1. Service Overview

As a provider of technology solutions to schools, Amplify’s commitment to data privacy and security is essential to our organization. This overview of Amplify’s Information Security Program describes physical, technical and administrative safeguards Amplify implements to protect student data in our care.

Company profile

Amplify Education, Inc. (Amplify) is a privately held company founded in 2000 as Wireless Generation. Amplify’s products include curriculum and instruction, assessment and intervention, professional development services and consulting services for K-12 education.

Service hosting

Amplify leverages Amazon Web Services (AWS) as its cloud hosting provider. Within AWS, Amplify utilizes Virtual Private Clouds (VPCs), which provide an isolated cloud environment within the AWS infrastructure. External network traffic to a VPC is managed via gateway and firewall rules, which are maintained in source code control to ensure that the configuration remains in compliance with Amplify security policy. In addition, the production VPCs and the development VPCs are isolated from each other and maintained in separate AWS accounts.

2. Policies & standards

Information security program

Amplify maintains a comprehensive information security program based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the NIST SP 800-53 Rev. 5 family of information security controls. These provide a robust framework of best practices from which an organization can build its security policies and protocols based on identified risks, compliance requirements, and business needs. They cover critical practice areas, including access control, configuration management, incident response, security training, and other information security domains.

Governance

Amplify’s Information Security Committee has primary responsibility for the development, maintenance, and implementation of the Amplify information security program. The Information Security Committee is responsible for all information risk management activities within the company and is composed of technology, business and legal leaders from the organization. The Committee meets weekly and includes a dedicated VP of Information Security and a program manager to oversee, direct and coordinate its activities.

Policy execution

Adherence to the internal Amplify information security policy is an obligation of every Amplify employee. Amplify conducts a series of internal monitoring procedures to verify compliance with internal information security policies, and all Amplify employees undergo annual criminal background checks. In addition, any third-party contractors who come into contact with systems that may contain student data are contractually bound to maintain security and privacy of the data.

3. Data access controls

Access control

Amplify’s access control principles dictate that all student data we store on behalf of customers is only accessible to district-authorized users and to a limited set of internal Amplify users who may only access the data for purposes authorized by the district. Districts maintain control over their internal users and may grant or revoke access.

In limited circumstances and strictly for the purposes of supporting school districts and maintaining the functionality of systems, certain Amplify users may access Amplify systems with student data. All such access to student data by Amplify technicians or customer support requires both authentication and authorization to view the information.

Encryption

Data encryption is an important element of our protection of sensitive data at rest and in transit, and is reviewed and updated as appropriate annually, based on the latest standards and guidelines published by OWASP and NIST.

  • In transit: Amplify encrypts all student data in transit over public connections, using Transport Layer Security (TLS), commonly known as SSL, using industry-standard protocols, ciphers, algorithms, and key sizes.
  • At rest: Amplify encrypts student data at rest using the industry-standard AES-256 encryption algorithm.

4. Application security by design

Building the right roles into applications

Permissions within Amplify applications are designed on the principle that school districts control access to all student data. To facilitate this, Amplify applications are designed so that roles and permissions flow from the district to the individual user. For example, applications that offer schools a way to collect and report on assessment results have a web interface that requires district administrators to authorize individuals to view student data.

Security controls within applications are used to ensure that the desired privacy protections are technically enforced within the system. For example, if a principal is supposed to see only the data related to his or her school, Amplify ensures that, throughout the design and development process, our products restrict principals from seeing records for any students outside his or her school.

To make sure Amplify applications properly enforce permissions and roles, our development teams conduct reviews early in the design process to ensure roles and permissions are an essential component of the design of new applications.

Building security controls into applications

Amplify applications are also developed to minimize security vulnerabilities and ensure industry-standard application security controls are in place.

As part of the development process, Amplify has a set of application security standards that all applications handling student data are required to follow, including:

  • Student data is secured using industry standard encryption when in transit between end-users and Amplify systems.
  • Applications are built with password brute-force attack prevention.
  • User sessions expire after a fixed period of time.

We also conduct manual and automated static code analysis as well as dynamic application security testing to preemptively identify vulnerabilities published by industry leaders such as OWASP (Open Web Application Security Project)

5. Proactive security

Risk assessments

Amplify periodically engages a security consulting firm to conduct risk assessments, aimed at identifying and prioritizing security vulnerabilities. The Information Security Committee coordinates remediation of the vulnerabilities. The security consulting firm also provides ongoing advice on current risks and advises on remediation of vulnerabilities and incident response.

Penetration testing

Amplify engages third-party firms to continually conduct application penetration testing.  The purpose of this testing is to test for application security vulnerabilities in the production environment.  We work with third party penetration testing program partners. Third-party testing involves a combination of automated and manual testing.

Vulnerability management

Amplify ensures that its systems are free of known vulnerabilities in several ways. Every production server runs vulnerability detection software that compares the installed software against a global database of known vulnerabilities. Secondly, we employ real time network monitoring that reports on any potentially malicious traffic. In addition, a third-party security firm continually reviews all of our system logs for potential security breaches. Lastly we continually test our applications against common malicious internet traffic. Violations in any of these areas will alert one of our operations teams, who are available around the clock.

In addition, Amplify participates in a private bug bounty program through HackerOne, working with the security community to find security vulnerabilities and support our efforts to keep our data and systems safe and secure.

Endpoint security

Access to production systems at Amplify is restricted to a limited set of internal Amplify users to support technical infrastructure, troubleshoot customer issues, or other purposes authorized by the district. In addition, Amplify requires multi-factor (MFA) authentication methods for access to all production systems. MFA involves a combination of something only the user knows and something only the user can access. For example, MFA for administrative access could involve entering a password as well as entering a one-time passcode sent via text message to the administrator’s mobile phone. The use of MFA reduces the possibility that an unauthorized individual could use a compromised password to access a system.

Infrastructure security

Network filtering technologies are used to ensure that production environments with student data are properly segmented from the rest of the network. Production environments only have limited external access to enable customers to use our web interfaces and other services. In addition, Amplify uses firewalls to ensure that development servers have no access to production environments.

Other measures that Amplify takes to secure its operational environment include system monitoring to detect anomalous activity that could indicate potential attacks and breaches.

Security training

At Amplify, we believe that protecting student data is the responsibility of all employees. We implemented a comprehensive information security awareness training program that all employees  undergo upon initial hire, with an annual refresher training. We also provide information security training and annual social engineering tests for specific departments based on role.

6. Reactive security

Monitoring

Intrusion detection and prevention systems (IDS/IPS) are in place to analyze the network device logs, monitor the network and report anomalous activity for appropriate resolution.

Incident response

Amplify maintains a comprehensive Security Incident Response Policy Plan, which sets out roles, responsibilities and procedures for reporting, investigation, containment, remediation and notification of security incidents. Amplify works with reputable firms for incident response and digital forensics support, as well as annual table-top exercises in coordination with cybersecurity experts.

Business Continuity Planning and Disaster Recovery

Amplify maintains a comprehensive Business Continuity Planning and Disaster Recovery Plan (BCP/DR), to guide personnel in procedures to protect against business disruptions caused by an unexpected event. The plans and related operations processes are tested on a semiannual basis, with ensuing operations improvement and remediation work.

7. Compliance

Audits

In addition to penetration testing and other proactive security testing and monitoring outlined above, Amplify undergoes annual SOC 2 Type 2 examinations of controls relevant to security. The examination is formally known as a Type 2 Independent Service Auditor’s Report on Controls Relevant to Security. The most recent examination was conducted by Schellman & Company, LLC and covers the period from April 1, 2024–March 31, 2025. The report states that Amplify’s systems meet the criteria for the security principle and opine on management’s description of the organization’s system and the suitability of the design of controls to protect against unauthorized access, use, or modification.

The Type 2 report also opines on the operating effectiveness of controls over the review period. This means that our auditors confirmed that we have continued to follow established security controls over the period of time of the review.

Certifications

SOC 2: Amplify successfully completed the SOC 2 Type 2 examination of controls relevant to security (see above, under “Audits”).

Privacy

Amplify’s products are built to facilitate district compliance with applicable data privacy laws, including FERPA and state laws related to the collection, access and review and disclosure of student data. Amplify’s Customer Privacy Policy describes the types of information collected and maintained on behalf of our school district customers and limitations on use and sharing of that data.

8. Supporting documentation

In the course of customer security assessment, the following documentation can be provided by Amplify upon customers’ request:

  • Penetration Testing Report
  • Risk Assessment Report
  • SOC 2 Type 2 Report

9. Report a vulnerability

To report a security vulnerability, click here.

Vulnerability Disclosure Policy

As a provider of technology solutions to schools, Amplify’s commitment to data privacy and security is essential to our organization. Amplify demonstrates that commitment in part through the physical, technical, and administrative safeguards we maintain to protect student data and other sensitive information entrusted to our care.

Amplify looks forward to working with the security community to find security vulnerabilities and support our efforts to keep our data and systems safe and secure.

Before reporting a vulnerability, please read our program rules, eligibility overview, report submission rules and guidelines, legal terms, and out-of-scope list set out below.

General Rules

  • We appreciate reports on any Amplify-owned asset, but only vulnerabilities that prove to be outside of expected behavior are eligible for acceptance.
  • Reports involving third party services or providers not under Amplify’s control are out-of-scope for submission.
  • Amplify places a high priority on privacy. Vulnerabilities in the areas of inadvertent exposure of our customers’ personally identifiable information (PII) are considered to be of Critical severity.
  • We classify vulnerability severity per CVSS (the Common Vulnerability Scoring Standard). These are general guidelines, and the ultimate decision over a reward – whether to give one and in what amount – is a decision that lies entirely within our discretion on a case-by-case basis.
  • In order to receive an award for validated reports, you must have a HackerOne account. Please note reward decisions are subject to the discretion of Amplify. Please note these are general guidelines, and that reward decisions are subject to the discretion of Amplify.
  • Only interact with test accounts that you created via self sign-up or were provided by Amplify. The use of any credentials outside of these areas for testing purposes, including legacy credentials supplied through the program and leaked credentials from third parties is strictly prohibited.
  • Do not contact Amplify’s customer support for questions or to submit a vulnerability report.
  • Amplify may, in its sole discretion, disqualify you if you breach this policy or fail to comply with any of the program’s rules and terms.
  • Amplify reserves the right to cancel or modify this program without notice at any time.

Eligibility

  • You are not eligible for participation if you 1) are employed by Amplify or any of its affiliates 2) are an immediate family member of a person employed by Amplify or any of its affiliates or 3) left the employment of Amplify or its affiliates or subsidiaries within the past (12) months.
  • You are not eligible for participation if you have been prohibited in writing from participating in the Bug Bounty Program by Amplify at any time.
  • You may not be in violation of any national, state, or local law or regulation with respect to any activities directly or indirectly related to conducting your tests.
  • You may not compromise the privacy or safety of our customer and the operation of our services;
  • You may not cause harm to Amplify, our customers, or others;
  • You must follow the policy guidelines to responsibly disclose vulnerabilities to Amplify.

Vulnerability Submission Rules & Guidelines

  • Any testing conducted on customer data or accounts is strictly prohibited and will result in removal from the program.
  • If during the course of testing you encounter any sensitive data outside of your test accounts (including student or teacher names, login info, assessment data, activity data, and student work, etc.), please cease testing immediately and report what you have found. DO NOT include any text, screenshots, etc. with PII in the report. This action safeguards both potentially vulnerable data and yourself.
  • Do not access, download, or share any data you encounter in your testing.
  • Only interact with test accounts that you created or that we provided. The use of any credentials outside of these areas for testing purposes is strictly prohibited.
  • Provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.
  • In some cases, you may not have all of the context information to assess the impact of a vulnerability. If you’re unsure of the direct impact but are reasonably certain that you have identified a vulnerability, we encourage you to submit a detailed report and state the open questions on impact.
  • When duplicate submissions for the same vulnerability occur, we only award the first report that was received, provided that it can be fully reproduced.
  • Multiple reports describing the same vulnerability against multiple assets or endpoints must be submitted within a single report.
  • Avoid destruction of data and interruption or degradation of our service.
  • Proof of Concept (POC) videos that do not include PII are highly recommended to help verify the issue, provide clarity, and save time on triage.
  • Please provide timely responses to any follow-up questions and requests for additional information.
  • Understand that there could be submissions for which we accept the risk, have other compensating controls, or will not address in the manner expected. When this happens, we will act as transparently as we can to provide you with the necessary context as to how the decision was made.
  • Reports submitted using methods that violate policy rules will not be accepted and may result in account suspension from/denial of entrance to the program.
  • Please refer to any noted out-of-scope areas listed under Out-of-Scope Vulnerabilities.

Out-of-Scope Vulnerabilities

When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out-of scope. In addition, please refer to any noted Out of Scope areas listed under the program assets.

  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.
  • Clickjacking on pages with no sensitive actions.
  • Unauthenticated/logout/login CSRF.
  • Attacks requiring MITM or physical access to a user’s device.
  • Previously known vulnerable libraries without a working Proof of Concept.
  • Comma Separated Values (CSV) injection without demonstrating a vulnerability.
  • Missing best practices in SSL/TLS configuration.
  • Any activity that could lead to the disruption of our service (DoS).
  • Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
  • XSRF that requires the knowledge of a secret.
  • Automated tools that could generate significant traffic and possibly impair the functioning of our services.
  • Testing or demonstrating the ability to upload unlimited audio/video files to exhaust resources.
  • Leaked credentials from third party providers, including invalid or stale employee credential dumps, and/or leaked personal information of Amplify staff.
  • Leaked credentials for Amplify customers not caused by vulnerabilities in our systems.
  • Vulnerabilities identified via third party services or providers where Amplify is not the owner.
  • Issues that merely result in spam/annoyance without additional impact (e.g sending emails without sufficient rate limiting)
  • Attempts to access our offices or data centers.
  • Any activity that could contribute to the disruption of our service (DoS). Automated scanning tests should be kept to 10 requests per second or less.
  • Self XSS.
  • Broken links and/or crashes in general.
  • Issues that require unlikely user interaction.
  • Issues that do not affect the latest version of modern browsers
  • Issues that require physical access to a victim’s computer/device.
  • Disclosure of information that does not present a significant risk
  • Please refer to any noted out-of-scope areas listed under program assets.

Legal

  • Any information you receive or collect about us, our affiliates or any of our users, employees or agents in connection with the Bug Bounty Program (“Confidential Information”) must be kept confidential and only used in connection with the Bug Bounty Program. You may not use, disclose or distribute any such Confidential Information, including without limitation any information regarding your Submission, without our prior written consent. You must get written consent by submitting a disclosure request through the HackerOne platform.
  • Researchers must follow HackerOne’s disclosure guidelines. Public disclosure or disclosure to other third parties without the explicit permission of Amplify is prohibited.
  • We will not take legal action against you if vulnerabilities are found and responsibly reported in compliance with all of the terms and conditions outlined in this policy.
  • Amplify reserves the right to modify the terms and conditions of this program without notice at any time, and your participation in the Program constitutes acceptance of all terms.

Submit Vulnerability Report

Embracing artificial intelligence in the math classroom

Artificial intelligence seems to be everywhere these days. We use it when we ask Alexa or Siri for the morning weather report. We use it when GPS tells us how to best avoid traffic. We use it when we chill at the end of the day with a recommendation from Netflix. 

But what about during the day—and specifically, at school? Even more specifically, can AI be leveraged to enhance the math classroom? 

“While AI is an amazing tool, you’ve really got to make sure that you are focusing in on your expertise as well,” says veteran math educator and STEM instructional coach Kristen Moore, “And saying, ‘How can I use this to make something better?’ and not just, ‘How can I use this to make something?’” 

In this post, we’ll talk about the current state of AI in math education, and how it can support educators in making math better. (SPOILER: It’s not going to replace you!) 

First, some STEM learning for us: What is artificial intelligence? 

Artificial intelligence, or AI, refers to the development of computer systems able to perform tasks that typically require human intelligence. 

It involves creating algorithms and systems that enable computers to learn from data, adapt to new situations, and make decisions or predictions.

AI aims to mimic human cognitive functions such as understanding language, recognizing patterns, solving problems, and making decisions. It encompasses a range of techniques and technologies, including machine learning, neural networks, natural language processing, and robotics.

The term “artificial intelligence” was introduced in 1956.  The availability of vast amounts of data and advancements in computer power in the 2010s led to additional breakthroughs. And with the proliferation of smartphones, smart devices, and the internet, AI technologies began to work their way into our homes, cars, pockets, and everyday lives.

What’s the state of AI in education? 

AI is already commonplace in schools and classrooms. Here are just a few examples:

  • Adaptive learning: This software uses AI algorithms to adjust the difficulty and content of lessons based on a student’s performance, helping students remain engaged and challenged at their optimal level.
  • Assistive technologies: AI helps students with disabilities by providing assistive technologies like text-to-speech and speech-to-text tools, making educational content more accessible.
  • Plagiarism detection: These tools use AI algorithms to identify instances of copied or unoriginal content in students’ assignments, essays, and projects. 
  • Data analysis for teachers: AI analyzes data from student assessments to identify trends and insights, helping teachers make informed decisions about instructional strategies. It can also predict students’ performance trends, helping teachers identify at-risk students early and intervene to provide additional support.
  • Grammar, spelling, and style checkers: AI can provide real-time feedback to students (and teachers!) on their writing work.

Embracing AI technology in your math classroom

While AI is not here to replace teachers, it is here to stay. And experts say it’s only going to become more commonplace. But despite how common AI is already—both outside and inside school—not all teachers are familiar with its numerous applications and potential. Now is a great time for educators to start exploring its uses and get ahead of the curve.

Here are a few easy entry points for math teachers. 

ChatGPT: A common AI tool, ChatGPT is designed to understand and generate human-like text based on the input it receives. It’s trained on a wide range of internet text, which enables it to generate responses to a vast array of prompts and questions. 

Most students have likely experimented with ChatGPT, while teachers—though aware of it—are less likely to use it. ChatGPT has highly practical applications for both groups, though—including in the math (and science) classroom. 

It can, for example, help teachers plan interesting, relevant math lessons for their students. Kristen Moore, who discusses this topic on Math Teacher Lounge, suggests that math teachers use ChatGPT to:

  • Connect topics to student interests and vice-versa. (Teachers can ask ChatGPT for real-life applications of polynomials and select those that might pique student interest, or ask about math applications derived from students’ hobbies and pursuits.) 
  • Generate word problems (including step-by-step solutions), lessons, projects and rubrics, and more.

Toward the (near) future

As AI advances, it will continue to revolutionize education. Here are a few time-saving ways that educators can look forward to using it in their classrooms.

  • AI tutors: AI-powered virtual tutors will help math students with homework questions and provide explanations for various concepts. These tutors can be available at home 24/7, allowing students to seek an AI homework helper whenever they need it.
  • Automatic graders: Some AI tools can automatically grade math work, including multiple-choice and short-answer assignments. These tutors can be available at home 24/7 in any household with internet access, allowing students to seek more personalized instruction.
  • Personalized learning paths: These AI-powered platforms will work particularly well for math students by adapting to each student’s skill level and pace, offering tailored exercises and challenges that cater to their strengths and identify areas of improvement. They will analyze students’ performance and adjust the difficulty of content, ensuring that students get targeted support and opportunities to progress.

More to explore

To dive deeper into AI in math education—and get rolling with AI in your classroom—check out this two-episode mini-series on our Math Teacher Lounge podcast focused on just that: 

“I’m a believer that learning is inherently social,” says Carolan, who is quick to emphasize how technology can enhance that quality, not replace it. The same can be said for the role teachers play in the classroom—a role technology can support, but never take away. To learn more about this topic (and discuss it with your fellow educators!), head to our Math Teacher Lounge community

5 strategies to transform your math classroom

Want to shift your math teaching practices this year, but not sure where to start? That’s a good problem to have! 

You can boost your instruction this fall with problem-based learning, technology in the math classroom, and more—all in ways that put students at the center. 

“All students need the opportunity to feel like they can figure out mathematics,” says Jennifer Bay-Williams, Ph.D., an author and professor of mathematics education at University of Louisville. “That’s where they develop a math identity, [the idea] that they can do math. And they start feeling like, ‘I can figure this out.’” 

Bay-Williams spoke at our 2024 Math Symposium, along with other thought leaders and expert educators. Keep reading to see how their key takeaways can help you shift your math instruction this school year!

Center student ideas in a collaborative math classroom

Amplify Math Suite Executive Director Kristin Gray had great tips for teachers looking to center student ideas in the classroom. Simply put, it’s all about helping them make several types of connections. These can include any of the following: 

  • Connecting students’ classroom math experiences to real life
  • Connecting math ideas to one another
  • Connecting their ideas to the ideas of their classmates 

How do teachers foster these important connections? That’s where problem-based lessons come in. Rather than teaching a concept or formula in isolation, then having students practice it, try inviting students to collaborate on a real-life problem that will lead them to that math idea. (For example, you might ask them to work on designing a small traffic or subway system that requires developing ideas about distance, rate, and time.)

As a result, students build problem-solving skills collaboratively, feel their ideas are valued, develop their own ways to make math make sense, and learn from and with each other. Teachers also get to know and appreciate the different backgrounds and styles students bring to the classroom, opening up new opportunities for engagement—and connection. 

Reimagine student engagement

No matter how engaging you are as a teacher, it’s typically students who drive engagement—and that’s actually good news. You don’t have to reinvent the wheel or do somersaults to get their attention. In fact, a lot of engagement comes from creating routine and familiar opportunities for connection. And it can also come from allowing students to make mistakes. 

“We want all students to have an entry point into [math] tasks,” notes Amplify STEM Product Specialist James Oliver. “Those students that seem to always feel like they don’t fit or don’t have the identity in that math classroom, we want them to immediately have successes and have their curiosities tested.” Successes—and productive failures. “What we’ve learned is, you are not firing any synapses, nothing’s happening if you’re just getting it immediately correct.”

Nurture student curiosity

Which is better: letting students dive into a box of LEGO pieces to see what happens, or providing a step-by-step guide to building the airplane? 

It’s actually a tie. In both structured and loose approaches, the key is to spark curiosity and communication. “If we want them to be mathematicians, we should let them talk about math,” says Amplify Director of 6–12 Core Math Curriculum Kurt Salisbury, Ph.D. Here’s his 3D approach:

DISCOVER
Discovering the relationships among mathematical ideas is a key part of mathematical thinking. 

DESCRIBE
Students communicate their mathematical thinking by describing the processes, procedures, or relationships needed to work with a concept or pattern. 

DEVELOP
When students develop a strategy they can apply to a variety of contexts, their math thinking gets validation and purpose.  

So whether you lean into a more structured approach or prefer to let kids figure the LEGOS out themselves, small mindset changes like these can create more space for your students to discover, describe, and develop as mathematicians.

Make math fluency fun 

As with someone fluent in a language, someone fluent in math is able to think and calculate mathematically without struggle or effort—that is, with fluidity. 

In order to think and calculate fluently, students need to build a toolbox of strategies—and games are a great way to do that. 

While you’re making the learning fun, students are absorbing tools they’ll use throughout their lives. “When we ensure that every student has access to a range of strategies, and has regular opportunities to choose among those strategies, that’s what games do for us.” says Bay-Williams.

Elevate student voices 

When student thinking isn’t explicitly invited into the classroom, students may begin to narrow their focus, providing merely what they think their teacher wants to hear. But given genuine invitations to share, students are more likely to follow their thought process wherever it leads them, taking a more organic approach to problem-solving.

“Taking a step back as a teacher, and inviting students to take a step forward, [activates] students getting started with finding the answer,” says Stephanie Blair, vice president of Desmos Coaching. “And all of them might take a different step forward, which is okay.”

It’s time for math that does more for students

“All students need the opportunity to feel like they can figure out mathematics,” says Bay-Williams. We need to connect with our students, nurture their curiosity and comfort with math, and welcome their unique ways of thinking.

We hope the thought leaders and speakers from our Math Symposium have inspired you to do just that!

NO PURCHASE NECESSARY. A PURCHASE DOES NOT INCREASE YOUR CHANCES OF WINNING. VOID WHERE RESTRICTED OR PROHIBITED BY LAW.

These Terms and Conditions (the “T&Cs”) apply to each sweepstakes offered by Amplify Education, Inc. (the “Sponsor”) on a webpage, email, or other document that links to these T&Cs (the “Entry Page”). For detailed rules for each sweepstakes, please review the sweepstakes rules on the Entry Page (such rules, the “Sweepstakes Rules”). These Terms and Conditions, together with the Sweepstakes Rules, will comprise the “Official Rules” for the sweepstakes.

To enter

Fill out the entry form on the Entry Page. Limit of one (1) entry per person using only one (1) email address for each drawing conducted during the sweepstakes period. Eligibility of individual entries will be at the sole discretion of the Sponsor, for any reason or for no reason, though specific reasons for disqualification may include use of inappropriate language. Entries generated by script, macro, mechanical or other automated means and entries by any means which subvert the entry process are void. Multiple entries received from any person in excess of the stated limitation will be void. Sponsor is not responsible for incomplete, lost, late, stolen, misdirected, damaged, illegible entries, for address changes of entrants, or for malfunctions of electronic or telephone equipment, computer hardware or software, failure of any entry to be received on account of technical problems or traffic congestion on the Internet, or any combination thereof, including any injury or damage to any entrant’s or any other person’s computer or other property related to or resulting from participation in the sweepstakes, or for other problems related to electronic entries. All entries become the property of Sponsor and will not be returned.

Eligibility

In addition to any eligibility restrictions contained in the Sweepstakes Rules, each sweepstakes is open only to individual legal residents of the states of the United States or the District of Columbia, except for residents of Rhode Island, who are at least 13 years of age or older as of the time of entry.

  • Minors – Parents and Guardians: An eligible person under the age of majority in such person’s jurisdiction must have his/her parent’s or legal guardian’s consent to enter this sweepstakes. The parent(s) or legal guardian(s) of an entrant under the legal age of majority in his/her jurisdiction of residence (a) will ensure that the entrant in respect of whom they agree to the Official Rules will comply with the Official Rules; and (b) warrants that he/she agrees to the Official Rules and gives the consents contained herein, including permission for his/her child/ward to participate in this sweepstakes. The parents(s) or legal guardian(s) of each such entrant agrees to indemnify the Released Parties (as defined below) for and against: (i) any claims made by the entrant, his or her legal guardian(s), or any member of his or her family against the Released Parties in connection with this sweepstakes; and (ii) any losses (including any liability) caused by any conduct of the entrant that is inconsistent with the Official Rules.
  • Teachers/School Personnel: By entering this sweepstakes, you represent and warrant that your participation in this sweepstakes complies with your school, institution, school board and school district policies. Any entry submitted in violation of such policies may result in disqualification. Verification: Amplify reserves the right to verify an individual’s eligibility, compliance with applicable policies in the case of teachers and school personnel and, if applicable, a parent’s or legal guardian’s consent to enter the sweepstakes by requesting proof of identity, compliance, or eligibility in the form acceptable to Amplify. Failure to provide such proof may result in disqualification, such that entrant will no longer be eligible to participate in the sweepstakes and will have no recourse or other opportunity to submit an entry.
  • Entrant: In the event of a dispute regarding any entry, the entry will be deemed made by the authorized account holder of the e-mail address submitted at the time of entry (i.e., the natural person who is assigned to an email address by an Internet access provider, online service provider or other organization responsible for assigning email addresses for the domain associated with the submitted e-mail address).
  • Ineligibility: Employees of Amplify, its advertising and promotion agencies, its contest administration agents, and each of Amplify’s and such agencies’ respective parent companies, subsidiaries and affiliates (all of the foregoing, the “Sweepstakes Entities”), and such employees’ immediate family and household members, are not eligible.

Drawing

Winners will be selected on the date(s) specified in the Sweepstakes Rules (the “Drawing Dates”). Each winner be selected in a random drawing, from all eligible entries received since the beginning of the sweepstakes period or the prior Drawing Date, as applicable. Winner does not need to be present to win. The drawing(s) will be conducted by Sponsor or its designee, the judge of the sweepstakes, whose decisions are final and binding on all matters relating to the sweepstakes. Winner will be required to sign and return an affidavit of eligibility/liability and publicity release, or the prize will be forfeited and an alternate winner selected.

Prize and odds of winning

The Prizes and number to be awarded are specified in the Sweepstakes Rules. Odds of winning depend on the number of eligible entries received. Prizes will be awarded. No prize substitutions, upgrades or cash equivalents, except at the sole discretion of the Sponsor if an advertised prize becomes unavailable. Prizes are non-transferable. All taxes, if any, associated with the prize are the winner’s sole responsibility.

General

By entering, entrants agree to: (1) release the Sponsor, its agents, and any platforms used to conduct the sweepstakes, such as Facebook, Twitter, or others (each, a “Platform” and together with Sponsor and its agents, the “Released Parties”), from all liability, injuries, loss and/or damage of any kind arising from their participation in the sweepstakes and the acceptance, possession and use/misuse of any prize; (2) to be bound by the Official Rules and the decisions of the judge; and (3) to be contacted by Sponsor by mail, telephone and/or email regarding the sweepstakes. The sweepstakes is in no way sponsored, endorsed or administered by, or associated with, any Platforms used to promote it. By accepting a prize, winner consents to the use of his/her name and likeness for advertising and promotional purposes without additional compensation in all media worldwide (except where prohibited by law). The sweepstakes is subject to all applicable federal, state and local laws and regulations. If for any reason the sweepstakes is not capable of running as planned, including due to an infection by computer virus, bugs, tampering, unauthorized intervention, fraud, technical failures, or any other causes which corrupt or affect the administration, security, fairness, integrity, or proper conduct of this sweepstakes, Sponsor and its agents reserve the right, at their sole discretion, to modify, suspend or terminate the sweepstakes, and select the winner from all eligible entries received prior to the termination and/or to disqualify any individual who is responsible or who tampers with the entry process. This sweepstakes is governed by the laws of the State of New York, with venue in New York County, New York, and all claims must be resolved in the state or federal courts in New York County, New York.

Removal for future mailings

To have your name and address removed from Sponsor’s future mailings, please select the unsubscribe link in any email you receive from Sponsor. Sponsor will process your request within 60 days.

Winner’s name

For the name of the winner, email mail@amplify.com or send a stamped, self-addressed envelope to be postmarked within 15 days and received within 30 days of the relevant Drawing Date to: Amplify, Marketing Department, Winner’s Name, 55 Washington Street, Suite 800, Brooklyn, NY 11201.

Sponsor

Amplify Education, Inc., 55 Washington Street, Suite 800, Brooklyn, New York 11201.