SOC 1 / SOC 2 Type 2, SOC 3, ISO 27001:2022, ISO 27017/018, PCI DSS L1
Production runs on AWS us-east-1; AWS holds active SOC 2 Type 2 and ISO 27001:2022.
Security & certifications
ScreenComply is a remote-proctoring and integrity-analysis platform for higher education. Production runs on AWS, fronted by Cloudflare. We operate under FERPA as a school official under §99.31(a)(1)(i)(B), with a complete CSA STAR Level 1 self-assessment, a HECVAT Lite on file, and an active SOC 2 readiness program.
CSA STAR L1 · HECVAT Lite · SOC 2 Type 1 in progress (Q3 2026) · Internal pentest: 0 findings
At a glance
Concrete evidence — not vague reassurance. Every figure below is backed by a document on file, available to procurement and security review teams.
Certifications & assessments
Inherited certifications come from our hosting and edge providers. Application-level certifications are tracked at the ScreenComply application and desktop agent directly, audited against the same evidence customers receive.
Production runs on AWS us-east-1; AWS holds active SOC 2 Type 2 and ISO 27001:2022.
DNS, WAF, and DDoS protection on Cloudflare edge; active SOC 2 Type 2 and ISO 27001.
Completed June 2026. Published to the CSA STAR Registry (star.watch).
Completed June 2026. Published to the HECVAT Cloud Broker Index.
Completed June 2026 against production. Zero open findings across all severities.
Apple Developer Program, Microsoft Partner Center, Google Play Console.
Target Q3 2026 via Drata. Security, Availability, and Confidentiality TSCs.
Target Q4 2026. Requires a 6-month observation window post-Type 1.
Following SOC 2 Type 1; controls mapping maintained in parallel.
Q3 2026 engagement via Sensiba; attestation shared under NDA.
CSA STAR Registry entry published at star.watch · HECVAT Cloud Broker Index entry available on request
SOC 2 readiness
Trust Services Criteria coverage as of June 2026 across Security (CC), Availability (A1), and Confidentiality (C1). Tracked continuously in Drata; Type 1 audit targets Q3 2026.
Documents on file
The full policy set and unredacted pentest report are available under NDA from info@screencomply.ai.
22 sections covering all CCM domains; founder-signed 2026-06-15.
38 controls mapped; 37 In Place, 1 Partial, 0 Gap.
Customer-facing posture summary, sub-processor register, and encryption matrix.
June 2026; 0 findings across all severities. Available under NDA.
Available for all institutional customers; names FERPA §99.31(a)(1)(i)(B) designation.
Penetration test
Engagement dated June 15, 2026. Source-code static analysis with manual confirmation across 177 HTTP routes, authentication, LTI 1.3, magic-link and OAuth code, and object-storage access gating. Third-party external pentest with Sensiba commissioned for Q3 2026.
VERIFIED DURING THE REVIEW PASS
HARDENING BEYOND THE FINDINGS
Sub-processors
Signed DPAs are maintained for all critical vendors. 30-day advance notice is provided for any material change to sub-processors. Annual vendor compliance audits — next review June 1, 2027.
Vendors receiving customer data by default
Compute, database, and storage hosted in us-east-1. Holds SOC 1/2/3, ISO 27001/17/18, and PCI DSS L1.
DNS, WAF, and DDoS protection. Holds SOC 2 Type 2, ISO 27001, and PCI DSS L1.
Vendors receiving data on customer opt-in
Optional Workspace integration for calendar sync and meeting recording retrieval.
Optional integration for automated recording ingestion and analysis.
Transactional email delivery for magic-links and notifications. Holds SOC 2 Type 2.
Talk to security
Send security questionnaires, DPA requests, or pentest report requests to our security team. Typical response within 2 business days.