Trust & data
What we can't prove, and where your students' data actually goes
We have no evidence that PrepGraph works. No study has begun, no result exists, there are no case studies, and nothing here is offered as evidence of effect. What follows is the product as it is. Every number carries a bracket saying what it was counted from and when: [code, 1 Sep 2026] means we read it out of our source, migrations or configuration on that date; [dev content bank, 29 Aug 2026] means it was counted in a development copy of our content database — not production, which we could not query. Treat those counts as as-built rather than as-deployed, and ask us to re-run any of them against production in front of you.
- Studies
- None
- FERPA program
- None
- SOC 2 / VPAT
- Neither
- Data residency
- India
The five questions
The questions the Department of Education says to ask us
The US Department of Education's August 2026 guidance tells schools to ask every technology provider five things. They are answered here in order, including the one where the honest answer is that no evidence exists.
- 01
1. What learning problem does it solve?
A narrow one. PrepGraph does not teach your class; it answers the question a teacher asks on Monday morning. Overnight it bands each activated student on every concept it has evidence for, ranks the class's concepts by which to reteach first, and names the students behind each. A leader gets chapter-level mastery across every class in one table and a single at-risk register merging every class's flagged students, worst first. Misconceptions come from the specific pre-tagged distractor a student chose, not from a raw score. The problem it does not solve is a student who has not used it: every signal comes from tutoring, practice and platform-graded work inside PrepGraph, and teacher-entered marks never reach the model.
- 02
2. When should it be used?
After a unit is taught, as weekly triage, by the teacher who already teaches those students. It should not be used as a placement instrument, a screening tool, an eligibility determination, or as evidence in an IEP, a 504 plan or an MTSS tier decision — the band is a three-level cut on an ability estimate, not a validated score, and none of those uses has been studied. We are putting that warning inside the product on the at-risk register itself, because a register ranked worst-first is exactly what a school reaches for when building a tier list. One consequence to plan for: once your staff maintain these bands and flags, they are part of the education record you hold, and a parent may ask to inspect them and to challenge what they say. We have no parent-facing view and no amendment path, so until we build one your staff carry those requests by hand.
- 03
3. For whom?
High school first, and math and science before anything else. Our strongest US assessment content is college-admissions testing — 3,949 questions built from past ACT and SAT papers [dev content bank, 29 Aug 2026] — and our strongest US course content is a concept map covering 39 AP courses [same source and date]. We would decline an elementary pilot and you should want us to: our US K-12 practice questions are generated by our models, are not teacher-reviewed, and about 8% have passed a solvability check. Three further limits on who this reaches. It is a paid per-student product. We have commissioned no accessibility audit and have no VPAT, so for a student using a screen reader or keyboard-only navigation we cannot tell you it works. And US tutoring is English-only by policy — the tutor declines a request to switch languages — which is your exposure under Title VI and the EEOA, not just our product gap. A grades 6–8 pilot also puts eleven- and twelve-year-olds on the product, squarely inside COPPA, and we have no verifiable parental-consent mechanism.
- 04
4. For how long?
We do not know, and no one should tell you they do: there is no research, ours or anyone's, establishing a dosage for this product. What we can tell you is the mechanism, because it is a setting. A concept shows a band as soon as there is any graded evidence for it — there is no minimum response count in our code [code, 1 Sep 2026] — which means an early band can rest on one or two answers. Treat a fresh grid as thin, and ask us for the response count behind any cell before acting on it. What we would propose is a semester if your calendar allows, with the measurement set up before the first login, a mid-point look at activation and weekly active practice together, and a standing agreement that if the usage is not there we stop rather than let it run empty and produce a number that means nothing.
- 05
5. What evidence shows it works?
None. What we offer instead is instrumentation you own: four measures are implemented in our pilot tooling — activation, weekly active practice, completion, and score change on an instrument the school sets, matched student by student. Four, not six; two more were designed and never built. You choose the baseline instrument, we do not score it, and we will say the limit in the same paragraph as any result: a baseline-versus-final comparison cannot separate our product from ordinary teaching, from the school year, from test timing, or from the attention a pilot attracts. Under the ESSA evidence tiers your authorizer and your Title funding actually use, that is Tier IV at best — a rationale — and a pilot as designed would not reach Tier III. Any figure we publish arrives with how many students took part, how many were approached and declined, how many left, who paid for the work and who conducted it — and the honest answer to the last is that the write-up is vendor-authored: we have appointed no independent reviewer, and a council we fund cannot serve as one. We publish a null on the same terms as a positive result.
Student data
Where your students' data would actually go
Read from our own source, configuration and migrations rather than from a policy document, because a policy document is a statement of intent and this is a statement of fact.
- Where the data lives
- Our production database and cache are in India, on Azure; our identity records are there too. A US-resident deployment does not exist. The only US-region setting in our infrastructure config is an object-storage bucket for images. Detecting a visitor's country changes words on a website; it does not move a database. [code, 1 Sep 2026]
- Cross-border legal reach
- Records held in India sit under Indian law, which gives Indian authorities a legal relationship to them. We have no documented transfer basis, no commitment to notify you of a government demand, and every retention sweep in this product was written to India's DPDP regime rather than to any US schedule.
- Who processes student work
- Provisional subprocessor list, published now rather than at signing so you can check it against your state's prohibited-vendor list: OpenAI, Anthropic, Moonshot (China), Deepgram, Inworld, Google, Sarvam (India), Pinecone, Twilio, Microsoft Azure (India). The contractual version goes in the agreement.
- The China question
- Our default teaching model is Moonshot's Kimi on every deployment where that key is set, at api.moonshot.ai; our own routing code names it as a residency problem, and the only mitigation is off by default and targets southindia, not the US. What reaches it is the tutoring conversation itself. We will tell you in writing whether it is set on the deployment your students would use, we will not place a US school on a PRC-based provider, and we will block it in the routing layer rather than by hoping an environment variable stays unset. [code, 1 Sep 2026]
- Model training and retention terms
- We cannot yet tell you, provider by provider, whether student work may be retained or used to train models. We have not established no-training or zero-retention terms in writing with our providers. Until we can show you that in the agreement, assume we cannot answer it, and do not sign on the assumption that the answer is no.
- The tutor records children
- Every tutoring session is a live voice session and we record it; audio and transcript are swept after 90 days, and deleting an account purges those and uploaded photographs of student work immediately. Three caveats: the window is a setting on our side, not a contract term; both sweeps were written for Indian law; and recorded student voice is treated as a biometric identifier in Illinois and Texas, which require written notice and consent before collection. We do not have that notice text today.
- What is retained
- Everything else survives. Practice attempts, ability estimates, misconception records, entered marks, doubts and roster rows are deactivated rather than erased. There is no export of a student's record, no contract-end bulk purge, and no written retention schedule by data class.
- Deletion
- Account deletion is self-service and operates only on the account making the request. A school cannot direct deletion of a named student's record, and a school-provisioned child account has no sign-in of its own and therefore no deletion path at all. That is a blocker to signing any district agreement, it is ours to fix, and we will not sign a data agreement we cannot perform. [code, 1 Sep 2026]
- Audit logging
- Every change to an assessment mark is written with the value before and after. There is no log of who viewed a student's record — not by your staff and not by ours. A FERPA disclosure record is a different thing again and we do not have one.
- Who at PrepGraph can read student work
- Our team is in India, staff access to student records is not logged, and we have no written least-privilege or access-review policy to show you. Ask this of every vendor; almost none will answer it.
- Open security defect
- During this review we found an access-control defect on a student learning endpoint: it accepted a record id without checking who owned it, so a signed-in student could alter another student's review schedule and ability estimate. It is a write, not a readout, no US school is on the product, and fixing it is a launch condition for this page. We are auditing the remaining student-facing endpoints — two structurally similar defects were found and fixed in another surface earlier this year — and we will publish what that audit finds. The full open-defect register goes to your IT director before a pilot, not after. We make no absolute claim of isolation across every endpoint until that audit is done.
- What isolation we do claim
- Class analytics are readable only by that class's assigned faculty and by administrators of your own tenant, enforced in the query. Within class analytics, students are never shown other students' data.
- Sign-in
- Email and password, or one of three consumer social providers our identity service exposes: Google, Facebook and LinkedIn. We are naming all three because two of them should not be on a product with children on it. None has a school-domain restriction and all auto-create an account with the student role, so a consumer address can create a student account today. No Microsoft or Entra, no SAML. Removing Facebook and LinkedIn and restricting Google to your domain is work we do before a school tenant exists. [code, 1 Sep 2026]
- Rostering
- A file your staff load. We searched our entire codebase for Clever, ClassLink, OneRoster, PowerSchool, Infinite Campus, Google Classroom and LTI: there is no integration code for any of them. The only textual hits at all are the English word "clever" in three unrelated source comments and one stylesheet comment naming Schoology's folder colours. Run the search yourself on a call; we will share the screen.
- Activation
- A student appears in the analytics once their account exists and has been used, not when their name is loaded. The activation path we ship today runs through an India-specific guardian payment or a manual school waiver, so a US charter cannot activate a roster through the product as it stands. Replacing it is work we have not done, and it is the single largest implementation risk in a first pilot.
- Compliance artefacts we do not have
- No FERPA program, no signed district data privacy agreement, no SOC 2, no VPAT, no SDPC membership, and no US privacy notice on our product site — which has no /privacy or /terms route at all [code, 1 Sep 2026]. The order we build them in: a US student DPA written to the FERPA school-official exception with direct-control language, named subprocessors, use restrictions, breach notification and deletion on termination; then school-directed deletion and export; then the contractual subprocessor list and a hard provider block; then a US-resident deployment or a residency commitment with a date in the contract. The first four are prerequisites to signing, not follow-on work. A WCAG 2.1 AA audit and a VPAT are not scheduled. SOC 2 has not started — the only SOC 2 material anywhere near us is an in-progress Type 1 evidence file belonging to a different company with a different product, and citing it for PrepGraph would be misattribution. None of the four prerequisites has started; realistically none completes inside this school year, and if any of them gates your signature we are a next-year conversation.
- The legal commitments we will make now
- PrepGraph acts as a school official under your direct control. Student data is used only for the purposes you disclosed it for, we claim no ownership of it, we will not sell it, will not use it for targeted advertising, will not build profiles for non-educational purposes, and will not market to your families using a roster you gave us. These cost us nothing to state and they go in the agreement verbatim.
- US standards
- We have ingested no US state's official standards and no question in our bank carries a standards code. What sits in our database under state names is worse than empty: a third-party scrape of a commercial competitor's website carrying that competitor's proprietary skill codes and titles — roughly 11,585 rows under Texas alone [dev content bank, 29 Aug 2026] — flagged in our own file as not the official legal source and marked for rebuild. We are removing it rather than shipping it, and no coverage number will ever be quoted to you from it.
- Texas specifically
- We hold no TEKS codes. The row in our database carrying the TEKS name is scoped to Indian Class 11 and 12 chemistry and biology concepts, and it is the only US row in our catalogue whose serving flag is on with no verification metadata behind it — which makes it the one US curriculum our runtime will serve on its own authority. A Texas class configured against it today would be taught Indian curriculum under a Texas label. It is a defect, not a roadmap item, and it is disabled before any Texas conversation.
- What a US student is actually taught from
- Our own truth record marks every US grade and state row as not approved for tutoring use; they serve at all because a production migration waives that flag and substitutes our Indian NCERT-anchored teaching-unit library. That waiver, not a US curriculum, is what a US student sees today.
- Practice items
- 175,175 items, of which zero carry a fitted psychometric calibration and 49 carry any IRT parameter at all — mapped by a script from a 1-to-5 difficulty label a human typed, with no record of who typed it. Fitting a real calibration needs about thirty responses per item and has never been run. Of the items attached to US-standards concepts, about 8% (536 of roughly 6,400) have passed a solvability check, and the read-time gate that would withhold the rest ships switched off because turning it on would leave roughly 60% of concepts with no servable item. [dev content bank, 29 Aug 2026]
- Lessons
- Every lesson carries a conformance record against its source chapter, and that record is not a serving gate. Roughly 9,700 lessons whose latest verdict is red — including some flagged as contradicting the chapter they were written from — are served to students exactly like lessons that passed; we withhold only the small number of outright factual contradictions. Making conformance a serving gate is on our list and is not done. [dev content bank, 29 Aug 2026]
- ACT, SAT and AP content
- 3,949 items built from past ACT and SAT papers, and a concept map covering 39 AP course outlines [dev content bank, 29 Aug 2026]. We are reviewing our licensing position on every one of them and will show a school the source and that position before it signs. We are not affiliated with, endorsed by or licensed by ACT, Inc. or the College Board; we name their exams to say what our content covers, not to imply either has reviewed us.
- Screens that are wrong today
- Our leader dashboard ships a chart headed "Student Growth" that plots daily active-student headcount, and an "Average Mastery" tile whose data source is absent from the live schema and renders N/A. Neither is a measure of learning. If you see either in a demo, that is our error. They are removed or relabelled before the first US demo, and the one real academic delta we compute — a night-over-night change — is currently rendered by no screen at all.
- Price and seats
- There is no US school price. The only school-channel plan in our billing system is India-only and paid for by a parent; the only US plans are consumer $149 and $249 test-prep packages. Our code refuses org-level access grants as ineffective — access is granted per student. Whatever we quote you will be the first US school price we have written, and it will be in writing before a pilot starts. [code, 1 Sep 2026]
- What a school licence does not buy
- The AI tutor, the mastery practice loop and document Q&A are paid per-student features. Every student gets a 7-day trial. On day eight a student with no paid seat is denied all of them — and today that student cannot complete a study homework assignment at all, while our app still shows them a Start button whose session our server refuses. That is a defect, it fails in front of a child and a teacher, and either the school buys a seat for every student in the cohort or we do not run the pilot.
- Scale
- One named partner school, in India, and a live partner footprint measured in tens of students, not thousands. No US school has used this. You would be evaluating a product with almost no operating history, not a proven one that is new to your market.
- Support
- Our team is in India. Your Monday 8:15 a.m. is our evening. We have no US-hours support desk, no published status page and no response SLA to offer you yet, and a founding partner should get all three in the agreement rather than take our word for it.
- The Council
- PrepGraph convenes and funds the Council for Responsible AI and School Innovation. It has one member — its founding chair — no appointed ethics review panel, no meeting held, no data, and no study under way. It certifies nothing and endorses no vendor, PrepGraph included. Its own charter states that any figure or result attributed to it before its first published study is fabricated and is to be corrected on the public record. If anyone shows you a PrepGraph number with a Council seal beside it, that is the sentence to quote back.
- Our research layer
- prepgraph.ai is a prototype. Its own live pages say it has never been applied to a student, a teacher, a classroom or a syllabus, and that nothing has been measured. Nothing on this site rests on it, and we will never offer it as evidence for anything.
- How this page is policed
- Our training site's claim-language lint runs in CI and blocks a merge. Our research site's equivalent is written but not wired into CI, so today it blocks nothing, and the placeholder check on both carries a regex defect that lets bracketed placeholders through — which is exactly how a placeholder testimonial ended up live on our product site. Fixing the regex, wiring both gates in, and pointing them at this site is a launch condition for this page.
In one place
Everything we cannot do, cannot prove, or have not built
Written down so you do not have to assemble it, and so it can be held against us.
- 01 Nothing has been measured. No study has begun, no result exists, there are no case studies, and no figure on this site is offered as evidence of effect.
- 02 Our content library was built for Indian school and entrance-exam curricula. We have ingested no US state's official standards and no question in our bank carries a standards code. Our US K-12 practice questions are generated by our models, are not human-authored, are not teacher-reviewed, and about 8% have passed a solvability check.
- 03 Concept-level gaps come only from work students do inside PrepGraph. Marks a teacher enters from a paper test carry no concept tag and do not feed the model — a school that does not drive student usage sees an empty grid.
- 04 There is no progress-over-time view in the product. What ships is a nightly snapshot, plus a saved student set that can be re-checked against the current snapshot.
- 05 A school licence does not put the tutor in students' hands. The tutor, the mastery loop and document Q&A are paid per-student features; every student gets a 7-day trial, and on day eight an uncovered student is denied all of them.
- 06 A student appears in the analytics once their account is activated, not when their name is loaded onto the roster — and the activation path we ship today was built for Indian families.
- 07 A US-resident deployment is being stood up. Until it is live, production data is hosted in India — ask us for the current status and the cutover date in writing before any student record is loaded.
- 08 Student work is processed by third-party AI providers, listed by name and country on this page, including one that operates from China. We cannot yet tell you, in writing, whether any of them may retain or train on it.
- 09 Tutoring sessions are recorded. Audio, transcripts and uploaded photographs of student work are swept after 90 days; other records are deactivated rather than erased, a school cannot direct deletion of a named student's record, and there is no export or contract-end purge.
- 10 We have no FERPA program, no signed district data privacy agreement, no SOC 2 report and no VPAT, and no accessibility audit has been commissioned. None of the four prerequisites listed on this page has started.
- 11 We have no SIS, LMS, LTI or district SSO integration. Rostering is a staff-loaded file; sign-in is email and password, Google, Facebook or LinkedIn, with no domain restriction.
- 12 Our scope is a single school. There is no multi-campus, district or CMO rollup.
- 13 PrepGraph is a Delaware C Corporation operating in the United States and India. The platform is in service with 33 schools and approximately 40,000 students in India, alongside coaching centers, and is now being deployed in the United States. A US charter school would be an early US customer of an established product rather than the first user of a new one.
- 14 PrepGraph convenes and funds the Council for Responsible AI and School Innovation. It has one member — its founding chair — no appointed ethics panel, no study under way, and it certifies nothing, including us. Any figure attributed to it before its first published study is fabricated.
- 15 Our research layer at prepgraph.ai is a prototype that has never been applied to a student, a teacher, a classroom or a syllabus. Nothing here rests on it.
- 16 Every number on this page carries a bracket saying what it was counted from and when. [code, 1 Sep 2026] means it was read from our source, migrations or configuration on that date. [dev content bank, 29 Aug 2026] means it was counted in a development copy of our content database, not production, which we could not query — treat those as as-built rather than as-deployed. A number without a bracket is our error; tell us and we will date it or delete it, and we will re-run any of them against production in front of you.
- 17 One access-control defect on a student learning endpoint was found during this review and its fix gates the launch of this page. We are auditing the remaining student-facing endpoints and will publish what that audit finds. Until it is finished we make no absolute claim of data isolation across every endpoint.
What a pilot would have to establish before any of this changes
Ask us, and ask everyone else
The same six things about any number a vendor shows you: sample size, comparison group, duration, who funded the work, who reviewed it, and the name of one school where it showed no result. Where we have not run a study we will say so, and you should write down that we did not provide one.