QuantCore Learning Hub
Security & Data-Privacy Compliance
Last Updated: June 19, 2026 · Effective: June 19, 2026
The short version: The QuantCore Learning Hub is a financial-literacy platform built for K–12 schools. We collect the minimum data needed to teach, we host on SOC 2-certified infrastructure (Supabase and Vercel), and we align our practices with FERPA, COPPA, New York Education Law § 2-d, and the NIST Cybersecurity Framework. Our AEGIS AI assistant analyzes public market data only — it never sends student names, emails, IDs, grades, or any education record to an external AI service. This page documents our readiness for the New York City Public Schools (NYCPS) vendor-compliance process.
This page explains how QuantCore.AI (“we,” “our,” “us”) secures the QuantCore Learning Hub (the “Learning Hub”), how data flows through the platform, and how we satisfy the public-school vendor-compliance requirements that school districts — including the New York City Public Schools — apply before a product may be used with students. It is written for school administrators, privacy officers, IT-security reviewers, and parents. It complements, and should be read alongside, our Privacy Policy and Terms of Use.
1. New York City Public Schools (NYCPS) Vendor-Compliance Process
NYCPS requires vendors that provide software or web/mobile products touching student or staff data to complete a standardized data-privacy and security review before a school may use the product. The process is initiated by the school — a principal, superintendent, or division executive submits the request through the Enterprise Request Management Application (ERMA) — after which the vendor (QuantCore.AI) completes its parts. For a web-based, AI-enabled product like the Learning Hub, the process has up to four components, summarized below with our readiness status.
| Component | Who / What | Our Status |
|---|---|---|
| OneTrust Vendor Assessment | Required of all vendors. Covers organization details, the types of NYCPS data accessed (view vs. store), AI-technology disclosures, IT-security practices, and cloud-services information across eight adaptive sections. | Ready. Responses prepared; we disclose AEGIS as an AI feature and document its data flow (see Section 5). |
| Data Processing Agreement (DPA) | Required of all vendors. Commits the vendor to NY Education Law § 2-d and its regulations, with Attachments A–E (Services Description, Data Privacy & Security Plan, Parents’ Bill of Rights, Third-Party Information Security Requirements, Certificate of Records Disposal). | Ready to execute. We sign the NYCPS DPA and supply all attachments, including a public-facing Parents’ Bill of Rights. |
| IT Security Review | Required of any vendor providing software/web/mobile products. Evaluates the vendor against NYC Information Security Policies, ISO 27001, and NIST standards. | Ready. Our controls map to the NIST Cybersecurity Framework (Section 6); SOC 2 Type II is in progress. |
| OTI Cloud Review | Required of any cloud-based product. Vendor completes the Cloud Review Form in OneTrust for review by the NYC Office of Technology & Innovation (OTI). | Ready. The Learning Hub is delivered via SOC 2-certified cloud infrastructure (Vercel + Supabase); architecture and sub-processors are documented in Sections 4 and 7. |
2. Regulatory & Standards Alignment
We comply with the federal and state laws and the security standards that apply to school vendors, applying the strictest applicable standard everywhere we operate:
| Framework | How We Align |
|---|---|
| FERPA (20 U.S.C. § 1232g) | When a school uses the Learning Hub, we act as a “school official” with a legitimate educational interest under 34 C.F.R. § 99.31(a)(1). Education records stay under the school’s control; we are bound by FERPA’s re-disclosure limits. |
| NY Education Law § 2-d & Part 121 | We sign the NYCPS DPA, publish a Parents’ Bill of Rights, maintain a Data Security & Privacy Plan, and meet the breach-notification and data-return obligations of Section 2-d. |
| Chancellor’s Regulation A-820 | We handle student records consistent with the confidentiality and disclosure rules of A-820. |
| COPPA | For students under 13 on school accounts, the school provides consent under the FTC school-authorization doctrine. We do not collect personal information from children under 13 outside the school context. |
| NIST Cybersecurity Framework | Our administrative, technical, and physical safeguards are organized around the NIST CSF functions (Identify, Protect, Detect, Respond, Recover). See Section 6. |
| ISO 27001 / NYC Information Security Policies | Our controls map to ISO 27001 domains and the NYC Information Security Policies evaluated during the IT Security Review. |
| State student- & consumer-privacy laws | SOPIPA (CA), and the consumer-privacy laws of CA (CCPA/CPRA), VA, CO, CT, UT and others as they take effect — we apply the strictest applicable standard. |
3. What Data We Collect — and Minimize
We collect only what is necessary to operate a financial-literacy platform. Student data is collected on behalf of, and controlled by, the school.
| Category | Examples | Purpose |
|---|---|---|
| Account information | Name, school email, grade level, school name (school accounts); password handled by our authentication provider. | Create and secure accounts; deliver grade-appropriate content. |
| Learning activity | Lessons completed, quiz/exam scores, simulated (paper) trading results, progress. | Deliver lessons, track progress, report to teachers. |
| AEGIS queries | The market questions a student types (e.g. “analyze NVDA”) and the AI’s responses. | Provide market-analysis tutoring; stored as conversation history scoped to the user’s account. |
| Device & technical data | IP address, browser/OS, log data, error telemetry. | Operate, secure, and debug the platform. |
4. Where the Platform Runs (Cloud Infrastructure)
The Learning Hub is hosted and operated entirely within the United States on established, independently certified cloud providers. This is the basis of our OTI Cloud Review submission.
| Provider | Role | Relevant Certifications |
|---|---|---|
| Vercel | Application hosting and global edge delivery for the web app and APIs. | SOC 2 Type II; ISO 27001; data encrypted in transit (TLS). |
| Supabase (PostgreSQL) | Primary database for accounts, learning records, and AEGIS conversation history. Hosted in US regions. | SOC 2 Type II; HIPAA-eligible; encryption at rest (AES-256) and in transit; row-level security. |
| Upstash Redis | Caching and rate-limiting. | SOC 2; encryption in transit and at rest. |
| Market-data & AI providers | Public market data (Polygon, Unusual Whales, CoinMarketCap) and the AEGIS language model (xAI). | Receive market data and the user’s typed query only — never student records (see Section 5). |
A current, itemized list of sub-processors is maintained at qntcore.ai/subprocessors and updated whenever it changes. Every sub-processor is contractually bound to the same confidentiality, security, and use restrictions that apply to us.
5. The AEGIS AI Assistant — How It Handles Data
5.1 What AEGIS is for
AEGIS (“Adaptive Engine for Guided Investment Study”) helps students understand markets. A student asks a question about a stock, crypto asset, or options contract (for example, “What’s the read on TSLA?”) and AEGIS returns an educational, institutional-style briefing. All trading on the platform is simulated; AEGIS provides analysis for learning, not financial advice.
5.2 Exactly what is sent to the external AI model
When a student submits a query, our backend assembles a payload for the language model that contains only the following:
- The market question the student typed (e.g. a ticker symbol or a sentence about a market).
- Public market data we fetch from financial data providers: prices, trading volume, technical indicators (RSI, MACD), market capitalization, options data (Greeks, open interest), macro snapshots (S&P 500, US Dollar Index, 10-year Treasury yield), and public news headlines for the asset.
- A fixed system instruction that defines AEGIS’s analytical persona and output format.
- For follow-up questions in the same chat, the prior market questions and AEGIS answers in that conversation, used purely as context.
That is the complete list. The payload is constructed deterministically by our code from market-data feeds — there is no field in it for a student’s name, email, ID, grade, school, or any other personal identifier, and none is added.
5.3 How a student’s identity is kept separate
Students must be signed in to use AEGIS, and we store each conversation so a student can revisit it. We do this using an internal account identifier (a random user ID) that lives only in our own database. That identifier is used to scope and retrieve history on our servers; it is not included in the request to the external AI model. The link between a conversation and a real student exists only inside our SOC 2-certified database, never at the AI provider.
5.4 The AI provider does not train on our data
AEGIS uses xAI’s Grok model through xAI’s business API (api.x.ai), governed by xAI’s enterprise terms — not the consumer Grok product. Under those terms, business API inputs and outputs are not used to train xAI’s foundation models in the way consumer chats may be, and xAI offers a Zero Data Retention (ZDR) option for enterprise accounts under which prompts and completions are processed in real time and never persisted. Because our payload already excludes all student PII, even the data that does transit to the model contains no education record.
5.5 Transparency, bias, and human understanding
Consistent with NYCPS AI guidance, AEGIS:
- Is clearly disclosed to schools as an AI feature, with this documented data flow.
- Produces explanations a student and teacher can read and understand — it states a verdict and the reasoning, not an opaque score alone.
- Does not make consequential decisions about students (no grading, discipline, or eligibility decisions). It is an educational explainer.
- Is held to the same privacy and security standards as the rest of the platform; if we add or change AI features, we will notify NYCPS as required.
- Carries an explicit disclaimer that its output is algorithmic market analysis for educational use, not financial advice.
5.6 The data-flow, step by step
For a single AEGIS request, data moves as follows:
- 1. Student types a market question in the Learning Hub and is authenticated.
- 2. Our backend fetches public market data for the asset from financial-data providers.
- 3. A deterministic engine computes technical indicators from that market data.
- 4. We send the market question + market data to xAI’s Grok API to write the narrative analysis. No PII is included.
- 5. The streamed answer is returned to the student.
- 6. The question and answer are saved to our database, scoped by internal user ID, so the student can revisit the conversation. The student can delete a conversation at any time.
6. How We Protect Information
We use industry-standard administrative, technical, and physical safeguards aligned with the NIST Cybersecurity Framework.
| Control | How We Implement It |
|---|---|
| Encryption | All personal information is encrypted in transit (TLS 1.2+) and at rest (AES-256). Backups are encrypted. |
| Access control & authentication | Authenticated sessions for all student-facing features; least-privilege access to production data; database row-level security. |
| Use limitation | Data is used only for the contracted educational purpose. We never sell personal information, use student data for advertising, or train AI models on identifiable student data. |
| Breach notification | We notify affected schools, users, and regulators of any unauthorized release without unreasonable delay, applying the strictest applicable timeline (as short as 7 calendar days in some states). |
| Monitoring & logging | Application monitoring and error tracking (Sentry) to detect and respond to incidents. |
| Data return / destruction | Upon contract termination, student data is returned to the school or securely destroyed within 60 days, with written confirmation on request (Certificate of Records Disposal). |
| Independent assurance | Hosted on SOC 2 Type II-certified infrastructure; our own SOC 2 Type II assessment is in progress. |
7. Sub-processors
We rely on a small set of vetted vendors. Each is bound by contract to confidentiality, security, and use restrictions equivalent to ours, and the current list is published at qntcore.ai/subprocessors.
| Sub-processor | Function | Data Received |
|---|---|---|
| Vercel | Application hosting / edge delivery | Encrypted application traffic; log/technical data. |
| Supabase | Database & authentication | Account data, learning records, AEGIS history. |
| Upstash | Caching / rate limiting | Transient technical data. |
| xAI | AEGIS language model (market analysis) | Market data + the user’s typed query only — no student PII. |
| Polygon / Unusual Whales / CoinMarketCap | Public market-data feeds | Asset symbols only; no student data. |
| Sentry | Error monitoring | Technical error telemetry. |
8. Data Retention & Destruction
- School-managed accounts: governed by the school’s DPA. By default, student data is returned to the school or securely destroyed within 60 days of contract termination.
- AEGIS conversation history: retained while the account is active; deletable by the user at any time and removed with the account.
- Backups: rotated out within 90 days.
- After these periods, information is deleted or de-identified.
9. Compliance Contacts
For the NYCPS review, a DPA, our Data Security & Privacy Plan, or any security questionnaire, contact us at:
- Email: info@qntcore.ai (subject: “School Compliance” or “DPA Request”)
- Privacy requests: info@qntcore.ai (subject: “Privacy Request”)
- School privacy contact: designated under our DPA with each school
- Website: qntcore.ai
Relevant NYCPS intake channels for schools initiating a request: thirdpartycompliance@schools.nyc.gov (general), ContractorDataSharing@schools.nyc.gov (DPA), and CloudReview@schools.nyc.gov (OTI Cloud Review).
10. Related Documents
- Sub-processors list — every third party that may process data, and what each receives.
- Parents’ Bill of Rights — your rights under NY Education Law § 2-d (DPA Attachment C).
- Privacy Policy and Terms of Use.
- Compliance packet (PDF) — this entire document, formatted for download and offline review.