Get a Quote

EdTech App Security

PowerSchool's breach exposed roughly 62.4 million students' records from one compromised support-portal credential with no MFA. If your LMS, learning app, or student portal was vibe-coded with Lovable, Bolt, or Replit, we find and fix the gaps before a district's security review, or a breach, finds them first.

Get a Free Security Scan Book an AI App Audit
WHY EDTECH IS DIFFERENT

Districts Won't Buy What They Can't Vet

Edtech vendors sit inside the most heavily regulated consumer-data niche in the US: student data is protected by FERPA, the amended COPPA Rule, and 130+ state student-privacy laws in 41 states, many requiring a signed Data Privacy Agreement before a district may legally use a product. The sector just lived through the largest student-data breaches in US history, and researchers scanning vibe-coded apps found one Lovable-showcased edtech app exposing 18,697 user records, including 4,538 student accounts, with inverted auth logic granting anonymous full access.

~62.4MStudents' records exposed in the PowerSchool breach, disclosed Jan 2025
275MRecords claimed in the Instructure/Canvas breach, May 2026 — largest education breach on record if claims hold
275,000+Standardized Data Privacy Agreements signed via SDPC since 2016 — no DPA, no sale
18,697Records exposed in one Lovable-showcased edtech app, incl. 4,538 student accounts — Feb 2026
WHAT EDTECH VENDORS BUILD WITH AI

Every One of These Touches a Student's Education Record

These are the apps we see edtech founders and school-facing vendors stand up fast with AI builders — and exactly where the risk sits in each one.

Learning apps / study tools

Flashcards, spelling apps, and AI homework helpers aimed at under-13 users trigger the amended COPPA Rule, which requires verifiable parental consent, a written security program, and defined retention limits. Default AI builds ship with no age gate or consent flow, at penalties up to per violation.

LMS / course platforms

These hold grades, enrollment, and student–teacher messages — exactly what attackers exfiltrated from Canvas (3.65TB claimed, May 2026). AI scaffolds routinely ship with broken object-level authorization, letting any logged-in user read another student's records.

Tutoring / coaching booking platforms

Session notes, minors' schedules, home addresses, and parent payment data often sit in one table. Vibe-coded apps have been found with exposed PII and hundreds of leaked secrets in live scans.

Student portals / SIS-lite dashboards

PowerSchool proved a single compromised credential with no MFA on a support portal can expose an entire student population. Texas's AG sued specifically over missing MFA, weak access controls, and unencrypted data.

Assessment / quiz + gradebook tools

Grades and disability/IEP accommodations are FERPA "education records." Using them beyond the school's instructional purpose — for model training or marketing — breaks the FERPA school-official exception and California's SOPIPA.

Parent dashboards / school communication apps

Custody flags, restraining-order notes, and medication schedules were among the fields exposed in the PowerSchool breach. AI builders default to permissive access rules, and one audit found roughly 70% of sampled Lovable apps had row-level security disabled.

REGULATIONS & PENALTIES

What a Bad Build Actually Costs

Edtech vendors face a federal student-privacy law, a still-unresolved COPPA overlap, and a state-by-state patchwork that follows the product into every district that buys it.

RegulationWhen It AppliesPenalty
FERPA (school-official exception)Vendor receives education records; must use data only for the contracted purpose, no redisclosureLoss of federal ED funding falls on the district, so districts refuse non-compliant vendors; no private right of action
COPPA (amended, full compliance Apr 22, 2026)Child-directed service or actual knowledge of under-13 usersUp to /violation
California SOPIPAAny site/app/service designed and marketed for K-12, even without a school contract; bans targeted ads and sale of student dataCA AG enforcement via UCL; first KOPIPA enforcement (Illuminate) totaled .1M with NY/CT
NY Education Law §2-dAny third-party contractor receiving student data from NY schools; requires a signed DPACivil penalties –; breach violations the greater of or /student affected
~130 state student-privacy laws (41 states)Varies by state; most follow the product wherever a district uses itState AG enforcement
District procurement gate (SDPC DPA)CA/NY/IL/CO/CT require a signed DPA before any product touches student dataNot a fine — a blocked sale
GDPR / UK GDPR + ICO Children's CodeServing EU/UK students, especially beyond the school's instructionsUp to €20M or 4% of turnover (UK £17.5M/4%)
REAL INCIDENTS

This Isn't Hypothetical

Dec 19, 2024, disclosed Jan 2025 — PowerSchool

A single compromised subcontractor credential with no MFA on a support portal exposed ~62.4M students' and 9.5M teachers' records, including SSNs, medical data, grades, and custody/restraining-order notes. A ransom was paid; districts were re-extorted in May 2025.

Apr 29–30, 2026, disclosed May 2026 — Instructure/Canvas

ShinyHunters exploited a flaw tied to the Free-for-Teacher program; attackers claimed 3.65TB across ~275M user records, spanning roughly 8,800–9,000 institutions. Names, emails, student IDs, and Canvas Inbox messages were confirmed exposed.

Nov 6, 2025 — Illuminate Education settlement

.1M settlement with NY, CA, and CT AGs over a 2022 breach affecting 10.1M students — the first-ever enforcement under CA's KOPIPA and CT's student-privacy law. An FTC consent order finalized June 5, 2026 added mandatory data-minimization and a decade of third-party security assessments.

Jan 2025, disclosed May 2025 — Pearson

Attackers entered via an exposed GitLab personal access token in a public .git/config, found hardcoded AWS/GCP/Salesforce credentials in source, and exfiltrated data over months.

Feb 2026 — Lovable edtech app

A researcher found 16 vulnerabilities (6 critical) in an AI-built edtech app on Lovable's Discover page, exposing 18,697 user records including 4,538 student accounts through inverted auth logic.

THE FIX-IT CHECKLIST

What We Check On Every EdTech App

  • Row-level security enabled and tested on every table holding student records, grades, or messages
  • MFA required on any support, admin, or backend portal — the exact gap that caused the PowerSchool breach
  • Age-gating and verifiable parental consent implemented for any under-13 audience, per the amended COPPA Rule
  • Student data is used only for the contracted instructional purpose — no model training or marketing use that would break the FERPA school-official exception
  • Grades, IEP/accommodation data, and health-adjacent fields are encrypted at rest
  • A documented data-retention and deletion schedule exists ahead of district security review
  • Object-level authorization is verified so no logged-in student or parent can read another student's records
  • A signed DPA (SDPC-standard or state-specific) is ready before any district touches the product
FAQ

EdTech App Security Questions

Is my AI-built LMS FERPA compliant?

Not automatically. FERPA's school-official exception requires the vendor to be under the district's direct control, use data only for the contracted purpose, and never redisclose it. AI builders don't generate these usage restrictions or the written agreement districts require — that has to be added deliberately.

Do I need a Data Privacy Agreement to sell to school districts?

Yes, in most states with meaningful edtech markets. California, New York, Illinois, Colorado, and Connecticut all require a signed DPA before a district may legally use your product. Over 275,000 standardized DPAs have been executed through the Student Data Privacy Consortium since 2016 — it's standard procurement plumbing, not optional paperwork.

Does the amended COPPA rule apply to my under-13 learning app?

Yes, if your app is child-directed or you have actual knowledge of under-13 users. Full compliance is required by April 22, 2026, including verifiable parental consent, a written security program, and defined data-retention limits, with penalties up to per violation.

What happened in the PowerSchool breach and why does it matter for my app?

A single compromised support-portal credential with no MFA exposed roughly 62.4 million students' records, including SSNs and medical data. It matters because AI-built support and admin portals routinely ship without MFA by default — the same root cause.

Is my Lovable-built edtech app affected by known vulnerabilities?

Possibly. A researcher found 16 vulnerabilities, 6 critical, in one Lovable-showcased edtech app, exposing 18,697 records including 4,538 student accounts through inverted authorization logic. We test specifically for this class of access-control bug.

How fast can Zooc Digital audit an AI-built edtech app?

Most LMS, learning-app, or student-portal audits complete within a few business days. We start with a free automated scan, then a manual review of authentication, RLS/database access, and MFA coverage before handing you a prioritized fix list you can show a district.

RELATED

More Ways We Can Help

Related searches: FERPA compliance for edtech vendors · student data privacy agreement for edtech startups · how to sign the SDPC national DPA · COPPA compliance checklist for education apps 2026 · sell edtech to school districts security requirements · NY Ed Law 2-d compliance for vendors · SOPIPA compliance California edtech · is my AI-built app FERPA compliant · edtech app security audit · fix Supabase row level security education app

Don't Let a Vibe-Coded App Fail a District Security Review

Get a free automated scan of your LMS, learning app, or student portal — then a full audit if you need one.

Get Your Free Security Scan