SECURITY & TRUST

Security & Trust

Advanced Learning Academy operates on enterprise-grade infrastructure with transparent security practices, federal-aligned compliance, and customer-controlled data sovereignty. Built for federal, healthcare, and Fortune 500 procurement scrutiny.

NIST CSF 2.0 Tier 3
Cloudflare Edge Network
TLS 1.3 Enforced
AES-256 At Rest
MFA Enforced
SOC 2 Inherited
FedRAMP Inherited
PCI DSS Level 1
GDPR Aligned
$1M Cyber Insurance

Compliance & Certification Status

NIST CSF 2.0

Self-Attested Tier 3 (Repeatable). All six functions assessed with subcategory-level ratings and gap analysis.

Documentation Available

SOC 2 Type II

Inherited via Cloudflare infrastructure. ALA-specific SOC 2 Type II audit planned for 2027.

Documentation Available

FedRAMP Moderate

Inherited via Cloudflare authorization. ALA infrastructure runs on FedRAMP-authorized Cloudflare services.

Documentation Available

PCI DSS Level 1

Inherited via Stripe payment processor. ALA never stores, processes, or transmits cardholder data directly.

Documentation Available

EEOC Uniform Guidelines

Assessment designed for alignment with EEOC Uniform Guidelines on Employee Selection Procedures.

Documentation Available

ADA Title III

Accessible design principles applied across all assessment and reporting interfaces.

Documentation Available

Section 508

Accessibility tested for compliance with Section 508 of the Rehabilitation Act.

Documentation Available

GDPR

Aligned for EU data subjects. Data processing agreements available. Right to erasure supported.

Documentation Available

CCPA

Compliant for California residents. No sale of personal information. Consumer rights honored.

Documentation Available

HIPAA

Coverage via insurance rider. Business associate agreements available upon request.

Documentation Available

FISMA

Alignment documentation available. Controls mapped to NIST SP 800-53 families.

Documentation Available

Four Deployment Models — Matched to Your Data Sensitivity

ALA understands that one deployment model does not fit every federal mission. Choose the model that fits your data sensitivity requirements.

DEFAULT

Standard Cloud

  • Infrastructure: Cloudflare Workers, US-region
  • Compliance: FedRAMP Moderate inherited
  • Suitable for: 90% of federal pilots
  • Availability: Immediately, standard pricing
PERSONNEL DATA

Anonymized Mode

  • Agency tokenizes identifiers before data reaches ALA
  • ALA receives only tokenized IDs and assessment responses
  • PII never crosses agency boundary
  • Availability: Immediately, $0 additional cost
AGENCY-ISOLATED

Dedicated Instance

  • Agency-dedicated Workers, D1, R2 storage
  • Agency-specific encryption keys
  • Isolated from all other ALA customers
  • Setup: 30-45 days, $50K-$150K
ON-PREM / GOVCLOUD

Custom Deployment

  • On-premises, AWS GovCloud, or Azure Government
  • Air-gap-compatible architecture
  • Setup: Scoped per agency
  • Pricing: $300K-$1.5M per engagement

What We Do With Your Data — In Plain English

YOUR DATA STAYS IN THE US.

All data stored in US-region Cloudflare data centers.

WE DO NOT TRAIN AI ON YOUR DATA.

Never used for AI/ML training or product improvement.

WE DO NOT SELL YOUR DATA.

No selling, sharing, licensing, or monetizing. Period.

YOU CONTROL RETENTION.

Default 1 year. Customers may specify 90 days to 7 years.

WE DELETE ON REQUEST.

Within 30 days, certified per NIST SP 800-88.

WE NOTIFY YOU OF INCIDENTS.

24 hours detection notice, 72 hours full forensic, 30 days written report.

YOU HAVE THE RIGHT TO AUDIT.

Self-attested, third-party, or on-site — your choice.

Security Architecture

Encryption

  • TLS 1.3 enforced via Cloudflare
  • AES-256 at rest (D1, R2, KV)
  • Payment data tokenized via Stripe
  • Email transit TLS-secured via Mailgun

Access Control

  • MFA on all admin accounts
  • Single-tenant logical isolation
  • Least-privilege enforced
  • Quarterly access review
  • No third-party access without BAA/DPA

Monitoring & Detection

  • Real-time Cloudflare WAF
  • DDoS mitigation (300+ global PoPs)
  • Application-level audit logging
  • Continuous vulnerability scanning
  • 24/7 security event monitoring

Subprocessors With Access to Customer Data

ALA discloses every third party that touches customer data. 30-day advance notification of any subprocessor changes.

Subprocessor Service Data Accessed Certifications
Cloudflare, Inc. Infrastructure All assessment and account data SOC 2 Type II, ISO 27001, FedRAMP Moderate
Stripe, Inc. Payment processing Payment information only PCI DSS Level 1, SOC 2 Type II
Mailgun (Sinch) Transactional email Email addresses, message content SOC 2 Type II, GDPR
Bunny.net Static asset CDN Static media files only (no PII) ISO 27001

Insurance Coverage

Coverage Types
General Liability $1,000,000 per occurrence / $2,000,000 aggregate
Cyber Liability $500,000
Errors & Omissions Active
Professional Liability Active
Certificate Availability
Certificates Available upon written request
Elevated Coverage $2M-$5M GL available per contract

Forward-Looking Security Commitments

1

Q3 2026

SOC 2 Type II audit initiation

2

Q4 2026

Annual penetration testing begins

3

Q1 2027

SOC 2 Type II report available

4

Ongoing

Quarterly access reviews, annual policy updates

Security Documentation

Available Under NDA

  • Subprocessor & Data Flow Document
  • Detailed Control Matrix
  • Incident Response Plan
  • Business Continuity Plan
  • Insurance Certificates

Available Upon Engagement

  • Master Services Agreement
  • Mutual NDA
  • Data Processing Agreement
  • W-9
  • Statement of Work

Security Disclosure & Responsible Reporting

If you discover a security issue affecting Advanced Learning Academy services, please report it responsibly.

Report To

[email protected]

Subject: "Security Disclosure — [Brief Description]"

Our Commitments

  • Acknowledge within 24 hours
  • Initial assessment within 5 business days
  • Remediation progress updates
  • Credit in security advisory (if desired)

We do not currently offer a paid bug bounty program.

Request Security Documentation

Complete this form to receive documents listed under "Available Under NDA" in the Download Vault.

Security questions? Contact [email protected] — we respond within 24 business hours.