Security Statement
Our approach
Pennant One handles material that schools care deeply about: their brand, their communications, and their reputation. We designed the platform around three principles — keep client data isolated, keep a human in control of everything that publishes, and collect as little sensitive information as possible in the first place.
No student data by design
The most effective protection is not holding sensitive data at all. Pennant One does not require, request, or process student records, grades, attendance, health information, disciplinary records, or family contact information. Generated content uses template merge fields; personalization with individual recipient data happens in the client's own systems of record, outside Pennant One. Performance analytics from connected channels are collected at the aggregate level only.
Data isolation between clients
Each client organization's data is maintained in a separate, dedicated data set. Brand specifications, ingested material, generated content, and review history belonging to one client are never shared with, combined with, or used to improve services for any other client. There is no cross-client pooling of data.
Encryption
Client data is encrypted in transit and at rest. Credentials for connected third-party channels, such as OAuth tokens, are stored encrypted and isolated from other data.
Access control
Access to client data is restricted to what is necessary to operate and support the service. Platform accounts are provisioned through the client organization, and publishing permissions are limited to channels the client has explicitly authorized.
Human approval and audit logging
Nothing publishes without sign-off from an authorized person on the client's team. Every approval, decline, and edit is recorded, creating an audit trail of who approved what, and when, for every piece of content the platform produces.
AI processing
Pennant One uses Anthropic's commercial API to generate and evaluate content. Under Anthropic's Commercial Terms, Anthropic may not train its models on customer content submitted through its commercial services, and inputs and outputs are deleted from Anthropic's backend systems within 30 days by default. Statement Branding does not use client material to train any model, and never uses one client's material to improve outputs for another.
Channel integrations
When a client connects a publishing channel, we request only the minimum permissions needed to publish approved content and, where applicable, retrieve aggregate performance data. Clients can revoke any connection at any time, either in the platform or directly with the provider.
Infrastructure and subprocessors
The platform runs on established cloud infrastructure, with data stored and processed in the United States. We require subprocessors to maintain appropriate confidentiality and security protections, and a current list of subprocessors is available on request.
Incident response
No system is perfectly secure. If a breach affects client data, we will notify the affected client without undue delay and cooperate with their own notification obligations.
Data retention and deletion
Client material and generated content are retained for the duration of the client relationship and as set out in the applicable service agreement. On termination, we delete or return client data in accordance with that agreement.
Reporting a vulnerability
If you believe you have found a security issue in Pennant One, we want to hear about it. Email hello@pennantone.com with details, and please do not access or modify data that is not yours while investigating. We will acknowledge your report and follow up.
Questions
Schools evaluating Pennant One often have their own security review process. We are glad to participate — contact hello@pennantone.com.
Related: Privacy Policy · Terms of Use