ContentNest is built to protect the learning content and customer data you trust us with. Our security program is designed around the AICPA SOC 2 Trust Services Criteria — the same controls a Type II audit evaluates.
ContentNest is not yet SOC 2 certified. A SOC 2 Type II report requires an independent CPA firm to observe controls operating over a period of time, and that audit is on our roadmap below. In the meantime, we operate the controls listed here today and are transparent about what is still in progress. We're happy to walk a prospective customer through our current posture under NDA.
Protecting systems and data against unauthorized access, disclosure, and damage.
All traffic is served over TLS 1.2+; HTTP is redirected to HTTPS at the edge (CloudFront / load balancer).
Databases (RDS) and object storage (S3) are encrypted at rest using AWS-managed KMS keys.
Cloud access is granted through scoped IAM roles on a need-to-know basis; no routine use of root credentials.
Application secrets are stored in AWS Secrets Manager and injected at runtime — never committed to source control.
Databases run in private subnets with no public ingress; access is restricted by security groups.
MFA is enrolled and enforced on root and all human console users; access is denied for any session that is not MFA-authenticated.
Automated scanning of third-party dependencies for known vulnerabilities in CI.
Centralizing application and infrastructure logs with anomaly alerting.
A documented set of information-security policies covering access, data handling, and acceptable use.
Recurring security training for everyone with access to production systems or customer data.
A documented plan for detecting, responding to, and communicating about security incidents.
Keeping the service available for operation and use as committed.
Hosted on AWS (ECS Fargate, RDS, S3/CloudFront) using managed services, with encrypted and access-restricted data stores.
The database is backed up automatically with point-in-time recovery (7-day retention); object storage is durably replicated by AWS.
Continuous health checks and uptime monitoring with alerting on degradation.
A documented, periodically tested recovery plan with defined RTO/RPO targets.
Protecting information designated as confidential throughout its lifecycle.
ContentNest is multi-tenant by design; data is logically segregated and scoped per tenant on every request.
Access to customer data is limited to the minimum personnel required to operate and support the service.
Documented process for securely deleting customer data on request and at end of contract.
Ensuring processing is complete, valid, accurate, timely, and authorized.
Changes ship through an automated CI/CD pipeline; production deploys are built from version-controlled source.
Automated tests run on changes before release to catch regressions.
Documented change-control process with peer review and traceable release history.
Collecting, using, retaining, and disclosing personal information responsibly.
A public privacy policy describes what we collect, why, and how it is handled.
We collect only the personal data needed to deliver the service.
Process for handling access, correction, and deletion requests (GDPR / CCPA).
We maintain and disclose the list of subprocessors that may handle customer data.
The third parties that may process customer data on our behalf.
We're pursuing certification deliberately, in step with customer need.
Implement and document controls mapped to the SOC 2 Trust Services Criteria.
Adopt a complete information-security policy set and assign control ownership.
Onboard a compliance-automation platform to monitor controls continuously.
Engage an independent CPA firm for a SOC 2 Type II observation period and report.
Security and compliance teams: reach out and we'll share our current control documentation and answer your questionnaire — under NDA where needed.