Information Security Policy (Data Security & Privacy Plan)
AskElira’s Data Security and Privacy Plan under 8 NYCRR § 121.6 — the administrative, technical, and physical safeguards behind the DPA and §2-d Addendum.
What it is
The Data Security and Privacy Plan (8 NYCRR § 121.6) attached to each school’s DPA — mapped to NY Ed Law §2-d, 8 NYCRR Part 121, FERPA, and the NIST Cybersecurity Framework.
Safeguards
Encryption in transit and at rest, envelope-encrypted school credentials, least-privilege access, quiet-hour and consent gates enforced in code, and 24/7 automated security monitoring with a 48-hour school-notification standard.
People controls
Privacy/security training before anyone touches Student Data and annually thereafter, background checks, and a named security lead and data-privacy contact.
Vendors
Every subprocessor with access to Student Data is bound in writing to equivalent encryption, breach-notice, and retention/deletion obligations; schools get 30 days’ notice before changes.
Insurance & risk transfer
Beyond the controls, AskElira carries Cyber Liability insurance (United Specialty Insurance Company, A.M. Best A-rated) with $1M privacy, privacy-regulatory, network-security, and breach-response limits, plus $1M General and $1M Professional (Tech E&O) liability — so a security or privacy incident is backed by real coverage, not just a promise. See the Insurance & Liability Coverage summary.
Honest scope
Controls are sized to a small company and reviewed as school volume grows; open items (e.g. SOC 2 timing) are flagged in the document itself rather than papered over.