AI Academy Platform — An AI Governance & Infrastructure Company

Trust, Governance & Enterprise Assurance

The Trust Center is the governance and assurance layer of the AI Academy Platform AI Governance & Infrastructure Ecosystem — supporting security, compliance, privacy, procurement readiness, and operational assurance for every organization we serve.

It gives enterprise customers, healthcare organizations, governments, and strategic partners confidence that our AI governance and operational infrastructure meets enterprise readiness expectations.

For procurement questionnaires, BAAs, DPAs, subprocessor lists, or our latest pentest attestation, contact security@aiacademy.example.

Access & Identity

Enterprise-grade identity controls, with single sign-on, MFA, and automated provisioning available on every plan.

Authentication

Email + password with optional Google sign-in. Organization-scoped membership controls access to every customer record.

Multi-Factor Authentication (MFA)

Available

TOTP enrollment available for all users. Administrators can require MFA per organization via the Identity Center.

Single Sign-On (SAML 2.0 / OIDC)

Available

Enterprise SSO supports Okta, Microsoft Entra ID, Google Workspace, and OneLogin. Configurable per organization.

SCIM 2.0 Provisioning

Available

Just-in-time and lifecycle provisioning via standards-compliant SCIM endpoints. Compatible with Okta and Entra ID.

Role-Based Access Control

Roles are stored separately from user profiles and enforced by security-definer database functions and row-level security policies.

Data Protection

Customer data — including PHI in healthcare deployments — is encrypted, isolated, and audited end to end.

Encryption in Transit

All connections to the platform use TLS 1.2+. Internal traffic between the application and database is encrypted.

Encryption at Rest

Customer data, audit logs, and document storage are encrypted at rest by the managed backend provider.

Tenant Isolation

Row-level security policies enforce strict per-organization data isolation. Every customer-facing table is protected by RLS.

PHI Audit Logging

17 of 17 PHI modules instrumented

Every read, create, and update of Protected Health Information is recorded in an append-only audit log with user, timestamp, resource, and organization.

Identity Audit Logging

SSO sign-ins, SCIM provisioning events, MFA enrollment, and session policy changes are recorded in the identity audit log.

Operations & Resilience

Documented runbooks, regular dependency scans, third-party penetration testing, and an exercised disaster recovery plan.

Vulnerability Management

Dependency scans run on every release. High and critical findings are triaged within one business day. Most recent external penetration test: see Resources.

Incident Response

Documented incident response runbook with breach notification workflow aligned to 60-day HIPAA breach notification timelines.

Disaster Recovery

Database backups run continuously with point-in-time recovery. DR drill executed; restoration time objective and validation results documented in Resources.

Change Management

All schema and policy changes are reviewed before deployment. Migrations are versioned and audit-tracked.

Compliance

HIPAA technical safeguards in place; SOC 2 Type I readiness complete; FERPA-aligned controls for higher education; GDPR DPA on request.

HIPAA Technical Safeguards

Unique user IDs, audit logging, encryption at rest and in transit, automatic session timeout via session policies. BAAs available on request for qualifying customers.

SOC 2 Readiness

SOC 2 Type I readiness pack completed (control matrix, narratives, audit evidence mapping, risk register). Type II audit roadmap in progress.

FERPA (Universities)

Education-facing modules support FERPA-aligned access controls and audit logging. Customer-specific FERPA addenda available on request.

GDPR & Data Subject Rights

Customer-initiated data export and deletion supported. DPA available on request.

Resources

Documentation available on request via security@aiacademy.example. Customers under NDA can request copies during procurement.

  • SOC 2 Type I Readiness Pack— Available on request
  • HIPAA Technical Safeguards Mapping— Available on request
  • Penetration Test Report — Summary & Attestation— Available on request
  • Disaster Recovery Drill Report— Available on request
  • Data Processing Addendum (DPA)— Available on request
  • Business Associate Agreement (BAA) Template— Available on request
  • Subprocessor List— Available on request
  • Incident Response Runbook (Summary)— Available on request