SECURITY & TRUST
Security & Trust
Advanced Learning Academy operates on enterprise-grade infrastructure with transparent security practices, federal-aligned compliance, and customer-controlled data sovereignty. Built for federal, healthcare, and Fortune 500 procurement scrutiny.
AT A GLANCE
COMPLIANCE FRAMEWORKS
Compliance & Certification Status
NIST CSF 2.0
Self-Attested Tier 3 (Repeatable). All six functions assessed with subcategory-level ratings and gap analysis.
Documentation AvailableSOC 2 Type II
Inherited via Cloudflare infrastructure. ALA-specific SOC 2 Type II audit planned for 2027.
Documentation AvailableFedRAMP Moderate
Inherited via Cloudflare authorization. ALA infrastructure runs on FedRAMP-authorized Cloudflare services.
Documentation AvailablePCI DSS Level 1
Inherited via Stripe payment processor. ALA never stores, processes, or transmits cardholder data directly.
Documentation AvailableEEOC Uniform Guidelines
Assessment designed for alignment with EEOC Uniform Guidelines on Employee Selection Procedures.
Documentation AvailableADA Title III
Accessible design principles applied across all assessment and reporting interfaces.
Documentation AvailableSection 508
Accessibility tested for compliance with Section 508 of the Rehabilitation Act.
Documentation AvailableGDPR
Aligned for EU data subjects. Data processing agreements available. Right to erasure supported.
Documentation AvailableCCPA
Compliant for California residents. No sale of personal information. Consumer rights honored.
Documentation AvailableHIPAA
Coverage via insurance rider. Business associate agreements available upon request.
Documentation AvailableFISMA
Alignment documentation available. Controls mapped to NIST SP 800-53 families.
Documentation AvailableDEPLOYMENT OPTIONS
Four Deployment Models — Matched to Your Data Sensitivity
ALA understands that one deployment model does not fit every federal mission. Choose the model that fits your data sensitivity requirements.
Standard Cloud
- ✓ Infrastructure: Cloudflare Workers, US-region
- ✓ Compliance: FedRAMP Moderate inherited
- ✓ Suitable for: 90% of federal pilots
- ✓ Availability: Immediately, standard pricing
Anonymized Mode
- ✓ Agency tokenizes identifiers before data reaches ALA
- ✓ ALA receives only tokenized IDs and assessment responses
- ✓ PII never crosses agency boundary
- ✓ Availability: Immediately, $0 additional cost
Dedicated Instance
- ✓ Agency-dedicated Workers, D1, R2 storage
- ✓ Agency-specific encryption keys
- ✓ Isolated from all other ALA customers
- ✓ Setup: 30-45 days, $50K-$150K
Custom Deployment
- ✓ On-premises, AWS GovCloud, or Azure Government
- ✓ Air-gap-compatible architecture
- ✓ Setup: Scoped per agency
- ✓ Pricing: $300K-$1.5M per engagement
DATA COMMITMENTS
What We Do With Your Data — In Plain English
YOUR DATA STAYS IN THE US.
All data stored in US-region Cloudflare data centers.
WE DO NOT TRAIN AI ON YOUR DATA.
Never used for AI/ML training or product improvement.
WE DO NOT SELL YOUR DATA.
No selling, sharing, licensing, or monetizing. Period.
YOU CONTROL RETENTION.
Default 1 year. Customers may specify 90 days to 7 years.
WE DELETE ON REQUEST.
Within 30 days, certified per NIST SP 800-88.
WE NOTIFY YOU OF INCIDENTS.
24 hours detection notice, 72 hours full forensic, 30 days written report.
YOU HAVE THE RIGHT TO AUDIT.
Self-attested, third-party, or on-site — your choice.
TECHNICAL CONTROLS
Security Architecture
Encryption
- ✓ TLS 1.3 enforced via Cloudflare
- ✓ AES-256 at rest (D1, R2, KV)
- ✓ Payment data tokenized via Stripe
- ✓ Email transit TLS-secured via Mailgun
Access Control
- ✓ MFA on all admin accounts
- ✓ Single-tenant logical isolation
- ✓ Least-privilege enforced
- ✓ Quarterly access review
- ✓ No third-party access without BAA/DPA
Monitoring & Detection
- ✓ Real-time Cloudflare WAF
- ✓ DDoS mitigation (300+ global PoPs)
- ✓ Application-level audit logging
- ✓ Continuous vulnerability scanning
- ✓ 24/7 security event monitoring
SUBPROCESSORS
Subprocessors With Access to Customer Data
ALA discloses every third party that touches customer data. 30-day advance notification of any subprocessor changes.
| Subprocessor | Service | Data Accessed | Certifications |
|---|---|---|---|
| Cloudflare, Inc. | Infrastructure | All assessment and account data | SOC 2 Type II, ISO 27001, FedRAMP Moderate |
| Stripe, Inc. | Payment processing | Payment information only | PCI DSS Level 1, SOC 2 Type II |
| Mailgun (Sinch) | Transactional email | Email addresses, message content | SOC 2 Type II, GDPR |
| Bunny.net | Static asset CDN | Static media files only (no PII) | ISO 27001 |
INSURANCE
Insurance Coverage
ROADMAP
Forward-Looking Security Commitments
Q3 2026
SOC 2 Type II audit initiation
Q4 2026
Annual penetration testing begins
Q1 2027
SOC 2 Type II report available
Ongoing
Quarterly access reviews, annual policy updates
DOCUMENTATION
Security Documentation
Public Downloads
Available Under NDA
- ★ Subprocessor & Data Flow Document
- ★ Detailed Control Matrix
- ★ Incident Response Plan
- ★ Business Continuity Plan
- ★ Insurance Certificates
Available Upon Engagement
- ★ Master Services Agreement
- ★ Mutual NDA
- ★ Data Processing Agreement
- ★ W-9
- ★ Statement of Work
RESPONSIBLE DISCLOSURE
Security Disclosure & Responsible Reporting
If you discover a security issue affecting Advanced Learning Academy services, please report it responsibly.
Our Commitments
- ✓ Acknowledge within 24 hours
- ✓ Initial assessment within 5 business days
- ✓ Remediation progress updates
- ✓ Credit in security advisory (if desired)
We do not currently offer a paid bug bounty program.
Request Security Documentation
Complete this form to receive documents listed under "Available Under NDA" in the Download Vault.
Security questions? Contact [email protected] — we respond within 24 business hours.