Security & certifications

    A security posture institutions can defend.

    ScreenComply is a remote-proctoring and integrity-analysis platform for higher education. Production runs on AWS, fronted by Cloudflare. We operate under FERPA as a school official under §99.31(a)(1)(i)(B), with a complete CSA STAR Level 1 self-assessment, a HECVAT Lite on file, and an active SOC 2 readiness program.

    CSA STAR L1 · HECVAT Lite · SOC 2 Type 1 in progress (Q3 2026) · Internal pentest: 0 findings

    At a glance

    The numbers behind our posture.

    Concrete evidence — not vague reassurance. Every figure below is backed by a document on file, available to procurement and security review teams.

    37 / 38SOC 2 Trust Services Criteria controls In Place; 1 Partial, 0 Gap
    0open findings across all severities on the internal penetration test
    0known vulnerabilities in production dependencies (pip-audit, June 2026)

    Certifications & assessments

    Where we stand across every layer.

    Inherited certifications come from our hosting and edge providers. Application-level certifications are tracked at the ScreenComply application and desktop agent directly, audited against the same evidence customers receive.

    InheritedInfrastructure (AWS)

    SOC 1 / SOC 2 Type 2, SOC 3, ISO 27001:2022, ISO 27017/018, PCI DSS L1

    Production runs on AWS us-east-1; AWS holds active SOC 2 Type 2 and ISO 27001:2022.

    InheritedEdge (Cloudflare)

    SOC 2 Type 2, SOC 3, ISO 27001, ISO 27701, PCI DSS L1, CSA STAR L1

    DNS, WAF, and DDoS protection on Cloudflare edge; active SOC 2 Type 2 and ISO 27001.

    CompleteScreenComply Application

    CSA STAR Level 1 (CAIQ v4.0.3)

    Completed June 2026. Published to the CSA STAR Registry (star.watch).

    CompleteScreenComply Application

    HECVAT Lite

    Completed June 2026. Published to the HECVAT Cloud Broker Index.

    PassedScreenComply Application

    Internal Penetration Test

    Completed June 2026 against production. Zero open findings across all severities.

    ActiveDesktop Agent

    Signed Installer / Registered Partner

    Apple Developer Program, Microsoft Partner Center, Google Play Console.

    In progressScreenComply Application

    SOC 2 Type 1

    Target Q3 2026 via Drata. Security, Availability, and Confidentiality TSCs.

    In progressScreenComply Application

    SOC 2 Type 2

    Target Q4 2026. Requires a 6-month observation window post-Type 1.

    In progressScreenComply Application

    ISO 27001:2022

    Following SOC 2 Type 1; controls mapping maintained in parallel.

    InitiatedScreenComply Application

    Third-Party Penetration Test

    Q3 2026 engagement via Sensiba; attestation shared under NDA.

    CSA STAR Registry entry published at star.watch · HECVAT Cloud Broker Index entry available on request

    SOC 2 readiness

    38 controls assessed. 37 in place. 0 gaps.

    Trust Services Criteria coverage as of June 2026 across Security (CC), Availability (A1), and Confidentiality (C1). Tracked continuously in Drata; Type 1 audit targets Q3 2026.

    TSC familyTotalIn placePartialGap
    CC1 — Control Environment5500
    CC2 — Communication3300
    CC3 — Risk Assessment4400
    CC4 — Monitoring2200
    CC5 — Control Activities3300
    CC6 — Logical & Physical Access8800
    CC7 — System Operations5410
    CC8 — Change Management1100
    CC9 — Risk Mitigation2200
    A1 — Availability3300
    C1 — Confidentiality2200
    Total383710
    Remaining partial control — what closes itCC7.5 / A1.3 (Recovery testing) — first quarterly backup restore test scheduled by 2026-09-15.

    Documents on file

    Everything procurement and security teams ask for.

    The full policy set and unredacted pentest report are available under NDA from info@screencomply.ai.

    Information Security Policy Set

    22 sections covering all CCM domains; founder-signed 2026-06-15.

    SOC 2 Readiness Checklist

    38 controls mapped; 37 In Place, 1 Partial, 0 Gap.

    Security Overview

    Customer-facing posture summary, sub-processor register, and encryption matrix.

    Internal Penetration Test Report

    June 2026; 0 findings across all severities. Available under NDA.

    Data Processing Agreement (DPA)

    Available for all institutional customers; names FERPA §99.31(a)(1)(i)(B) designation.

    Penetration test

    Internal pentest — zero open findings.

    Engagement dated June 15, 2026. Source-code static analysis with manual confirmation across 177 HTTP routes, authentication, LTI 1.3, magic-link and OAuth code, and object-storage access gating. Third-party external pentest with Sensiba commissioned for Q3 2026.

    Critical0
    High0
    Medium0
    Low0

    Controls confirmed effective

    VERIFIED DURING THE REVIEW PASS

    • Magic-link tokens use 16 bytes of entropy from a cryptographically secure source — guessing is computationally infeasible.
    • HMAC token comparisons use constant-time comparison. No timing side channel.
    • Subprocess invocation uses argument lists throughout. No shell injection surface.
    • No eval, exec, or os.system invocation on user-controlled input.
    • LTI signature verification correctly binds issuer and audience to the signed decode.
    • S3 path-traversal protection normalizes folder names; no escape from the tenant prefix.
    • Filename sanitization for S3 keys is robust against control characters and path separators.
    • Tenant scoping on read paths correctly intersects with organization membership.
    • AI Review endpoints enforce per-object access on every mutation.
    • Recording-list endpoint scopes to the caller's organization.

    Defense-in-depth additions

    HARDENING BEYOND THE FINDINGS

    • Session cookies flagged HttpOnly, SameSite=Lax, and Secure in production.
    • Outbound HTTP fetches on URL analysis disable automatic redirect following — prevents redirect-based SSRF bypass.
    • Audit log captures every privileged action (login, login failure, impersonation enter/exit, member change) with actor, target, action, IP, and timestamp.
    Dependency scanning — pip-audit, June 16, 2026Zero known vulnerabilities detected across the full production requirements.txt for the Flask API. Cadence going forward: monthly manual audit or on addition of any new production dependency.

    Sub-processors

    Full transparency on who touches customer data.

    Signed DPAs are maintained for all critical vendors. 30-day advance notice is provided for any material change to sub-processors. Annual vendor compliance audits — next review June 1, 2027.

    Vendors receiving customer data by default

    Amazon Web Services

    Compute, database, and storage hosted in us-east-1. Holds SOC 1/2/3, ISO 27001/17/18, and PCI DSS L1.

    Cloudflare

    DNS, WAF, and DDoS protection. Holds SOC 2 Type 2, ISO 27001, and PCI DSS L1.

    Vendors receiving data on customer opt-in

    Google APIs

    Optional Workspace integration for calendar sync and meeting recording retrieval.

    Zoom APIs

    Optional integration for automated recording ingestion and analysis.

    Resend

    Transactional email delivery for magic-links and notifications. Holds SOC 2 Type 2.

    Prohibited third-party integrationsScreenComply does not use any of the following with candidate data:
    • Public LLM APIs (OpenAI / Anthropic) for candidate data
    • Third-party analytics (Google Analytics / Mixpanel)
    • Marketing pixels (Meta / LinkedIn)
    • External chat / support widgets (Intercom / Drift)

    Talk to security

    Need our security package for procurement?

    Send security questionnaires, DPA requests, or pentest report requests to our security team. Typical response within 2 business days.