Security & Compliance
TL;DR: We use enterprise-grade security: AES-256 encryption, TLS 1.3, MFA, and regular audits. We comply with FERPA, GDPR, CCPA, and maintain HIPAA-ready practices. Report vulnerabilities to security@scrubcampus.com.
Security Commitment
At ScrubCampus, protecting your data is our highest priority. As a platform trusted by nursing students, educators, and healthcare institutions, we understand the sensitive nature of educational data and the importance of maintaining the highest security standards.
Our security program is designed around the principle of defense in depth, implementing multiple layers of protection to safeguard your information.
Infrastructure Security
Encryption
| Protection Layer | Standard | Details |
|---|---|---|
| Data in Transit | TLS 1.3 | HTTPS enforced via HSTS, forward secrecy enabled |
| Data at Rest | AES-256 | Database encryption, encrypted backups with separate keys |
| Key Management | Secure KMS | Keys managed through secure key management services |
Cloud Hosting
Our infrastructure is hosted on enterprise-grade cloud platforms that maintain:
| Certification | Status |
|---|---|
| SOC 2 Type II | Certified |
| ISO 27001 | Certified |
| Third-party Security Assessments | Regular |
| Physical Security | Biometric access, 24/7 monitoring |
Network Security
| Measure | Protection |
|---|---|
| Web Application Firewall (WAF) | Common attack prevention |
| DDoS Protection | Service availability |
| Intrusion Detection/Prevention | Threat monitoring |
| Network Segmentation | Component isolation |
Access Controls
| Control | Implementation |
|---|---|
| Role-Based Access (RBAC) | Least privilege access |
| Multi-Factor Authentication | Required for admin access |
| Privileged Access Management | Sensitive operations |
| Audit Logging | All sensitive data access logged |
| Regular Access Reviews | Periodic deprovisioning |
Application Security
Secure Development
Our development practices include:
- Secure coding guidelines and training for all developers
- Code review requirements for all changes
- Static application security testing (SAST) in CI/CD pipeline
- Dependency scanning for known vulnerabilities
- Regular third-party penetration testing
Authentication and Authorization
| Feature | Standard |
|---|---|
| Authentication Protocols | OAuth 2.0, OpenID Connect |
| Session Management | Automatic timeout |
| Password Requirements | Complexity and uniqueness enforced |
| Enterprise SSO | SAML 2.0 supported |
| Rate Limiting | Brute force prevention |
Data Protection
- Input validation and output encoding prevent injection attacks
- Content Security Policy (CSP) prevents cross-site scripting
- Protection against CSRF, clickjacking, and other common attacks
- Regular vulnerability assessments and remediation
Compliance
Quick Reference
| Regulation | Status | Key Points |
|---|---|---|
| FERPA | Compliant | School official status, no re-disclosure |
| GDPR | Compliant | DPAs with SCCs available |
| CCPA | Compliant | Full privacy rights supported |
| HIPAA | Ready | BAA available upon request |
FERPA Details (U.S. Educational Institutions)
- School Official Status: We operate as a “school official” under FERPA, with a legitimate educational interest in accessing student records
- Data Use Limitation: Educational records are used only for the purposes specified by the institution
- No Re-disclosure: We do not disclose personally identifiable information without consent except as permitted under FERPA
- Security Safeguards: Technical, administrative, and physical safeguards protect education records
- Data Processing Agreements: Our agreements with institutions include FERPA-compliant terms
GDPR Details (EU/UK/Switzerland)
- Lawful Basis: We process personal data only when we have a valid legal basis
- Data Minimization: We collect only the data necessary for our purposes
- Purpose Limitation: Data is used only for specified, explicit purposes
- Storage Limitation: Data is retained only as long as necessary
- Data Subject Rights: We support rights to access, rectification, erasure, portability, and objection
- Data Processing Agreements: We offer DPAs with Standard Contractual Clauses for international transfers
- Data Protection Officer: Available at dpo@scrubcampus.com
CCPA Details (California Residents)
- Right to Know: We disclose what personal information we collect and how we use it
- Right to Delete: Users can request deletion of their personal information
- Right to Opt-Out: We do not sell personal information
- Non-Discrimination: We do not discriminate against users who exercise their privacy rights
- Privacy Policy: Our Privacy Policy includes all required CCPA disclosures
HIPAA Details (Healthcare Organizations)
While ScrubCampus is primarily an educational platform and does not typically handle Protected Health Information (PHI), we maintain HIPAA-ready practices:
- Technical Safeguards: Encryption, access controls, and audit logging
- Administrative Safeguards: Policies, procedures, and training
- Physical Safeguards: Secure hosting environment
- Business Associate Agreements: Available for customers who require them
If your use case involves PHI, please contact us to discuss appropriate agreements.
Additional Standards
| Standard | Coverage |
|---|---|
| SOC 2 Type II | Security, availability, and confidentiality |
| ISO 27001 | Information security management |
| NIST Cybersecurity Framework | Risk management and security practices |
Incident Response
| Phase | Actions |
|---|---|
| Detection | 24/7 monitoring, automated alerting, severity classification |
| Containment | Immediate containment, root cause analysis, evidence preservation |
| Notification | Within 72 hours, clear communication, regulatory notifications |
| Recovery | Service restoration, post-incident review, preventive improvements |
Vulnerability Reporting
We welcome responsible security research and will not take legal action against researchers who make a good faith effort to follow these guidelines.
How to Report
Email: security@scrubcampus.com
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
Our Response
| Timeline | Action |
|---|---|
| Within 48 hours | Acknowledgment |
| Ongoing | Regular updates on remediation |
| After fix | Recognition in security hall of fame (if desired) |
Scope
| In Scope | Out of Scope |
|---|---|
| ScrubCampus web application | Physical attacks |
| ScrubCampus APIs | Social engineering on employees |
| Authentication systems | Denial of service attacks |
| Third-party services |
Data Processing Agreements
When You Need a DPA
| Situation | Need DPA? |
|---|---|
| U.S. educational institution (FERPA) | Yes |
| Processing EU resident data (GDPR) | Yes |
| Organizational policy requires it | Yes |
| Individual user account | No |
Request a DPA
Email: legal@scrubcampus.com
Include: organization name, contact information, and any specific requirements.
Contact Us
| Team | For | |
|---|---|---|
| Security | security@scrubcampus.com | Vulnerabilities, security inquiries |
| Privacy | privacy@scrubcampus.com | Data protection inquiries |
| DPO | dpo@scrubcampus.com | GDPR-related matters |
| Legal | legal@scrubcampus.com | DPAs, compliance documentation |