Skip to main content

Security

Data Protection & Compliance

Enterprise-grade security measures and compliance with educational privacy regulations. Learn how FragmentTrails protects student and candidate data while enabling fair, defensible assessments.

Security Framework

Data Encryption

TLS 1.3 for transit, AES-256 for at rest

Access Control

Role-based permissions and MFA

Compliance

FERPA and privacy regulation compliant

Audit Trails

Complete logging and monitoring

Data Protection Measures

Encryption Standards

FragmentTrails employs industry-standard encryption to protect data in transit and at rest. All API communications use TLS 1.3 with perfect forward secrecy. Data stored in our databases is encrypted using AES-256 encryption algorithms. Encryption keys are managed through a secure key management system with regular rotation policies.

Access Controls

Role-based access control ensures users only access data necessary for their roles. Multi-factor authentication is required for administrative access. Access requests are logged and reviewed regularly. Principle of least privilege is enforced across all systems and applications.

Data Retention

Data retention policies align with institutional requirements and legal obligations. Institutions can configure retention periods for different data types. Automated deletion processes remove data according to configured policies. Data export capabilities support institutional data management requirements.

Backup and Recovery

Automated daily backups with point-in-time recovery capabilities. Backups are encrypted and stored in geographically distributed locations. Recovery time objectives and recovery point objectives are defined and tested regularly. Disaster recovery procedures ensure business continuity.

Compliance Framework

FERPA Compliance

FragmentTrails is designed to comply with the Family Educational Rights and Privacy Act (FERPA). Our platform includes features for directory information management, consent tracking, and parental access controls. Data minimization practices limit collection to educationally relevant information. Regular compliance reviews ensure ongoing adherence to FERPA requirements.

GDPR Considerations

For institutions serving international students, FragmentTrails incorporates GDPR-compliant practices including data subject rights, cross-border data transfer mechanisms, and privacy by design principles. Data processing agreements clarify responsibilities between FragmentTrails and institutional data controllers.

Security Certifications

Our infrastructure maintains SOC 2 Type II compliance through regular third-party audits. Security practices align with NIST cybersecurity framework standards. Penetration testing and vulnerability assessments are conducted annually by independent security firms.

Institutional Compliance Support

FragmentTrails provides documentation and support for institutional compliance processes. This includes security assessment questionnaires, audit trail exports, and compliance documentation. Our team works with institutional legal and compliance offices to address specific requirements.

Incident Response

Monitoring and Detection

24/7 security monitoring detects potential threats and anomalies. Automated alerting notifies security teams of suspicious activities. Security information and event management (SIEM) systems correlate events across our infrastructure. Regular vulnerability scanning identifies potential security issues proactively.

Response Procedures

Documented incident response procedures outline roles, responsibilities, and escalation paths. Security incidents are classified according to severity and impact. Response timelines meet industry best practices. Post-incident reviews identify improvement opportunities.

Breach Notification

In the event of a data breach, FragmentTrails follows legal and contractual notification requirements. Affected institutions are notified promptly with relevant information about the incident and recommended actions. Coordination with institutional security teams ensures comprehensive response.

Security Questions?

Our security team is available to answer questions about our security practices, compliance measures, and data protection policies.