Trust
Security
Last updated: 2026-06-29
This is a plain-language summary of the controls the Institute uses to protect participant data. If your organization needs a formal questionnaire response, and we can answer specifics.
How we protect participant data
All traffic is encrypted in transit (HTTPS), and data is encrypted at rest.
- Accounts are created only from the console against an approved program roster, by a developer. There is no public sign-up or self-registration.
- Access to participant data is restricted by role and enforced at the database layer.
- Sensitive administrative actions are recorded in an audit log.
- We rely on a small set of vetted infrastructure providers with data-processing terms covering use, retention, and breach notification.
- The only third-party script is Vercel’s cookieless analytics (aggregate traffic and page performance); no advertising, no cross-site tracking, and no analytics cookies.
- We monitor for errors and keep regular, encrypted backups.