Skip to main content

Security & Data Governance

Security & Data Protection

This page documents the security and data-protection controls used across Elevate for Humanity public, learning, apprenticeship, administrative, and partner systems.

Reviewed: August 20, 2026

This is a control description, not a SOC 2, ISO 27001, FedRAMP, StateRAMP, penetration-test, or other independent certification claim. A certification or assurance report is represented only when a current supporting record exists.

Identity and access control

Authenticated services use role- and relationship-based authorization. Privileged operations are separated from learner and public access. Authorization must be enforced on the server and in database policies rather than relying only on hidden navigation or client-side checks.

Database protection and tenant boundaries

Production data is protected with database access policies, including row-level security where applicable. Administrative and service-role access is restricted to trusted server-side operations. Cross-tenant and cross-user access is treated as a security defect and is included in hardening and regression work.

Encryption and transport

Public and authenticated production services use encrypted HTTPS transport. Managed infrastructure and service providers apply their platform encryption and key-management controls to hosted data according to the service configuration and contract.

Application and release controls

Source changes are version controlled and production releases are subject to build, integrity, security, route, accessibility, and workflow checks. A successful source commit is not treated as proof that a production release is healthy; deployed services require production verification.

Audit and operational evidence

Administrative, application, apprenticeship, credential, attendance, AI-assisted, and other consequential workflows use database records or audit events appropriate to the feature. Auditability is an engineering control and does not by itself constitute a third-party compliance certification.

Payments and sensitive data

Card payment data is handled by payment processors rather than intentionally storing full payment-card numbers or card security codes in the application database. Sensitive identity and participant records are restricted to the workflows and roles that require them.

Incident and vulnerability handling

Suspected security incidents, access-control failures, exposed secrets, vulnerable dependencies, or data-integrity issues are investigated, contained, remediated, and documented according to the affected system and applicable notification or contractual obligations.

Backups, availability, and recovery

Availability and recovery depend on the managed production services, database configuration, deployment architecture, and operational procedures in use at the time. This page does not publish an uptime, recovery-time, or recovery-point guarantee unless that commitment is included in an executed service agreement.

Security questions, incidents, and procurement review

Use the contact channel to report a suspected security issue or request security architecture, data-flow, access-control, subprocessor, or procurement information appropriate to an authorized review.

Security & Data Protection | Elevate for Humanity