SecurePoint Education
Contact security

Trust & Security

Security at SecurePoint Education

SecurePoint Education screens the people and organizations your institution designates against U.S. sanctions and watch lists, routes potential matches to a human reviewer, and keeps a time-stamped record. It is one control within your compliance program — the legal obligation to comply with sanctions law stays with your institution.

Last updated June 30, 2026

01

Overview

A sanctions and restricted-party screening and compliance-workflow product for schools, universities, and research institutions.

  • Screens students, guardians, tuition payors, sponsors, donors, agents, researchers, faculty, vendors, and related organizations.
  • Supports roster import, screening, case review, continuous monitoring, evidence packs, and audit history.
  • Designed to help you document reasonable care — not to replace your compliance program.
02

Hosting & infrastructure

In place

Built on managed, redundant cloud platforms in US regions.

  • Application served on Vercel (edge and serverless).
  • Database, authentication, and file storage on Supabase (PostgreSQL).
  • US-region processing; region and residency requirements are confirmed during onboarding.
03

Authentication & access control

In place

Access is authenticated, role-based, and fails closed.

  • Authentication through the SecurePoint platform identity layer (Supabase Auth).
  • Multi-factor authentication available; Microsoft Azure AD (OAuth) single sign-on supported.
  • Server-side role-based access control; privileged compliance actions require an explicit permission.
  • Fails closed: the app renders only for an authenticated user with an active organization and an enabled entitlement.
04

Tenant isolation

In place

Each organization’s data is isolated at the database layer, not only in application code.

  • Every record is scoped to an organization identifier.
  • PostgreSQL Row-Level Security enforces that scoping at the database engine, so isolation holds even if application logic fails.
  • Uploaded files and evidence are kept in private storage buckets with organization-scoped access.
05

Encryption

In place

Encrypted in transit and at rest.

  • TLS encryption for traffic in transit.
  • Provider-managed encryption at rest for the database and file storage.
  • Exact encryption standards are confirmed in the full security packet.
06

Audit log & evidence

In place

A durable, append-only record of compliance activity.

  • The audit log is append-only — updates and deletes are blocked for the application role.
  • Audit records hold identifiers, actions, and codes; they are designed to avoid raw personal data.
  • Evidence packs are PDFs with a SHA-256 integrity hash, generated only for resolved cases.
07

Screening integrity

In place

Screening is rules-based, fails closed, and a person makes the final call.

  • Screens by default against the OFAC SDN list, the OFAC sectoral and U.S. Consolidated Screening List (which includes the BIS Entity List), and the BIS Denied Persons List; additional sources are configurable.
  • Potential matches are reviewed and dispositioned by a person, with the decision and reviewer recorded — matches are never automatically cleared.
  • Fails closed: a failed or stale screen routes to review rather than a silent pass.
  • Active records are re-screened on a recurring monitoring schedule.
  • AI features assist drafting only; they do not make screening or compliance decisions.
08

Data & privacy

In place

We ask for the minimum needed to screen, and you stay in control of what you send.

  • Only a name and a role are required; everything else is optional.
  • Social Security numbers are not collected or required.
  • The read-only import preview returns counts and summaries only — never raw row data.
  • You decide which records and fields to upload and who in your organization can import, review, or export.
09

FERPA-aligned handling

In place

For FERPA-regulated education records, SecurePoint Education is designed to operate under your institution's DPA and FERPA Addendum as a limited-purpose service provider.

  • Institutions designate SecurePoint as a school official/service provider with a legitimate educational interest for sanctions and restricted-party screening workflows.
  • Education records are used only for the authorized screening, review, evidence, and audit workflow; they are not used for advertising or unrelated model training.
  • Redisclosure is limited to authorized subprocessors, institution-directed disclosures, or legal requirements under the DPA and FERPA Addendum.
  • SecurePoint assists the institution with student or parent record-review requests; the institution remains the FERPA decision-maker and compliance owner.
10

Subprocessors

In place

Vetted service providers that support the product. The complete list and data scope are in the security packet.

  • Supabase — database, authentication, and storage.
  • Vercel — application hosting.
  • Upstash Redis — rate limiting.
  • Sentry and Datadog — error and performance monitoring.
  • Resend and Twilio — email and SMS notifications.
  • Stripe — billing.
  • Groq and OpenAI — AI-assisted drafting.
11

Data retention

In place

Retention is aligned to sanctions recordkeeping and configurable to your policy.

  • Default retention of 10 years, aligned to OFAC recordkeeping (31 CFR 501.601).
  • Configurable per organization; cleanup runs server-side and is audited.
  • Deletion or pseudonymization is supported on request, consistent with required audit trails.
12

Incident response

In place

A documented process for detecting, containing, and learning from incidents.

  • Internal incident-response runbook covering detection, containment, investigation, communication, and post-incident review.
  • The append-only audit trail is preserved and can be exported for forensics.
  • Security incidents can be reported to security@securepointusa.com.
13

Business continuity

In place

Resilience comes from managed, redundant platforms and a stateless application tier.

  • The application tier is stateless and runs on provider-redundant infrastructure.
  • The authoritative database is managed PostgreSQL with provider-managed backups.
  • The cache tier is not a system of record and degrades safely if unavailable.
  • Recovery objectives and backup details are provided during enterprise due diligence.
14

Compliance posture

In progress

We claim only what we can evidence. Certifications are in progress and not asserted without a signed report.

  • SOC 2 Type II — controls mapping in progress; no certification report available (target window Q2–Q3 2026, subject to auditor timelines).
  • ISO 27001 — readiness and policy alignment in progress; not certified.
  • CMMC Level 2 — control mapping in progress; no assessment report.
  • The product supports your institution’s compliance program; it does not make your institution compliant on its own.
15

Frequently asked questions

How do you stop one school from seeing another school’s data?
Every record is tagged with an organization identifier, and PostgreSQL Row-Level Security enforces that scoping at the database layer — so a query cannot reach another organization’s data even if application logic has a bug.
Do you have a SOC 2 report?
Our SOC 2 Type II controls mapping is in progress and no certification report is available yet (target window Q2–Q3 2026, subject to auditor timelines). We do not claim a certification unless we can provide a signed report during due diligence.
Does AI make the screening decision?
No. Screening is rules-based matching against sanctions and watch lists, and every potential match is reviewed and dispositioned by a person with the decision recorded. AI features assist with drafting only and never decide a match.
What data do you need, and do you need Social Security numbers?
Only a name and a role are required; other fields are optional. Social Security numbers are not collected or required.
How do you handle FERPA-regulated student records?
SecurePoint Education is designed to operate under your institution's DPA and FERPA Addendum as a school-designated service provider/school official for the limited screening workflow you authorize. We use records only for that authorized workflow, limit redisclosure, assist the institution with record-review requests, and do not claim FERPA certification or replace the institution's compliance program.
Where is our data stored, and how long do you keep it?
Data is stored on managed cloud infrastructure (Supabase / Vercel) in US regions. Default retention is 10 years to align with OFAC recordkeeping, and it is configurable to your policy.
Can we get your full security packet or a questionnaire response?
Yes. Email security@securepointusa.com and we will share the vendor-review packet and complete a security questionnaire.

Reviewing SecurePoint Education?

We are glad to support your IT, finance, and compliance review. Email us for the full vendor-review packet, a completed security questionnaire, or a walkthrough.

Email security@securepointusa.com