Encryption, access, audit, and disclosures.
Who uses it: Admins and facilitators operating AmplifyED day to day. Purpose: The operational counterpart to the procurement facing FERPA overview — what you actually do inside…
Who uses it: Admins owning user lifecycle; security reviewers documenting access posture. When to use it: During onboarding, at every role change, and at quarterly access…
Purpose: Document encryption at rest, in transit, and for sensitive credentials. TLS 1.2 or higher on every connection. HSTS enabled with preload eligibility. Certificate…
Purpose: Describe how AmplifyED detects, escalates, and communicates about security incidents. A security incident is any confirmed or suspected event that affects: The…
Purpose: Tell good faith security researchers (and customer IT teams) how to report vulnerabilities responsibly. Email security@amplifyed.app with: A clear description of the…