Third Party Index

Snapshot 28226

Document
Privacy policy
URL
https://proctorio.com/company/privacy
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
39937 bytes
SHA-256 (raw)
a94fcc63f7f3ac0a3873495f2c72de86bdbb564b2fb5600268c331ea2c9192d1
SHA-256 (normalized text)
5efe07d8f2eb88f8965a0fb85880ab83698bd088bcda6f6e31e9265141a75344

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy and security
Proctorio exceeds industry standards with layered encryption, third-party audits, and global compliance.
Read our policies
Your privacy, simplified
Proctorio limits the personal information collected from end users. All exam audio, video, and screen recordings are end-to-end encrypted and can only be decrypted by institution-approved representatives.
Three layers are better than one
Proctorio protects exam data at three levels: end to end, in transit, and at rest.
End-to-end
The end-to-end encryption layer is secured using AES-GCM.
In-transit
Data transmitted over TLS 1.2/1.3 with Perfect Forward Secrecy (PFS) support.
At rest
AES-256 encryption, FIPS 140-2 compliant. All data centers are ISO 27001 certified.
Data processor vs data controller
Data processor
As a data processor for "Institutions" (organizations and customers utilizing Proctorio Services), Proctorio processes test-taker Personal Information (information that identifies an individual, as defined more fully under applicable law) only on Institution instructions, and encrypts it in these instances. Exam recordings received from the Institution are protected by end-to-end encryption; only approved "Institution representatives" (instructors, faculty, administrators, and other authorized staff) can access test-taker Personal Information, since Proctorio holds no cryptographic key and cannot access or disclose it.
Data controller
The Institution is the data controller ("controller"), and its privacy policy governs the processing of test-taker and Institution-representative Information. The Privacy Policy below offers test-takers and Institution representatives a general understanding of Proctorio's privacy practices, but they should also review their respective Institution's controlling privacy policies.
Updates
Proctorio is constantly improving and expanding, so we may need to update this Privacy Policy from time to time. If so, Proctorio will post its updated Privacy Policy on Proctorio's Site located at proctorio.com, include a notice on the homepage of proctorio.com, and include updates on Github.
You do not need a GitHub account to view these updates. Visit GitHub to see the page where Proctorio posts them.
Proctorio encourages you to review this Privacy Policy regularly for any changes. Your continued use of the Services and/or continued provision of Personal Information to Proctorio will be subject to the terms of the then-current Privacy Policy.
Compliance
Proctorio makes every effort to comply with the highest privacy and data security standards.
United StatesEuropeCanada
FERPA
The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records and applies to schools receiving funds from the U.S. Department of Education.
Visit FERPA
COPPA
The Children's Online Privacy Protection Act (COPPA) is a federal law that sets forth rigid requirements for websites or online services that may collect information from children under 13 years of age.
Visit COPPA
CCPA
The California Consumer Privacy Act (CCPA) of 2018 gives consumers more control over the personal information that businesses can collect and requires businesses to give consumers notice of their privacy practices.
Visit CCPA
SOPIPA
The Student Online Personal Information Protection Act (SOPIPA) of 2016 prohibits companies and institutions from sharing student data and using that data for targeted advertising on students for a non-educational purpose.
Visit SOPIPA
AB No.1584
The Assembly Bill No. 1584 added to the Education Code authorizes local educational agencies, as appropriate, to enter into a contract with a FERPA compliant 3rd party to provide digital educational software.
Visit AB No.1584
Audits
Independent auditors verify our controls every year. Here is what they certify and how often.
SOC 2 Type 2 audits
Proctorio partners with A-LIGN, an independent, third-party auditor, to complete our SOC 2 Types 1 and 2 (System and Organization Controls) cybersecurity audits. These audits assess the privacy, confidentiality, security, availability, and processing integrity of our software. Being SOC 2-compliant means Proctorio is designed to keep our users' private data secure.
ISO/IEC 27001:2022 certification
In June 2024, Proctorio achieved ISO/IEC 27001:2022 certification, an information security certification developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) to standardize the process for establishing, implementing, operating, reviewing, and maintaining an ISMS (Information Security Management System). ISO 27001 focuses on data confidentiality, integrity, and availability and certifies that our ISMS was implemented and managed effectively.
ISO/IEC 27018:2019 certification
Proctorio achieved ISO/IEC 27018:2019 certification in 2026. An extension of our ISO 27001 certification, ISO 27018 provides 25 additional privacy and security controls. This newer certification from the International Organization for Standardization examines the capacity of Proctorio's cloud to handle personally identifiable information (PII) and ensures user information and data are protected.
ISO/IEC 42001:2023 certification
Proctorio achieved ISO 42001 certification in June 2025. This certification from the International Organization for Standardization is the world's first international standard for AI management systems, establishing requirements for developing, implementing, and maintaining an AI management system. ISO 42001 ensures that Proctorio's artificial intelligence systems are deployed responsibly, with appropriate governance, risk management, and ethical considerations in place to protect users and maintain transparency.
Audited by A-LIGN and partnered with Hackrate
We have partnered with Hackrate, a leading ethical hacking company. This partnership allows us to ensure that our software remains secure, private, and accessible for our end users: test-takers and exam administrators.
Report a vulnerability
Questions about privacy?
Reach out to us
by email
[email protected]
by mail
US: 7340 E. Main St., Suite 203, Scottsdale, AZ 85251
Rest of World: Lindleystraße 8a, 60314 Frankfurt am Main-Bornheim/Ostend, Germany
Ready when you are
Multiple ways to get the help you need.
Got questions?
Contact our sales team for any questions.
Contact sales
Ready to use Proctorio?
You can start right now by signing up.
Sign up today
Need assistance?
We are here for you 24/7, 365 days a year.
Start live chat