It’s all about Respect

Security

Security and compliance: where we stand

We are not SOC 2 certified. We are in the audit process, and this page says exactly where it stands: what is built, what is ahead, and when each step landed. It is updated as each step lands. Last updated September 14, 2026.

The short version

StandardStatus
SOC 2 Type IIPending. The audit is in progress: the scope is settled, the technical controls are built and checked against the live system, and a request for quotes is with three CPA audit firms. Auditor selection is underway.
HIPAAPending, in the same engagement. This training holds no protected health information. The HIPAA work covers the parts of the platform where clinical information is handled.
GDPRWe act as a sub-processor for the organizations that license this training. A person's record can be exported or erased on request, and what we keep and for how long is stated.

What is built and running

These are the controls an auditor checks first. Each one is in place on the live system, and a readiness assessment re-checks them against production rather than against a checklist.

  • Every client's data is walled off at the database, not only in the application. Every table that holds client data enforces row-level security on every query, and the account the site runs as cannot bypass it.
  • Records that are evidence cannot be rewritten. Orders, invoices, certificates, escalations and audit events live in append-only ledgers that refuse updates and deletes.
  • Administrators sign in with a one-time link sent to their email, and can turn on a second factor.
  • Traffic is encrypted in transit and the site sends the standard browser security headers. The database connection itself runs over TLS.
  • A person's record can be exported or erased on request. Erasure is a logged, ticketed scrub of personal data, and certificate records keep only what the law requires.
  • Course media is served only to the people entitled to it. A signed-out link gets nothing.

The timeline

StepWhenStatus
Scope settled: SOC 2 Type II, with HIPAA in the same engagementSeptember 4, 2026Done
Readiness assessment built and run against the live systemSeptember 4, 2026, and re-run sinceDone, ongoing
Export and erasure of a person's recordSeptember 6, 2026Done
Request for quotes to three CPA audit firmsSeptember 2026Sent
Auditor selected and engagedPendingAhead
Encryption of the database volume at restNeeds a maintenance window. The date goes here when it is set.Ahead
Observation periodStarts when the auditor is engaged. A Type II report covers at least three months of operation.Ahead
Audit fieldwork and reportAfter the observation periodAhead
Report available to customers under NDAAfter the report is issuedAhead

Type II is the one that matters. A Type I report shows the controls existed on one day. A Type II report shows they operated over a period. We chose to go straight to Type II.

See for yourself

If you are evaluating this platform for your organization, we would rather show you than tell you. Your security team can ask for the database-level controls, the readiness assessment output, and a walkthrough with the people who built it. Ask us on the help page.

Who runs the platform

This site runs on a learning platform built and operated by Special Learning. The audit covers that platform, so every organization that licenses training on it will be covered by the same report.