Trust & Security

Security aligned with SOC 2 controls

ContentNest is built to protect the learning content and customer data you trust us with. Our security program is designed around the AICPA SOC 2 Trust Services Criteria — the same controls a Type II audit evaluates.

Where we stand

ContentNest is not yet SOC 2 certified. A SOC 2 Type II report requires an independent CPA firm to observe controls operating over a period of time, and that audit is on our roadmap below. In the meantime, we operate the controls listed here today and are transparent about what is still in progress. We're happy to walk a prospective customer through our current posture under NDA.

Status key:In placeIn progressPlannedLast reviewed: June 2026
CC — Common Criteria

Security

Protecting systems and data against unauthorized access, disclosure, and damage.

Encryption in transit
In place

All traffic is served over TLS 1.2+; HTTP is redirected to HTTPS at the edge (CloudFront / load balancer).

Encryption at rest
In place

Databases (RDS) and object storage (S3) are encrypted at rest using AWS-managed KMS keys.

Least-privilege access
In place

Cloud access is granted through scoped IAM roles on a need-to-know basis; no routine use of root credentials.

Secrets management
In place

Application secrets are stored in AWS Secrets Manager and injected at runtime — never committed to source control.

Network isolation
In place

Databases run in private subnets with no public ingress; access is restricted by security groups.

Multi-factor authentication
In place

MFA is enrolled and enforced on root and all human console users; access is denied for any session that is not MFA-authenticated.

Dependency & vulnerability scanning
In progress

Automated scanning of third-party dependencies for known vulnerabilities in CI.

Centralized logging & monitoring
Planned

Centralizing application and infrastructure logs with anomaly alerting.

Information security policies
Planned

A documented set of information-security policies covering access, data handling, and acceptable use.

Security awareness training
Planned

Recurring security training for everyone with access to production systems or customer data.

Incident response plan
Planned

A documented plan for detecting, responding to, and communicating about security incidents.

A — Availability

Availability

Keeping the service available for operation and use as committed.

Managed cloud infrastructure
In place

Hosted on AWS (ECS Fargate, RDS, S3/CloudFront) using managed services, with encrypted and access-restricted data stores.

Automated backups
In place

The database is backed up automatically with point-in-time recovery (7-day retention); object storage is durably replicated by AWS.

Uptime & health monitoring
In progress

Continuous health checks and uptime monitoring with alerting on degradation.

Disaster recovery plan
Planned

A documented, periodically tested recovery plan with defined RTO/RPO targets.

C — Confidentiality

Confidentiality

Protecting information designated as confidential throughout its lifecycle.

Tenant data isolation
In place

ContentNest is multi-tenant by design; data is logically segregated and scoped per tenant on every request.

Need-to-know access
In place

Access to customer data is limited to the minimum personnel required to operate and support the service.

Secure data disposal
In progress

Documented process for securely deleting customer data on request and at end of contract.

PI — Processing Integrity

Processing Integrity

Ensuring processing is complete, valid, accurate, timely, and authorized.

Reviewed CI/CD pipeline
In place

Changes ship through an automated CI/CD pipeline; production deploys are built from version-controlled source.

Automated testing
In progress

Automated tests run on changes before release to catch regressions.

Change management
In progress

Documented change-control process with peer review and traceable release history.

P — Privacy

Privacy

Collecting, using, retaining, and disclosing personal information responsibly.

Published privacy policy
In place

A public privacy policy describes what we collect, why, and how it is handled.

Data minimization
In place

We collect only the personal data needed to deliver the service.

Data subject requests
In progress

Process for handling access, correction, and deletion requests (GDPR / CCPA).

Subprocessor transparency
In progress

We maintain and disclose the list of subprocessors that may handle customer data.

Subprocessors

Who we rely on

The third parties that may process customer data on our behalf.

Amazon Web Services (AWS)
Cloud hosting, database, object storage, and transactional email (SES)
United States (us-east-1)
Stripe
Payment processing and billing
United States
Highlight.run
Application error and session monitoring
United States
Contentful
Headless CMS for marketing and content pages
European Union / United States
Roadmap

Our path to SOC 2 Type II

We're pursuing certification deliberately, in step with customer need.

1
Align to controlsIn progress

Implement and document controls mapped to the SOC 2 Trust Services Criteria.

2
Formalize policiesPlanned

Adopt a complete information-security policy set and assign control ownership.

3
Continuous monitoringPlanned

Onboard a compliance-automation platform to monitor controls continuously.

4
Type II auditPlanned

Engage an independent CPA firm for a SOC 2 Type II observation period and report.

Questions about security?

Security and compliance teams: reach out and we'll share our current control documentation and answer your questionnaire — under NDA where needed.

security@contentnest.ioTalk to our team