Control Evidence Matrix

What each published control claims, and how strongly it is verified.

Last updated August 24, 2026

StorylineIQ publishes a control only when a verification basis exists. 31 controls are published here; 26 are backed by automated tests that run on every change. Controls without a verification basis are not published as capabilities — they appear in the open evidence list below instead.

What the verification labels mean

  • VERIFIED IN CODEEnforced by application code in this repository and covered by automated tests that run in CI.
  • VERIFIED BY CONFIGURATIONEnforced by a setting StorylineIQ owns and can re-read on demand; not provable by code alone.
  • VERIFIED BY EXTERNAL EVIDENCEConfirmed by written third-party or platform evidence held on file.
  • DOCUMENTEDA written process or decision exists. No automated test or external attestation supports it yet.
  • EVIDENCE REQUIREDThe claim cannot be substantiated yet. It is never published as a capability statement.

Review areas

AreaPositionPublished controlsOpen evidence
Data PrivacySTRONGAC-05, AC-07, AI-01, AI-02, AI-03, AI-04, DR-01, DR-03, PR-01, PR-02, RT-01DR-02 — not claimed; open evidence item
Data Access / RightsSTRONGAC-03, AC-07, AU-01, AU-03, DR-01, DR-03DR-02 — not claimed; open evidence item
Data SecuritySTRONG WITH EVIDENCE GAPAC-01, AC-02, AC-03, AC-07, AI-01, AI-05, AU-01, AU-02, AU-03, AU-04, AU-05, DP-01, DP-03, DR-03, IR-01, RT-02DP-02 — not claimed; open evidence item
Data Integrity / RecoveryNEEDS REMEDIATIONAC-01BR-01, BR-02, BR-03 — not claimed; open evidence item
Data RetentionSTRONGAU-02, DR-03, RT-01, RT-02DR-02 — not claimed; open evidence item

These review areas are StorylineIQ’s own mapping. StorylineIQ has not been rated, reviewed, or certified by EdPrivacy or any other assessor.

Published controls

IDControlObjectiveVerificationReviewed
AC-01Tenant isolationA user authenticated in one district can never read or write another district's records.VERIFIED IN CODE2 automated checks2026-08-24
AC-02Role-based access controlAuthorization is decided by role in the database, not by hiding interface elements.VERIFIED IN CODE3 automated checks2026-08-24
AC-03Multi-factor authenticationA district can require a second authentication factor for all of its staff accounts.VERIFIED IN CODE3 automated checks2026-08-24
AC-04Account provisioningOnly people the district invites can obtain an account.VERIFIED BY CONFIGURATION2 automated checks2026-08-24
AC-05Cross-class student contextEducators who share a student can see context without gaining a broader data grant.VERIFIED IN CODE2 automated checks2026-08-24
AC-06Session controlsAn unattended session in a classroom does not stay open indefinitely.VERIFIED BY CONFIGURATION1 automated check2026-08-24
AC-07Privileged and administrative accessElevated database access is never reachable from the browser or from ordinary reads.VERIFIED IN CODE2 automated checks2026-08-24
DP-01Encryption in transitDistrict data is never transmitted over an unencrypted channel.VERIFIED BY CONFIGURATION2026-08-24
DP-03Secrets handlingCredentials and API keys never reach the browser or the repository.VERIFIED IN CODE1 automated check2026-08-24
DP-04Practice-data segregationTraining/practice activity can never contaminate a district's real records or reports.VERIFIED IN CODE2 automated checks2026-08-24
DP-05Uploaded document containmentPlan documents and roster files are never publicly reachable.VERIFIED BY CONFIGURATION1 automated check2026-08-24
AI-01Approved AI boundaryEvery model request leaves the product through one reviewable server-side path.VERIFIED IN CODE2026-08-24
AI-02Identifier redaction before AI transmissionDirect student identifiers are removed before documentation is sent for summarization.VERIFIED IN CODE2 automated checks2026-08-24
AI-03Human confirmation of AI outputAI output never becomes a record or a decision without an educator acting on it.VERIFIED IN CODE3 automated checks2026-08-24
AI-04No advertising, sale, or model training by StorylineIQStudent data is used only for the district's educational purpose.DOCUMENTED2026-08-24
AI-05Telemetry sanitationDiagnostic and analytics signals do not carry student content.VERIFIED IN CODE1 automated check2026-08-24
AU-01Sensitive-action audit logA district can reconstruct who did what to a student record and when.VERIFIED IN CODE2 automated checks2026-08-24
AU-02Audit record content disciplineAudit records are useful for review without becoming a second copy of student content.VERIFIED IN CODE1 automated check2026-08-24
AU-03Export and packet auditabilityAny assembly of a student's record into a portable document is traceable.VERIFIED IN CODE1 automated check2026-08-24
AU-04Cross-class access auditabilityViewing a student outside your own class is visible to district reviewers.VERIFIED IN CODE1 automated check2026-08-24
AU-05Administrative change auditabilityChanges to who can see what are reviewable after the fact.VERIFIED IN CODE2 automated checks2026-08-24
DR-01Student record review and exportA district can answer a parent inspection request without engineering help.DOCUMENTED1 automated check2026-08-24
DR-03Controlled deletionDestructive removal is authorized, scoped, and auditable — never ad hoc.VERIFIED IN CODE2 automated checks2026-08-24
RT-01Configured retention windowsData is not kept longer than the district's chosen window.VERIFIED BY CONFIGURATION1 automated check2026-08-24
RT-02District offboardingA district that leaves gets its data out and then out of production.VERIFIED IN CODE5 automated checks2026-08-24
AS-01Input validation and typingUntrusted input cannot reach data access unvalidated.VERIFIED IN CODE2 automated checks2026-08-24
AS-02Dependency managementKnown-vulnerable dependencies do not stay in the product.DOCUMENTED2026-08-24
IR-01Incident responseDistricts know how an incident is handled and how to reach us.DOCUMENTED2026-08-24
PR-01Data inventory as an architectural controlNo new data source can enter the product unclassified.VERIFIED IN CODE1 automated check2026-08-24
PR-02Subprocessor registerThe published subprocessor list matches the services that actually receive data.VERIFIED IN CODE1 automated check2026-08-24
PR-03Accessibility practiceEducators using assistive technology can complete core workflows.DOCUMENTED2 automated checks2026-08-24

Open evidence items

These controls are owned by the managed hosting platform rather than by StorylineIQ application code. StorylineIQ has requested written confirmation and makes no public claim until it is on file.

  • BR-01 Backups Confirmation that automated database backups run, with cadence, retention period, storage region, encryption, and whether object storage is covered. No public claim is made for BR-01. The Trust Center and procurement packet state the gap instead.
  • BR-02 Restore procedure and testing Point-in-time recovery availability and window, the self-service restore path, expected restore duration, and whether storage can be restored to a point in time. BR-02 is published only as a documented process; no quantitative figure is claimed.
  • BR-03 RPO / RTO Stated recovery point objective, recovery time objective, uptime commitment, and incident-notification commitment, plus whether these are contractual. No public claim is made for BR-03. The Trust Center and procurement packet state the gap instead.
  • DP-02 Encryption at rest Written confirmation that database volumes, object storage, and backups are encrypted at rest, with cipher, key custody, and rotation practice. No public claim is made for DP-02. The Trust Center and procurement packet state the gap instead.

Evidence last reviewed 2026-08-24. See the procurement packet for the full narrative responses and the state readiness mapping for Texas requirements.