generated: '2026-09-12' method: searched source: https://www.agilix.com/security name: Agilix Labs security and compliance posture description: >- Agilix does not operate a hosted trust center — trust.agilix.com, security.agilix.com, /trust and /compliance were probed and none exists. What it publishes is a single security page on its own marketing site describing infrastructure controls, encryption, disaster recovery and a completed SOC 2 examination, with the report and the annual penetration-test results available on request rather than openly. For a K-12 vendor handling student data that is a thinner public posture than the sector norm, and the omissions are specific: FERPA is claimed only for BusyBee in the corporate llms.txt and nowhere on the security page, and COPPA, GDPR, ISO 27001 and the state student-data-privacy pledges are not addressed anywhere public. trust_center_url: null trust_center_probes: - url: https://trust.agilix.com result: NXDOMAIN - url: https://security.agilix.com result: NXDOMAIN - url: https://www.agilix.com/trust status: 404 - url: https://www.agilix.com/compliance status: 404 security_page: https://www.agilix.com/security security_page_status: 200 certifications: - name: SOC 2 status: examination completed scope: security, availability, processing integrity, confidentiality, privacy report_public: false request_via: security@agilix.com evidence: https://www.agilix.com/security quote: >- "Agilix Labs recently completed its SOC 2 examination, which evaluated our controls relevant to security, availability, processing integrity, confidentiality, and privacy." note: >- No type (I or II), no audit period and no auditor are named on the public page, and no date is given for "recently". claims: - name: FERPA scope: BusyBee (the AI teaching assistant) evidence: https://www.agilix.com/llms.txt quote: 'Runs on AWS; FERPA compliant; student data is not used to train AI models.' note: >- Stated in the corporate llms.txt, not on the security page. No FERPA statement covering Buzz, TutorKit, Publish Anywhere or Dawn was found. - name: WCAG accessibility evidence: https://www.agilix.com/accessibility scope: Buzz and Dawn not_addressed: - ISO 27001 - PCI DSS - HIPAA - FedRAMP - GDPR - COPPA - Student Privacy Pledge / state student-data-privacy programs controls_published: - area: encryption detail: PKCS #1 SHA-256 with 2048-bit RSA to secure data at rest and in transit. - area: identity detail: Google authentication and single sign-on through SAML 2.0. - area: disaster recovery detail: Annual testing of recovery processes with multi-location data replication. - area: infrastructure detail: >- Runs on AWS; AWS IAM, Shield, KMS, CloudWatch and CloudTrail are named. Agilix is an AWS Public Sector Partner (https://www.agilix.com/partners/aws). - area: shared responsibility detail: >- The API documentation carries a Shared Security Responsibility section splitting security OF Buzz (Agilix) from security IN Buzz (the customer's users, configuration, credentials and data), plus a Tenant Isolation topic describing how multitenancy is enforced. url: https://api.agilixbuzz.com/docs/entry/Concept/SharedResponsibility.md - area: audit trail detail: >- The Data Stream emits a full security audit event class — AuthLoginFailed, AuthMFAFailed, AuthAccountLocked/Unlocked, AuthAdminAuthenticated, AuthAdminPasswordChanged, AuthProxyLoginStarted/Failed, AuthPasswordRisk, DomainPermissionsCreated/Changed/Deleted, OAuthClientKeyAdded/Removed — deliverable to the customer's own SIEM. url: https://api.agilixbuzz.com/docs/entry/Concept/DataStream/Overview.md - area: password policy detail: >- Per-domain policy covering minimum length, character classes, entropy, breached-password checking, expiry, lockout, stale accounts and MFA enforcement, readable through GetEffectivePasswordPolicy. url: https://api.agilixbuzz.com/docs/entry/Schema/PasswordPolicy.md contacts: - security@agilix.com