Skip to content
JurisCred

Trust

Security & compliance

Universities buy through their security office. This page is written for them.

Data we hold

Education records under FERPA: enrollments, progress, assessment attempts and scores, completions, and issued credentials. Course content authored by institutions. Staff contact details. No payment data, no government identifiers, no health data.

Our role

JurisCred acts as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1)(i)(B): the institution owns and controls its data; we use it only to provide the service. No sale, no advertising, no profiling. Cross-institution Library publishers receive aggregate counts only.

Isolation

Every institution is a separate organization on its own subdomain. Every query is scoped to the organization at the data-access layer and tested for cross-tenant leaks. Cross-organization reads happen only through explicit Library adoption. Platform staff reach an institution's data only through an audited "act in organization" action.

Encryption

TLS 1.2+ with HSTS in transit. Hosted on AWS in the United States; encryption at rest uses AWS volume encryption. Passwords, sign-in codes, and API keys are hashed; identity-provider secrets and signing keys are encrypted at rest.

Authentication

Institutions sign in through their own identity provider: Microsoft Entra ID, SAML 2.0, or OpenID Connect. Multi-factor authentication stays with the institution. Administrator and Manager roles can be restricted to single sign-on. Alumni and independent learners use short-lived, rate-limited one-time codes.

Audit and monitoring

A tamper-evident, hash-chained activity log records sign-ins, role changes, exports, issuance, and revocations per organization, exportable by the institution and retained for a configurable window (90 days minimum). Institutions can subscribe to daily or weekly security digests and real-time alerts.

Credentials

Credentials are Open Badges 3.0 verifiable credentials signed with an Ed25519 key published at /.well-known/did.json, with a W3C Bitstring Status List for revocation and expiry. Public verification pages are the authoritative record.

Subprocessors

Amazon Web Services (hosting, United States), Mux (video), IONOS (email), Microsoft (authentication for Entra institutions). Customers are notified at least 30 days before a new subprocessor handles their data.

Assurance

Static analysis and dependency scanning on every change, weekly external web scans, and a completed HECVAT 4.1 available on request. A third-party penetration test and SOC 2 are planned; institutions may run their own coordinated testing. Accessibility target WCAG 2.1 AA, with captions required on every published video.

Reporting a vulnerability

Email security@juriscred.org. We acknowledge within two business days and notify affected institutions of confirmed incidents within 72 hours. See security.txt.