Skip to main content

Encoura Trust Center

At Encoura, we’re committed to high standards of security and data privacy. You trust us with your data, and we take that responsibility very seriously. Here’s everything we’re doing to use it appropriately and keep it safe.

Compliance

Our Commitment to Security

Encoura is committed to the highest standards of information security. We recognize the responsibility that comes with handling sensitive data on behalf of educational institutions, students, and families, and we maintain rigorous safeguards to ensure the confidentiality, integrity, and availability of that information across our entire organization.

Our security program is built on industry-recognized frameworks and validated through independent, third-party audits and government authorization programs. We continuously monitor, test, and improve our controls to stay ahead of an evolving threat landscape, and we embed security and privacy considerations into the design, development, and operation of every product we deliver.

Certifications & Compliance Reports

Encoura maintains the following certifications and attestations across our product portfolio. Each represents a rigorous, independent evaluation of our security and compliance practices.


ISO/IEC 27001

International Standard for Information Security Management

A globally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Scope: MyEncoura, Reach, Engage, Encompass, Raise

SOC 2

Service Organization Control Type II Report

An auditing framework developed by the AICPA that evaluates a service organization's controls based on the Trust Services Criteria, including security, availability, and confidentiality. A Type II report covers the operating effectiveness of those controls over a defined period.

Scope: MyEncoura, Reach

PCI DSS

Payment Card Industry Data Security Standard

A set of security standards established by the Payment Card Industry Security Standards Council, applicable to organizations that store, process, or transmit payment card data.

Scope: Encompass, RNL Engage, ScaleFunder

TX-RAMP

Texas Risk and Authorization Management Program

A state program administered by Texas that establishes a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing services used by state agencies and institutions of higher education.

Scope: Encompass — Level 2 Certified |MyEncoura — Level 2 Certified

GovRAMP

Government Risk and Authorization Management Program

A standardized authorization program that provides a reusable framework of security control baselines for cloud services used by state and local government and education entities.

Scope: Reach — GovRAMP Moderate Authorization |Student Success — GovRAMP Progressing (Snapshot)

How We Protect Your Data

Our layered approach to security includes:

•     Encryption of data in transit and at rest using industry-standard protocols.

•     Role-based access controls and the principle of least privilege across all systems.

•     Continuous security monitoring, logging, and threat detection.

•     Regular vulnerability assessments and independent penetration testing.

•     Formal incident response and business continuity plans, tested regularly.

•     Mandatory security and privacy awareness training for all employees.

•     Vendor risk management to ensure our partners meet our security standards.

Requesting Compliance Documentation

Current customers and prospective partners may request copies of our audit reports and attestations, including our SOC 2 Type II report, subject to a non-disclosure agreement. To request documentation or ask questions about our security and compliance program, please contact our compliance team.