← Back to homeSecurity

Built to be trusted when you scale

Start free with no commitment. When your security team gets involved, the answers are already here.

AWS ca-central-1

Data hosted in Canada

Core learning records and your user directory stay at rest in Canada on AWS ca-central-1 (Montreal). TLS 1.2+ in transit, KMS-encrypted storage at rest. Your residency story stays simple.

SOC 2

  • SOC 2 controls in place, operating from day one
  • Type II report in progress; available under NDA when ready
  • We do not claim to be “SOC 2 certified”: we are transparent about where we are

Privacy: Law 25 & GDPR ready

  • Designated Privacy Officer (privacy@embaylms.com)
  • Data export and deletion on request; published retention matrix
  • Sub-processor transparency and a Data Processing Agreement (DPA)
  • Breach notification within 72 hours to the CAI / OPC and affected individuals

Access & identity

  • SSO (SAML 2.0, OIDC, Google, Microsoft) from the Starter tier
  • SCIM provisioning at Enterprise
  • TOTP MFA on all plans
  • Break-glass admin access for SSO-only tenants
  • Role-based access control and account lockout

Tenant isolation

  • Schema-per-tenant isolation keeps every organization’s data separate
  • Append-only audit log, customer-exportable
  • Consent-based, logged platform support access

Platform & payments

  • Penetration test before launch, with all critical and high findings remediated
  • AWS GuardDuty threat detection and ClamAV scanning on uploads
  • Card data is entered only into Stripe-served payment UI — hosted pages or embedded Stripe iframes — and never touches EmbayLMS servers (PCI DSS SAQ A / A-EP, QSA determination pending)

Sub-processors

We work with a short list of vetted sub-processors: AWS, Supabase, Vercel, Railway, Zoom, Stripe, HubSpot and Google / Microsoft. The full, current list is published.

View our sub-processors