Executive Summary
AI-generated analysis for Schoology
Schoology (schoology.com) is an established education technology platform assessed at Risk Tier 3 (Moderate Risk), reflecting a mixed security posture with meaningful strengths alongside gaps that warrant attention before onboarding at medium data access levels. Positive signals include:
Key Findings
- An 18-year domain history indicating a mature, established vendor
- A clean domain reputation with no entries on SURBL, Spamhaus DBL, or URLhaus, and zero threat intelligence pulses
- No sanctions matches across OFAC, EU, or UN watchlists
- No adverse media signals in current or historical scans
- No SEC enforcement filings or FDIC-related concerns
- A valid TLS 1.3 certificate issued by GlobalSign with strong cipher configuration
- Clean IP reputation and no Malware detection service threats detected
- Active trust and security pages published at trust.schoology.com and security.schoology.com Areas
Area Requiring Attention
requiring attention include the absence of publicly verifiable compliance certifications (SOC 2, ISO 27001, HITRUST, FedRAMP) — neither trust page scanning nor independent registry verification returned any confirmed certifications. The HTTP security grade for the marketing site is C- (45/100), with missing Content-Security-Policy and X-Frame-Options headers. Infrastructure scanning identified several sensitive port types (FTP, MySQL, RDP, Elasticsearch) on a CDN edge IP, which warrants clarification. Additionally, the published subprocessor page at schoology.com/subprocessors appears to contain placeholder content with no individual subprocessors listed — a material gap for GDPR Article 28 compliance due diligence. Schoology's AI data usage policy does not state its position on training commitments or data retention timelines, leaving this area unresolved. Overall, Schoology presents as a functional, long-established edtech vendor with no active threat indicators, but the absence of verifiable compliance certifications and incomplete subprocessor transparency prevent a clean approval. Conditional engagement is appropriate pending resolution of the identified documentation gaps.
Independence Statement
All evidence in this report was independently sourced from external data registries, DNS infrastructure, threat intelligence feeds, public web scans, and compliance databases — Schoology had no participation in or advance notice of this assessment.