Security & Compliance
Schools entrust technology providers with information about students, families, employees, visitors, and daily district operations. MEFTii takes that responsibility seriously. Security and privacy are not add-ons to the MEFTii platform. They are part of how the platform is designed, operated, and supported.
HITRUST Certified
MEFTii has achieved HITRUST CSF® e1 Certification for its platform, demonstrating that key cybersecurity controls have been independently validated. This provides districts with independent assurance that MEFTii has implemented defined controls designed to help protect sensitive information.
U.S.-Hosted Customer Data
MEFTii customer production data is hosted on Amazon Web Services (AWS) infrastructure located in the United States. Our hosting architecture provides the security, availability, and scalability necessary to support districts of different sizes while maintaining a consistent approach to data protection.
U.S.-Based Access to Customer Data
Access to customer production data is limited to authorized U.S.-based MEFTii employees when access is necessary to perform their responsibilities. MEFTii's offshore or non-U.S.-based application developers do not have access to customer production data.
FERPA
MEFTii supports schools and districts in protecting education records subject to the Family Educational Rights and Privacy Act (FERPA). When applicable under a district agreement, MEFTii may perform services as a School Official and processes education-record information only for authorized purposes. MEFTii does not use student education records for unrelated commercial purposes.
Children's Privacy
MEFTii's services are designed for use in the K–12 environment. When COPPA applies and a school or district provides authorization permitted by law, MEFTii uses children's information only to provide the school-authorized service and not for unrelated commercial purposes.
We Don't Sell Student Data
MEFTii does not sell student personal information. We also do not use student personal information for targeted advertising or create commercial advertising profiles from student information.
Controlled Access
MEFTii applies role-based and operational controls intended to limit access to information to authorized individuals with a legitimate need for that access. Customer access and permissions can be managed according to district roles and responsibilities.
Data Protection
MEFTii maintains administrative, technical, and organizational safeguards designed to protect customer information from unauthorized access, disclosure, alteration, loss, or misuse. Security practices are continually reviewed as technology, threats, regulatory requirements, and the MEFTii platform evolve.
Data Retention
MEFTii retains customer information only as necessary to provide authorized services and meet applicable contractual, operational, security, and legal requirements. Following termination of service, customer data is retained and deleted in accordance with the district's agreement and applicable law.
Accessibility
MEFTii is committed to providing accessible digital experiences and uses WCAG 2.1 Level AA as its accessibility goal for web and mobile experiences.
Questions About Security or Compliance?
Districts evaluating MEFTii may contact us to discuss security, privacy, compliance, data handling, or procurement requirements.
Contact
MEFTii, Inc.
8708 Technology Forest Place, Suite 175 PMB 1018
The Woodlands, TX 77381
[email protected]
