful in the first place. That connection point, between a district's student information system and any third-party platform, is one of the most sensitive integration points in a district's entire technology stack, because it is where names, IDs, schedules, and enrollment records actually flow.
Historically, that connection was handled through manually exported spreadsheets, emailed CSV files, or custom one-off data feeds built between a single district and a single vendor. Each of those methods multiplies the number of places student data can be exposed, lost, or intercepted. The industry's answer to that problem is OneRoster, a standardized, vendor-neutral specification from 1EdTech that securely and automatically synchronizes rosters, enrollments, and course data between a SIS and any connected application, without a human copying files between systems.
Pathful connects to PowerSchool, Infinite Campus, and Skyward through OneRoster, with single sign-on support for ClassLink, Clever, and Google. Within Pathful's Course Planner specifically, that connection means course catalogs, student plans, and even parent signature workflows can sync directly from the district's SIS rather than requiring counselors to import and export files by hand every semester.
The security benefit is not just theoretical. Reducing manual data handling reduces the number of places a mistake, a lost file, or a misdirected email can expose student information, which is precisely the kind of gap that has driven the rise in vendor-related breaches over the past two years.
What this means for your next security review
If your district is evaluating Pathful, or re-verifying us as part of an annual vendor review, you do not need to wait on a lengthy questionnaire cycle. Visit the Pathful Trust Center to pull our compliance frameworks, subprocessor list, and pentest summary directly, or request the full SOC 2 Type 2 report under an NDA. If your team has follow-up questions about how our SIS integrations fit into your specific environment, our Client Advocacy team can walk through that with your IT staff.
Trust is not a feature we bolt on after the fact. For a platform that touches career plans, work-based learning records, and postsecondary goals for millions of students, it has to be foundational, verified, and visible. That is what our SOC 2 Type 2 audit, our Trust Center, and our SIS integrations are built to prove.
Frequently asked questions
Yes. An independent auditor examined Pathful's security controls against the AICPA's Trust Services Criteria and confirmed they were not only well designed, but also operated effectively over a sustained period of time.
A Type 1 report confirms controls are designed correctly at a single point in time. A Type 2 report confirms those controls actually operated effectively over a sustained review period, which is the standard Pathful's audit met.
No. SOC 2 is an attestation report issued by an independent CPA firm, not a certification like ISO 27001. Pathful's SOC 2 Type 2 attestation was completed by Sensiba.
It's Pathful's public, self-service security hub at trust.pathful.com, where districts can view compliance frameworks, security features, subprocessors, and request detailed audit documentation.
Pathful connects to PowerSchool, Infinite Campus, and Skyward through the OneRoster standard, with single sign-on support for ClassLink, Clever, and Google.
Yes. The Pathful Trust Center lists compliance with FERPA, COPPA, and CCPA, along with accessibility standards VPAT and WCAG 2.2 AA.
Visit trust.pathful.com to view public compliance information or request access to detailed reports like the full SOC 2 Type 2 report and pentest summary, typically shared under an NDA.
Sources
- Pathful. Pathful Trust Center.
- Pathful. Products.
- DeepStrike. Data Breaches in Education 2025: Trends, Costs & Defense.
- GovTech. Cyber Attacks on Schools Plateaued in 2025, but More Records Exposed.
- Whiteboard Advisors. Cybersecurity Breaches are the "New Normal" for K-12.
- K-12 Dive. Ransomware attacks against education sector slow worldwide.
- NBOA. Cyberattacks on Education Up 23% in 2025.
- SchoolDay. Back to School, Not Back to Breaches.
- A-LIGN. What is SOC 2? Definition, Requirements, and How the Audit Works.
- Secureframe. 2025 Trust Services Criteria for SOC 2.
- Schellman. SOC 2 Trust Services Criteria (TSC) Explained.
- 1EdTech. OneRoster.
Auditor name (Sensiba) and SOC 2 usage terminology in this post are drawn from Pathful's internal SOC 2 Type 2 Audit Completion Pack provided by Sensiba; this internal document is not publicly linkable and is not included in the numbered source list above.