← Back to homeSecurity
Built to be trusted when you scale
Start free with no commitment. When your security team gets involved, the answers are already here.
AWS ca-central-1
Data hosted in Canada
Core learning records and your user directory stay at rest in Canada on AWS ca-central-1 (Montreal). TLS 1.2+ in transit, KMS-encrypted storage at rest. Your residency story stays simple.
SOC 2
- SOC 2 controls in place, operating from day one
- Type II report in progress; available under NDA when ready
- We do not claim to be “SOC 2 certified”: we are transparent about where we are
Privacy: Law 25 & GDPR ready
- Designated Privacy Officer (privacy@embaylms.com)
- Data export and deletion on request; published retention matrix
- Sub-processor transparency and a Data Processing Agreement (DPA)
- Breach notification within 72 hours to the CAI / OPC and affected individuals
Access & identity
- SSO (SAML 2.0, OIDC, Google, Microsoft) from the Starter tier
- SCIM provisioning at Enterprise
- TOTP MFA on all plans
- Break-glass admin access for SSO-only tenants
- Role-based access control and account lockout
Tenant isolation
- Schema-per-tenant isolation keeps every organization’s data separate
- Append-only audit log, customer-exportable
- Consent-based, logged platform support access
Platform & payments
- Penetration test before launch, with all critical and high findings remediated
- AWS GuardDuty threat detection and ClamAV scanning on uploads
- Card data is entered only into Stripe-served payment UI — hosted pages or embedded Stripe iframes — and never touches EmbayLMS servers (PCI DSS SAQ A / A-EP, QSA determination pending)
Sub-processors
We work with a short list of vetted sub-processors: AWS, Supabase, Vercel, Railway, Zoom, Stripe, HubSpot and Google / Microsoft. The full, current list is published.
View our sub-processors →