Security
Security and compliance: where we stand
We are not SOC 2 certified. We are in the audit process, and this page says exactly where it stands: what is built, what is ahead, and when each step landed. It is updated as each step lands. Last updated September 14, 2026.
The short version
| Standard | Status |
|---|---|
| SOC 2 Type II | Pending. The audit is in progress: the scope is settled, the technical controls are built and checked against the live system, and a request for quotes is with three CPA audit firms. Auditor selection is underway. |
| HIPAA | Pending, in the same engagement. This training holds no protected health information. The HIPAA work covers the parts of the platform where clinical information is handled. |
| GDPR | We act as a sub-processor for the organizations that license this training. A person's record can be exported or erased on request, and what we keep and for how long is stated. |
What is built and running
These are the controls an auditor checks first. Each one is in place on the live system, and a readiness assessment re-checks them against production rather than against a checklist.
- Every client's data is walled off at the database, not only in the application. Every table that holds client data enforces row-level security on every query, and the account the site runs as cannot bypass it.
- Records that are evidence cannot be rewritten. Orders, invoices, certificates, escalations and audit events live in append-only ledgers that refuse updates and deletes.
- Administrators sign in with a one-time link sent to their email, and can turn on a second factor.
- Traffic is encrypted in transit and the site sends the standard browser security headers. The database connection itself runs over TLS.
- A person's record can be exported or erased on request. Erasure is a logged, ticketed scrub of personal data, and certificate records keep only what the law requires.
- Course media is served only to the people entitled to it. A signed-out link gets nothing.
The timeline
| Step | When | Status |
|---|---|---|
| Scope settled: SOC 2 Type II, with HIPAA in the same engagement | September 4, 2026 | Done |
| Readiness assessment built and run against the live system | September 4, 2026, and re-run since | Done, ongoing |
| Export and erasure of a person's record | September 6, 2026 | Done |
| Request for quotes to three CPA audit firms | September 2026 | Sent |
| Auditor selected and engaged | Pending | Ahead |
| Encryption of the database volume at rest | Needs a maintenance window. The date goes here when it is set. | Ahead |
| Observation period | Starts when the auditor is engaged. A Type II report covers at least three months of operation. | Ahead |
| Audit fieldwork and report | After the observation period | Ahead |
| Report available to customers under NDA | After the report is issued | Ahead |
See for yourself
If you are evaluating this platform for your organization, we would rather show you than tell you. Your security team can ask for the database-level controls, the readiness assessment output, and a walkthrough with the people who built it. Ask us on the help page.
Who runs the platform
This site runs on a learning platform built and operated by Special Learning. The audit covers that platform, so every organization that licenses training on it will be covered by the same report.