Security & Data Governance
Security & Data Protection
This page documents the security and data-protection controls used across Elevate for Humanity public, learning, apprenticeship, administrative, and partner systems.
Reviewed: August 20, 2026
Identity and access control
Authenticated services use role- and relationship-based authorization. Privileged operations are separated from learner and public access. Authorization must be enforced on the server and in database policies rather than relying only on hidden navigation or client-side checks.
Database protection and tenant boundaries
Production data is protected with database access policies, including row-level security where applicable. Administrative and service-role access is restricted to trusted server-side operations. Cross-tenant and cross-user access is treated as a security defect and is included in hardening and regression work.
Encryption and transport
Public and authenticated production services use encrypted HTTPS transport. Managed infrastructure and service providers apply their platform encryption and key-management controls to hosted data according to the service configuration and contract.
Application and release controls
Source changes are version controlled and production releases are subject to build, integrity, security, route, accessibility, and workflow checks. A successful source commit is not treated as proof that a production release is healthy; deployed services require production verification.
Audit and operational evidence
Administrative, application, apprenticeship, credential, attendance, AI-assisted, and other consequential workflows use database records or audit events appropriate to the feature. Auditability is an engineering control and does not by itself constitute a third-party compliance certification.
Payments and sensitive data
Card payment data is handled by payment processors rather than intentionally storing full payment-card numbers or card security codes in the application database. Sensitive identity and participant records are restricted to the workflows and roles that require them.
Incident and vulnerability handling
Suspected security incidents, access-control failures, exposed secrets, vulnerable dependencies, or data-integrity issues are investigated, contained, remediated, and documented according to the affected system and applicable notification or contractual obligations.
Backups, availability, and recovery
Availability and recovery depend on the managed production services, database configuration, deployment architecture, and operational procedures in use at the time. This page does not publish an uptime, recovery-time, or recovery-point guarantee unless that commitment is included in an executed service agreement.
Security questions, incidents, and procurement review
Use the contact channel to report a suspected security issue or request security architecture, data-flow, access-control, subprocessor, or procurement information appropriate to an authorized review.