AI Academy Platform — An AI Governance & Infrastructure Company
Trust, Governance & Enterprise Assurance
The Trust Center is the governance and assurance layer of the AI Academy Platform AI Governance & Infrastructure Ecosystem — supporting security, compliance, privacy, procurement readiness, and operational assurance for every organization we serve.
It gives enterprise customers, healthcare organizations, governments, and strategic partners confidence that our AI governance and operational infrastructure meets enterprise readiness expectations.
For procurement questionnaires, BAAs, DPAs, subprocessor lists, or our latest pentest attestation, contact security@aiacademy.example.
Access & Identity
Enterprise-grade identity controls, with single sign-on, MFA, and automated provisioning available on every plan.
Authentication
Email + password with optional Google sign-in. Organization-scoped membership controls access to every customer record.
Multi-Factor Authentication (MFA)
AvailableTOTP enrollment available for all users. Administrators can require MFA per organization via the Identity Center.
Single Sign-On (SAML 2.0 / OIDC)
AvailableEnterprise SSO supports Okta, Microsoft Entra ID, Google Workspace, and OneLogin. Configurable per organization.
SCIM 2.0 Provisioning
AvailableJust-in-time and lifecycle provisioning via standards-compliant SCIM endpoints. Compatible with Okta and Entra ID.
Role-Based Access Control
Roles are stored separately from user profiles and enforced by security-definer database functions and row-level security policies.
Data Protection
Customer data — including PHI in healthcare deployments — is encrypted, isolated, and audited end to end.
Encryption in Transit
All connections to the platform use TLS 1.2+. Internal traffic between the application and database is encrypted.
Encryption at Rest
Customer data, audit logs, and document storage are encrypted at rest by the managed backend provider.
Tenant Isolation
Row-level security policies enforce strict per-organization data isolation. Every customer-facing table is protected by RLS.
PHI Audit Logging
17 of 17 PHI modules instrumentedEvery read, create, and update of Protected Health Information is recorded in an append-only audit log with user, timestamp, resource, and organization.
Identity Audit Logging
SSO sign-ins, SCIM provisioning events, MFA enrollment, and session policy changes are recorded in the identity audit log.
Operations & Resilience
Documented runbooks, regular dependency scans, third-party penetration testing, and an exercised disaster recovery plan.
Vulnerability Management
Dependency scans run on every release. High and critical findings are triaged within one business day. Most recent external penetration test: see Resources.
Incident Response
Documented incident response runbook with breach notification workflow aligned to 60-day HIPAA breach notification timelines.
Disaster Recovery
Database backups run continuously with point-in-time recovery. DR drill executed; restoration time objective and validation results documented in Resources.
Change Management
All schema and policy changes are reviewed before deployment. Migrations are versioned and audit-tracked.
Compliance
HIPAA technical safeguards in place; SOC 2 Type I readiness complete; FERPA-aligned controls for higher education; GDPR DPA on request.
HIPAA Technical Safeguards
Unique user IDs, audit logging, encryption at rest and in transit, automatic session timeout via session policies. BAAs available on request for qualifying customers.
SOC 2 Readiness
SOC 2 Type I readiness pack completed (control matrix, narratives, audit evidence mapping, risk register). Type II audit roadmap in progress.
FERPA (Universities)
Education-facing modules support FERPA-aligned access controls and audit logging. Customer-specific FERPA addenda available on request.
GDPR & Data Subject Rights
Customer-initiated data export and deletion supported. DPA available on request.
Resources
Documentation available on request via security@aiacademy.example. Customers under NDA can request copies during procurement.
- SOC 2 Type I Readiness Pack— Available on request
- HIPAA Technical Safeguards Mapping— Available on request
- Penetration Test Report — Summary & Attestation— Available on request
- Disaster Recovery Drill Report— Available on request
- Data Processing Addendum (DPA)— Available on request
- Business Associate Agreement (BAA) Template— Available on request
- Subprocessor List— Available on request
- Incident Response Runbook (Summary)— Available on request
