Agilix does not operate a hosted trust center — trust.agilix.com, security.agilix.com, /trust and /compliance were probed and none exists. What it publishes is a single security page on its own marketing site describing infrastructure controls, encryption, disaster recovery and a completed SOC 2 examination, with the report and the annual penetration-test results available on request rather than openly. For a K-12 vendor handling student data that is a thinner public posture than the sector norm, and the omissions are specific: FERPA is claimed only for BusyBee in the corporate llms.txt and nowhere on the security page, and COPPA, GDPR, ISO 27001 and the state student-data-privacy pledges are not addressed anywhere public.
Agilix maintains a public trust center documenting SOC 2 compliance.
generated: '2026-09-12'
method: searched
source: https://www.agilix.com/security
name: Agilix Labs security and compliance posture
description: >-
Agilix does not operate a hosted trust center — trust.agilix.com, security.agilix.com,
/trust and /compliance were probed and none exists. What it publishes is a single security
page on its own marketing site describing infrastructure controls, encryption, disaster
recovery and a completed SOC 2 examination, with the report and the annual penetration-test
results available on request rather than openly. For a K-12 vendor handling student data
that is a thinner public posture than the sector norm, and the omissions are specific:
FERPA is claimed only for BusyBee in the corporate llms.txt and nowhere on the security
page, and COPPA, GDPR, ISO 27001 and the state student-data-privacy pledges are not
addressed anywhere public.
trust_center_url: null
trust_center_probes:
- url: https://trust.agilix.com
result: NXDOMAIN
- url: https://security.agilix.com
result: NXDOMAIN
- url: https://www.agilix.com/trust
status: 404
- url: https://www.agilix.com/compliance
status: 404
security_page: https://www.agilix.com/security
security_page_status: 200
certifications:
- name: SOC 2
status: examination completed
scope: security, availability, processing integrity, confidentiality, privacy
report_public: false
request_via: security@agilix.com
evidence: https://www.agilix.com/security
quote: >-
"Agilix Labs recently completed its SOC 2 examination, which evaluated our controls
relevant to security, availability, processing integrity, confidentiality, and privacy."
note: >-
No type (I or II), no audit period and no auditor are named on the public page, and no
date is given for "recently".
claims:
- name: FERPA
scope: BusyBee (the AI teaching assistant)
evidence: https://www.agilix.com/llms.txt
quote: 'Runs on AWS; FERPA compliant; student data is not used to train AI models.'
note: >-
Stated in the corporate llms.txt, not on the security page. No FERPA statement covering
Buzz, TutorKit, Publish Anywhere or Dawn was found.
- name: WCAG accessibility
evidence: https://www.agilix.com/accessibility
scope: Buzz and Dawn
not_addressed:
- ISO 27001
- PCI DSS
- HIPAA
- FedRAMP
- GDPR
- COPPA
- Student Privacy Pledge / state student-data-privacy programs
controls_published:
- area: encryption
detail: PKCS #1 SHA-256 with 2048-bit RSA to secure data at rest and in transit.
- area: identity
detail: Google authentication and single sign-on through SAML 2.0.
- area: disaster recovery
detail: Annual testing of recovery processes with multi-location data replication.
- area: infrastructure
detail: >-
Runs on AWS; AWS IAM, Shield, KMS, CloudWatch and CloudTrail are named. Agilix is an AWS
Public Sector Partner (https://www.agilix.com/partners/aws).
- area: shared responsibility
detail: >-
The API documentation carries a Shared Security Responsibility section splitting security
OF Buzz (Agilix) from security IN Buzz (the customer's users, configuration, credentials
and data), plus a Tenant Isolation topic describing how multitenancy is enforced.
url: https://api.agilixbuzz.com/docs/entry/Concept/SharedResponsibility.md
- area: audit trail
detail: >-
The Data Stream emits a full security audit event class — AuthLoginFailed, AuthMFAFailed,
AuthAccountLocked/Unlocked, AuthAdminAuthenticated, AuthAdminPasswordChanged,
AuthProxyLoginStarted/Failed, AuthPasswordRisk, DomainPermissionsCreated/Changed/Deleted,
OAuthClientKeyAdded/Removed — deliverable to the customer's own SIEM.
url: https://api.agilixbuzz.com/docs/entry/Concept/DataStream/Overview.md
- area: password policy
detail: >-
Per-domain policy covering minimum length, character classes, entropy, breached-password
checking, expiry, lockout, stale accounts and MFA enforcement, readable through
GetEffectivePasswordPolicy.
url: https://api.agilixbuzz.com/docs/entry/Schema/PasswordPolicy.md
contacts:
- security@agilix.com
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.