Security

Current controls, plainly stated.

This page describes the deployed architecture and operating posture. It is not a SOC 2, ISO 27001, penetration-test, or regulatory certification.

Architecture and access

Application controls

Known work before a K–12 production pilot: complete the live database function-permission review, demonstrate comprehensive deletion in a disposable environment, establish incident-response ownership and notification terms, and complete independent legal/security review.

Incident reporting

Report a suspected security or privacy incident to kevinchoi@vindicaseneca.com. Include the affected URL, approximate time, and steps to reproduce; do not email student data, passwords, API keys, or exploit payloads containing live records.

Verification available to a school

Before a production pilot, Vindica can provide a scoped architecture diagram, data-field schedule, subprocessor list, access review, migration record, test results, and deletion rehearsal. Evidence is shared under appropriate confidentiality; it should be evaluated by the school rather than treated as a blanket assurance.

Last reviewed: September 27, 2026 (pre-pilot work list re-checked; leaked-password protection confirmed on)