Overview
A sanctions and restricted-party screening and compliance-workflow product for schools, universities, and research institutions.
- Screens students, guardians, tuition payors, sponsors, donors, agents, researchers, faculty, vendors, and related organizations.
- Supports roster import, screening, case review, continuous monitoring, evidence packs, and audit history.
- Designed to help you document reasonable care — not to replace your compliance program.
Hosting & infrastructure
In placeBuilt on managed, redundant cloud platforms in US regions.
- Application served on Vercel (edge and serverless).
- Database, authentication, and file storage on Supabase (PostgreSQL).
- US-region processing; region and residency requirements are confirmed during onboarding.
Authentication & access control
In placeAccess is authenticated, role-based, and fails closed.
- Authentication through the SecurePoint platform identity layer (Supabase Auth).
- Multi-factor authentication available; Microsoft Azure AD (OAuth) single sign-on supported.
- Server-side role-based access control; privileged compliance actions require an explicit permission.
- Fails closed: the app renders only for an authenticated user with an active organization and an enabled entitlement.
Tenant isolation
In placeEach organization’s data is isolated at the database layer, not only in application code.
- Every record is scoped to an organization identifier.
- PostgreSQL Row-Level Security enforces that scoping at the database engine, so isolation holds even if application logic fails.
- Uploaded files and evidence are kept in private storage buckets with organization-scoped access.
Encryption
In placeEncrypted in transit and at rest.
- TLS encryption for traffic in transit.
- Provider-managed encryption at rest for the database and file storage.
- Exact encryption standards are confirmed in the full security packet.
Audit log & evidence
In placeA durable, append-only record of compliance activity.
- The audit log is append-only — updates and deletes are blocked for the application role.
- Audit records hold identifiers, actions, and codes; they are designed to avoid raw personal data.
- Evidence packs are PDFs with a SHA-256 integrity hash, generated only for resolved cases.
Screening integrity
In placeScreening is rules-based, fails closed, and a person makes the final call.
- Screens by default against the OFAC SDN list, the OFAC sectoral and U.S. Consolidated Screening List (which includes the BIS Entity List), and the BIS Denied Persons List; additional sources are configurable.
- Potential matches are reviewed and dispositioned by a person, with the decision and reviewer recorded — matches are never automatically cleared.
- Fails closed: a failed or stale screen routes to review rather than a silent pass.
- Active records are re-screened on a recurring monitoring schedule.
- AI features assist drafting only; they do not make screening or compliance decisions.
Data & privacy
In placeWe ask for the minimum needed to screen, and you stay in control of what you send.
- Only a name and a role are required; everything else is optional.
- Social Security numbers are not collected or required.
- The read-only import preview returns counts and summaries only — never raw row data.
- You decide which records and fields to upload and who in your organization can import, review, or export.
FERPA-aligned handling
In placeFor FERPA-regulated education records, SecurePoint Education is designed to operate under your institution's DPA and FERPA Addendum as a limited-purpose service provider.
- Institutions designate SecurePoint as a school official/service provider with a legitimate educational interest for sanctions and restricted-party screening workflows.
- Education records are used only for the authorized screening, review, evidence, and audit workflow; they are not used for advertising or unrelated model training.
- Redisclosure is limited to authorized subprocessors, institution-directed disclosures, or legal requirements under the DPA and FERPA Addendum.
- SecurePoint assists the institution with student or parent record-review requests; the institution remains the FERPA decision-maker and compliance owner.
Subprocessors
In placeVetted service providers that support the product. The complete list and data scope are in the security packet.
- Supabase — database, authentication, and storage.
- Vercel — application hosting.
- Upstash Redis — rate limiting.
- Sentry and Datadog — error and performance monitoring.
- Resend and Twilio — email and SMS notifications.
- Stripe — billing.
- Groq and OpenAI — AI-assisted drafting.
Data retention
In placeRetention is aligned to sanctions recordkeeping and configurable to your policy.
- Default retention of 10 years, aligned to OFAC recordkeeping (31 CFR 501.601).
- Configurable per organization; cleanup runs server-side and is audited.
- Deletion or pseudonymization is supported on request, consistent with required audit trails.
Incident response
In placeA documented process for detecting, containing, and learning from incidents.
- Internal incident-response runbook covering detection, containment, investigation, communication, and post-incident review.
- The append-only audit trail is preserved and can be exported for forensics.
- Security incidents can be reported to security@securepointusa.com.
Business continuity
In placeResilience comes from managed, redundant platforms and a stateless application tier.
- The application tier is stateless and runs on provider-redundant infrastructure.
- The authoritative database is managed PostgreSQL with provider-managed backups.
- The cache tier is not a system of record and degrades safely if unavailable.
- Recovery objectives and backup details are provided during enterprise due diligence.
Compliance posture
In progressWe claim only what we can evidence. Certifications are in progress and not asserted without a signed report.
- SOC 2 Type II — controls mapping in progress; no certification report available (target window Q2–Q3 2026, subject to auditor timelines).
- ISO 27001 — readiness and policy alignment in progress; not certified.
- CMMC Level 2 — control mapping in progress; no assessment report.
- The product supports your institution’s compliance program; it does not make your institution compliant on its own.
Frequently asked questions
How do you stop one school from seeing another school’s data?
Do you have a SOC 2 report?
Does AI make the screening decision?
What data do you need, and do you need Social Security numbers?
How do you handle FERPA-regulated student records?
Where is our data stored, and how long do you keep it?
Can we get your full security packet or a questionnaire response?
Reviewing SecurePoint Education?
We are glad to support your IT, finance, and compliance review. Email us for the full vendor-review packet, a completed security questionnaire, or a walkthrough.
Email security@securepointusa.com