Technical Protection Measures
We implement multiple layers of security to protect sensitive data. All data transmissions are secured using 256-bit encryption, TLS 1.1, and HTTPS protocols, safeguarding information during transit. To prevent data leaks, we apply MD5 cryptographic hashing to lead and student data, such as email addresses and phone numbers. Our API security measures include authentication protocols, IP-based throttling, and geofencing to block unauthorized access. Furthermore, our multi-tenant architecture ensures strict data separation for each customer, preventing cross-account data access.
To enhance security, we enforce strict authentication and access management policies:
Mandatory Two-Factor Authentication (2FA): Required for all users via email and SMS.
Role-Based Access Control (RBAC): Restricting data access to only authorized personnel.
Limited Super Admins: No more than two super admins per account to prevent abuse.
Session & Device Security: Enforcing secure logins with 2FA for new devices and browsers.
Last updated