Enterprise-Grade Security

Trust Center

SkillsOS is built with security and compliance at its core. We understand the unique requirements of higher education institutions and are committed to protecting student data and institutional information.

FERPA Compliant
SOC 2 Type II
GDPR Ready
HECVAT Assessed

Compliance & Certifications

We maintain rigorous compliance standards to meet the regulatory requirements of educational institutions.

Compliant

FERPA Compliance

Full compliance with the Family Educational Rights and Privacy Act, ensuring protection of student education records.

Compliant

SOC 2 Type II

Independent audit verification of our security controls, availability, processing integrity, and confidentiality.

Compliant

GDPR Compliance

Ready to handle data from EU students and staff with full GDPR compliance for international institutions.

Compliant

HECVAT Assessment

Completed Higher Education Community Vendor Assessment Toolkit for streamlined procurement processes.

Compliant

WCAG 2.1 AA

Web Content Accessibility Guidelines compliance ensuring our platform is accessible to all users.

Compliant

CCPA Compliance

California Consumer Privacy Act compliance for institutions with California-based students and staff.

Security Features

Enterprise-grade security measures to protect your institution's data at every level.

Data Protection

Encryption at Rest

All data is encrypted using AES-256 encryption when stored in our databases.

Encryption in Transit

TLS 1.3 encryption for all data transmitted between your browser and our servers.

Automated Backups

Daily encrypted backups with point-in-time recovery and geographic redundancy.

Data Minimization

We only collect and retain data necessary for platform functionality.

Access Control

Role-Based Access Control

Granular permissions ensure users only access data relevant to their role.

Multi-Factor Authentication

Optional MFA support for enhanced account security.

Single Sign-On (SSO)

Integration with your institution's identity provider (SAML 2.0, OAuth 2.0).

Session Management

Automatic session timeout and secure session handling.

Infrastructure Security

Cloud Infrastructure

Hosted on enterprise-grade cloud infrastructure with SOC 2 certification.

DDoS Protection

Advanced DDoS mitigation to ensure platform availability.

Web Application Firewall

WAF protection against common web vulnerabilities and attacks.

99.9% Uptime SLA

Enterprise service level agreement with guaranteed availability.

Monitoring & Response

24/7 Monitoring

Continuous security monitoring and anomaly detection.

Incident Response

Documented incident response procedures with defined SLAs.

Penetration Testing

Regular third-party penetration testing and vulnerability assessments.

Audit Logging

Comprehensive audit trails for all system activities.

Have Security Questions?

Our security team is available to answer your questions, provide additional documentation, or schedule a security review call.