PowerSchool's breach exposed roughly 62.4 million students' records from one compromised support-portal credential with no MFA. If your LMS, learning app, or student portal was vibe-coded with Lovable, Bolt, or Replit, we find and fix the gaps before a district's security review, or a breach, finds them first.
Get a Free Security Scan Book an AI App AuditEdtech vendors sit inside the most heavily regulated consumer-data niche in the US: student data is protected by FERPA, the amended COPPA Rule, and 130+ state student-privacy laws in 41 states, many requiring a signed Data Privacy Agreement before a district may legally use a product. The sector just lived through the largest student-data breaches in US history, and researchers scanning vibe-coded apps found one Lovable-showcased edtech app exposing 18,697 user records, including 4,538 student accounts, with inverted auth logic granting anonymous full access.
These are the apps we see edtech founders and school-facing vendors stand up fast with AI builders — and exactly where the risk sits in each one.
Flashcards, spelling apps, and AI homework helpers aimed at under-13 users trigger the amended COPPA Rule, which requires verifiable parental consent, a written security program, and defined retention limits. Default AI builds ship with no age gate or consent flow, at penalties up to per violation.
These hold grades, enrollment, and student–teacher messages — exactly what attackers exfiltrated from Canvas (3.65TB claimed, May 2026). AI scaffolds routinely ship with broken object-level authorization, letting any logged-in user read another student's records.
Session notes, minors' schedules, home addresses, and parent payment data often sit in one table. Vibe-coded apps have been found with exposed PII and hundreds of leaked secrets in live scans.
PowerSchool proved a single compromised credential with no MFA on a support portal can expose an entire student population. Texas's AG sued specifically over missing MFA, weak access controls, and unencrypted data.
Grades and disability/IEP accommodations are FERPA "education records." Using them beyond the school's instructional purpose — for model training or marketing — breaks the FERPA school-official exception and California's SOPIPA.
Custody flags, restraining-order notes, and medication schedules were among the fields exposed in the PowerSchool breach. AI builders default to permissive access rules, and one audit found roughly 70% of sampled Lovable apps had row-level security disabled.
Edtech vendors face a federal student-privacy law, a still-unresolved COPPA overlap, and a state-by-state patchwork that follows the product into every district that buys it.
| Regulation | When It Applies | Penalty |
|---|---|---|
| FERPA (school-official exception) | Vendor receives education records; must use data only for the contracted purpose, no redisclosure | Loss of federal ED funding falls on the district, so districts refuse non-compliant vendors; no private right of action |
| COPPA (amended, full compliance Apr 22, 2026) | Child-directed service or actual knowledge of under-13 users | Up to /violation |
| California SOPIPA | Any site/app/service designed and marketed for K-12, even without a school contract; bans targeted ads and sale of student data | CA AG enforcement via UCL; first KOPIPA enforcement (Illuminate) totaled .1M with NY/CT |
| NY Education Law §2-d | Any third-party contractor receiving student data from NY schools; requires a signed DPA | Civil penalties –; breach violations the greater of or /student affected |
| ~130 state student-privacy laws (41 states) | Varies by state; most follow the product wherever a district uses it | State AG enforcement |
| District procurement gate (SDPC DPA) | CA/NY/IL/CO/CT require a signed DPA before any product touches student data | Not a fine — a blocked sale |
| GDPR / UK GDPR + ICO Children's Code | Serving EU/UK students, especially beyond the school's instructions | Up to €20M or 4% of turnover (UK £17.5M/4%) |
A single compromised subcontractor credential with no MFA on a support portal exposed ~62.4M students' and 9.5M teachers' records, including SSNs, medical data, grades, and custody/restraining-order notes. A ransom was paid; districts were re-extorted in May 2025.
ShinyHunters exploited a flaw tied to the Free-for-Teacher program; attackers claimed 3.65TB across ~275M user records, spanning roughly 8,800–9,000 institutions. Names, emails, student IDs, and Canvas Inbox messages were confirmed exposed.
.1M settlement with NY, CA, and CT AGs over a 2022 breach affecting 10.1M students — the first-ever enforcement under CA's KOPIPA and CT's student-privacy law. An FTC consent order finalized June 5, 2026 added mandatory data-minimization and a decade of third-party security assessments.
Attackers entered via an exposed GitLab personal access token in a public .git/config, found hardcoded AWS/GCP/Salesforce credentials in source, and exfiltrated data over months.
A researcher found 16 vulnerabilities (6 critical) in an AI-built edtech app on Lovable's Discover page, exposing 18,697 user records including 4,538 student accounts through inverted auth logic.
Not automatically. FERPA's school-official exception requires the vendor to be under the district's direct control, use data only for the contracted purpose, and never redisclose it. AI builders don't generate these usage restrictions or the written agreement districts require — that has to be added deliberately.
Yes, in most states with meaningful edtech markets. California, New York, Illinois, Colorado, and Connecticut all require a signed DPA before a district may legally use your product. Over 275,000 standardized DPAs have been executed through the Student Data Privacy Consortium since 2016 — it's standard procurement plumbing, not optional paperwork.
Yes, if your app is child-directed or you have actual knowledge of under-13 users. Full compliance is required by April 22, 2026, including verifiable parental consent, a written security program, and defined data-retention limits, with penalties up to per violation.
A single compromised support-portal credential with no MFA exposed roughly 62.4 million students' records, including SSNs and medical data. It matters because AI-built support and admin portals routinely ship without MFA by default — the same root cause.
Possibly. A researcher found 16 vulnerabilities, 6 critical, in one Lovable-showcased edtech app, exposing 18,697 records including 4,538 student accounts through inverted authorization logic. We test specifically for this class of access-control bug.
Most LMS, learning-app, or student-portal audits complete within a few business days. We start with a free automated scan, then a manual review of authentication, RLS/database access, and MFA coverage before handing you a prioritized fix list you can show a district.
Related searches: FERPA compliance for edtech vendors · student data privacy agreement for edtech startups · how to sign the SDPC national DPA · COPPA compliance checklist for education apps 2026 · sell edtech to school districts security requirements · NY Ed Law 2-d compliance for vendors · SOPIPA compliance California edtech · is my AI-built app FERPA compliant · edtech app security audit · fix Supabase row level security education app
Get a free automated scan of your LMS, learning app, or student portal — then a full audit if you need one.
Get Your Free Security Scan