Security & Compliance

Your data. Protected.

Arythmatic is built with enterprise-grade security from the ground up. Encryption, access controls, compliance frameworks, and infrastructure transparency — so you can focus on delivering great learning experiences.

Compliance Frameworks

We build to the standards your industry requires. Here is the current status of our compliance program.

GDPR

In Progress

Data processing agreements and right-to-erasure support are on our roadmap. Talk to us about your requirements before purchase.

SOC 2 Type II

In Progress

Currently undergoing SOC 2 Type II audit for Security, Availability, and Confidentiality trust service criteria. Expected completion Q3 2026.

HIPAA

Architecture Ready

Platform architecture supports HIPAA-compliant deployments for healthcare organizations. Business Associate Agreements (BAA) available upon request for enterprise plans.

FERPA

In Progress

Role-based access control, tenant isolation and audit logging support FERPA-aligned deployments. Parental consent workflows are not yet available. Talk to us about your requirements before purchase.

Security Features

Every layer of Arythmatic is designed to protect your organization's data and your learners' privacy.

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database encryption, backup encryption, and secure key management ensure your learner data is protected at every layer.

Role-Based Access Control (RBAC)

Granular permission system with predefined roles (Admin, Instructor, Manager, Learner) and custom role creation. Control who can access, edit, or manage courses, reports, and user data at the organization, department, or course level.

Single Sign-On (SSO)

SAML 2.0 and OAuth 2.0 integration for enterprise SSO. Connect Arythmatic to your identity provider (Okta, Azure AD, Google Workspace, OneLogin) for centralized authentication and user provisioning.

Audit Logging

Comprehensive audit trails for user actions, admin changes, content modifications, and access events. Logs are timestamped and available for export.

Data Residency

Data is currently stored in the US (Virginia). Additional regions are on our roadmap — talk to us if you have a residency requirement.

Automated Backups & Disaster Recovery

Continuous database replication with point-in-time recovery. Daily encrypted backups retained for 30 days. Recovery Time Objective (RTO) under 4 hours and Recovery Point Objective (RPO) under 1 hour.

Infrastructure & Operations

Cloud Infrastructure

AWS (Amazon Web Services) with multi-AZ deployment for high availability

Uptime SLA

Uptime targeted at 99%, monitored 24/7

DDoS Protection

Network and application-layer DDoS mitigation via AWS Shield

Vulnerability Management

Regular penetration testing, dependency scanning, and security patches within 48 hours of disclosure

Incident Response

Documented incident response plan with severity-based escalation. Security incidents communicated within 72 hours per GDPR requirements

Secure Development

OWASP Top 10 addressed in development lifecycle. Code reviews, automated security testing in CI/CD, and dependency auditing

Responsible Disclosure

Found a security vulnerability? We appreciate responsible disclosure. Please email security@arythmatic.cloud with details and we will respond within 48 hours. Do not publicly disclose vulnerabilities until we have confirmed a fix is deployed.

Ready to launch a secure academy?

Start your 14-day free trial today. No credit card required. Full access to everything.

Start Free Trial