Enterprise-Grade Security
How we protect your data, accounts, and certification integrity.
Security Architecture
Defense in depth, by default
Every layer of the Agency Script platform is designed with security as a first-class concern, from the edge to the database.
Authentication & Access Control
Passwords hashed with bcrypt (cost factor 12). Short-lived JWT sessions with refresh rotation. Multi-factor authentication available for all accounts. Fine-grained role-based access control across learner, instructor, and admin scopes.
Data Protection
TLS 1.3 enforced for all data in transit. AES-256 encryption at rest for sensitive fields. Strict tenant isolation at the database row level ensures no cross-account data leakage.
Audit & Compliance
Immutable, append-only audit logs for every privileged action. Hash-chain integrity verification prevents retroactive tampering. Controls mapped to SOC 2 Trust Services Criteria.
API Security
Adaptive rate limiting per endpoint and per consumer. Scoped API key management with automatic rotation reminders. Request-level abuse detection and CSRF protection on all state-changing operations.
Session Security
Short-lived access tokens (15 min) with secure, httpOnly refresh cookies. Step-up authentication required for sensitive operations like credential issuance. Instant session invalidation on password change.
Infrastructure
Served behind the Cloudflare edge network with automatic DDoS mitigation and a managed WAF. Self-hosted PostgreSQL supports point-in-time recovery patterns; restore-test claims publish only after owner-approved evidence exists. Environment secrets are managed through encrypted vaults, never checked into source.
Compliance Posture
Frameworks we align to
We map our controls to widely recognized security and AI governance frameworks so enterprise teams can evaluate us with confidence.
SOC 2
Controls mapped to Trust Services Criteria for security, availability, and confidentiality. Formal audit evidence is published only after owner-approved reports exist.
GDPR
Data minimization, privacy-rights workflows, and enterprise DPA support are mapped for review.
CCPA
Consumer-rights workflows are mapped for access, deletion, and opt-out handling.
EU AI Act (Article 9)
Risk management, data governance, and transparency obligations mapped for AI-driven assessment features.
ISO 27001
Information security management controls aligned to Annex A. Formal certification on the roadmap.
NIST AI RMF
AI risk functions (Govern, Map, Measure, Manage) applied to our certification and assessment pipelines.
Certification Integrity
Credentials you can trust
An AI certification is only as valuable as the integrity behind it. We enforce anti-fraud measures at every stage of the assessment lifecycle.
Proctoring Session Monitoring
Timed exam sessions with activity telemetry detect anomalous patterns and flag submissions for review.
Watermark Tokens
Every lab session and exam attempt is tagged with a unique, non-removable watermark token for traceability.
Integrity Hash Verification
Submissions are SHA-256 hashed at capture time. Any post-submission modification is cryptographically detectable.
Multi-Reviewer Panel
High-tier certifications require independent review by multiple qualified assessors before credential issuance.
Credential Revocation
Credentials can be revoked instantly if fraud or policy violations are confirmed, with full audit trail.
Public Verification API
Employers and partners can verify any credential in real time through our public verification endpoint.
Data Retention & Privacy
Your data, your rights
We collect only what is necessary, retain it only as long as required, and give you full control over your information.
Retention Schedules
- Account data retained while the account is active, deleted within 30 days of closure.
- Certification records retained for 7 years to support credential verification.
- Audit logs retained for 3 years. Legal hold exemptions override standard schedules when required.
Privacy Rights
- Self-service data export in machine-readable format (JSON) from your account settings.
- Right-to-delete requests processed within 15 business days.
- GDPR Article 30 records of processing activities maintained and available on request for DPA signatories.
Responsible Disclosure
Report a vulnerability
We value the security research community. If you discover a vulnerability, we want to hear about it and will work with you to resolve it quickly.
Contact
security@agencyscript.comResponse time: We acknowledge reports within 2 business days and aim to provide a resolution timeline within 5 business days.
Safe harbor:We will not pursue legal action against researchers who act in good faith, follow responsible disclosure practices, and do not access or modify other users' data.
Acknowledgment: With your permission, we will recognize your contribution on our security hall of fame.
Last reviewed: March 2026
For security inquiries, Data Processing Agreements, or to request our full security documentation package, contact security@agencyscript.com.