Security

Audited every year. Monitored every day.

Donor records are among the most sensitive an institution holds, and this platform is built and run on that assumption. Security here is a standing practice: controls examined over a full year by an independent auditor, a third-party firm testing continuously, and every control we hold ourselves to monitored and published where anyone can open it.

01SOC 2 Type 2

A full year examined. Sixty controls tested. No exceptions noted.

SOC 2 Type 2 is the attestation an institutional security office asks for before anything else, and it carries that weight for one reason: the company does not grade itself. An independent accounting firm, working to standards set by the AICPA, spends a full year testing whether the controls a vendor claims are the controls actually running, then signs its own name to the finding. A reviewer holding one has the answer before the question is asked.

There are two kinds. A Type 1 asks whether the controls are designed properly on the day someone looks at them. A Type 2 asks whether they actually worked, day after day, across a period of months. Ours is a Type 2, examined over a full year, December 4, 2024 to December 4, 2025, by Johanson Group LLP.

The examination covers security, availability and confidentiality, and every criterion in those three categories applied to us. Johanson tested sixty controls and recorded no exceptions against any of them. The opinion is clean on all three counts: how the system is described, how the controls are designed, and whether they worked.

Four questions you can answer without us

A security review runs on questions whose answers already exist somewhere. These four come up in nearly every one, so they are kept where a reviewer can reach them directly.

  • 01PoliciesIncident response, disaster recovery, business continuity, network security, logging, vendor management, vulnerability management, personal data. Each one is there to read in full, so you never have to ask whether it exists.
  • 02Continuous control monitoringControls tested on a schedule, each one’s current pass or fail published as it is checked. It tells you what is true this week, not what was true last December.
  • 03SubprocessorsEvery third party involved in running the platform, with the data location it holds. It answers the fourth-party question before your vendor risk team raises it.
  • 04Attestation reportsThe SOC 3 carries the opinion and the system description. The SOC 2 Type 2 adds every test result on request, and a prospective client is a named permitted recipient.
02Documentation

The standards our clients answer to are the standards we meet.

Past the attestation, higher education, the states and your accessibility office each hold a vendor to a standard of their own, with an instrument of their own. We complete all three and keep them current, because your obligations become ours the moment donor records enter the system. An attestation and a certification are different things to a reviewer, and each line below uses the word that belongs to it.

  • TX-RAMP Level 2 The State of Texas program for cloud services used by public institutions. Certificate TX1426258, granted July 1, 2025 and valid through June 30, 2028. Certification
  • HECVAT 4.02 The higher education vendor assessment, completed March 14, 2025 and available on request. It sets the sector’s baseline, and for most institutions it is the first questionnaire that gets sent. On request
  • VPAT 2.5 The accessibility conformance report, assessed against WCAG 2.1 Level AA. The current report is dated September 15, 2026 and states that the platform substantially conforms. On request
03Monitoring

The auditor assesses us once a year. These run every day.

An audit looks backward. An examiner tests a year of evidence and issues an opinion months after the year has closed. The controls below run forward, on their own schedule, and they are what stands between a vulnerability disclosed this morning and your donor records this afternoon.

  • 01 Testing that never stops Redpoint Security’s Surveyor works against the platform continuously, an AI-driven instrument in place of a single engagement once a year. The executive summary of the current assessment goes to any reviewer who asks for it.
  • 02 Threat detection that runs itself AWS GuardDuty watches the accounts and workloads behind the platform for malicious activity without being asked, alongside network and host intrusion detection and prevention and next-generation persistent threat monitoring.
  • 03 Vulnerabilities found as they are disclosed Amazon Inspector scans the workloads continually for newly published software vulnerabilities. Separately, every release is scanned with an authenticated account before it ships and checked for the common web application classes: injection, cross-site scripting, request forgery.
  • 04 You can test us yourself Your own team may run its own vulnerability testing against the platform at a time we agree between us. We hand over the results of our own application and system scans on request as well.
  • 05 The perimeter, and the record of it AWS WAF and AWS Shield filter traffic before it reaches the platform. CloudTrail records user activity and API calls across the account, and Elastic keeps those logs searchable and alerting on them.
  • 06 Keys, patches and hardened images Cryptographic keys are created and controlled in AWS Key Management Service. Servers are built from the cloud provider’s own hardened images, and patching runs to a documented process.

Self-reported controls are just claims until somebody outside verifies them, which is what independent testing and the SOC 2 Type 2 examination are both for. The most recent third-party assessment identified thirteen issues. The five with practical exploitation value were remediated during testing or immediately after it, five were confirmed as expected behavior, and three low-severity items stayed on the list. No critical, high or medium-severity finding was left open, and residual risk was rated Low. We’d be happy to provide the executive summary upon request.

The audit says the same thing from the other direction. Johanson’s report records no significant incident in the services provided to clients across the twelve months before the examination period closed, and no significant change to those services either.

04Authentication

Single sign-on if you have it, and no wait if you do not.

When federated identity is treated as a precondition, an institution whose identity project is queued behind three others waits to launch. Ovrture supports both paths, and your launch date does not depend on which one you take.

  • 01 Federated sign-on Shibboleth SAML2, InCommon Federation and ADFS. Your identity provider stays the authority on who your people are.
  • 02 Or local accounts A documented alternative with self-service password reset, so an institution without federated identity in place is not held up.
  • 03 Eight roles System, application, report, brand, content and data administrators, general users, and the donor or prospect who opens a website. Each role sees only what it is given.
  • 04 Multi-factor on our side Required of our own people wherever it is technically possible, and on every remote path into production for staff, administrators and vendors alike.
  • 05 Lockout An account locks after no more than five failed attempts and stays locked for at least fifteen minutes.
  • 06 How a donor gets in A donor opens the website built for them with a passcode or magic link.
05Data handling

Your donor data gets the strictest handling we have.

Donor and prospect records are classified Restricted, which is the top of our four tiers and the level with the tightest rules attached. Here is what that means in practice, including the question a reviewer usually asks last and cares about most: who at the vendor can reach it.

  • 01 Classification Donor and prospect data is Restricted, the highest of our four tiers. The handling rules follow from the classification, so nobody is making a judgment call about your donors.
  • 02 Encryption AES-256 at rest and TLS 1.2 or higher in transit. Both are written into the agreement you sign, so they are commitments and not just policy.
  • 03 Your region We deploy in the AWS region you choose and replicate backups to a second region inside the same country.
  • 04 Staff access Our engineers work through a virtual desktop with two-factor authentication instead of a direct network path, which is how your data stays in the region you picked.
  • 05 Separation The platform is multi-tenant with extensively tested logic barriers between institutions. Physical isolation from other tenants is available at additional cost.
  • 06 Backups Daily, encrypted the same way as production, kept thirty days, versioned, and restored in a test at least once a year, on storage AWS designs for eleven nines of durability.
  • 07 Perimeter AWS web application firewall and AWS Shield in front of the platform. Logs stay inside the private network.
06Commitments

An audit says somebody checked. A contract says there is a consequence.

Every line below is a clause in the services agreement, with a remedy attached where one applies. You do not have to take any of it on our word, and you do not have to wait for procurement to find it.

  • Breach notice If donor data is ever breached, you hear from us without undue delay and no later than seventy-two hours after we confirm it, with what happened, roughly how many records, what it is likely to mean and what we are doing about it.
  • Uptime 99.5 percent guaranteed, with scheduled maintenance excluded. Any month we miss it, a month of service is credited back to you.
  • Measurement You can run your own monitoring, or a third party's. We certify your instrument in writing within a month, and from then on your measurements are the evidence.
  • Maintenance Never more than four hours in a week, only between 2 and 6 a.m. Eastern, and never with less than seventy-two hours notice.
  • Audit You can audit us once a year on reasonable notice, and we cover the cost if you find a material breach.
  • Instructions We process donor data only on your documented instructions, and we are obliged to tell you if an instruction looks unlawful.

Support response times, escalation paths and the rest of the service level sit in the agreement too. Those belong to the commercial conversation, and they are not what a security review is for.

07Artificial Intelligence

If our infrastructure passed your review, our AI did too.

Every security review has an AI section now, and the question underneath it is about location: where the model runs, and whether your content has to leave a boundary you have already approved in order to reach it.

The platform’s AI runs on Amazon Bedrock, inside our own AWS account, in the region your data already sits in. The content and context it works with stay in that account. AWS states that data sent to Bedrock is not shared with model providers, is not used to improve the base models, and is encrypted in transit and at rest. Nothing of yours trains anything.

We are building on Amazon Bedrock AgentCore for the agents that follow, and the first of those arrives in the platform shortly. There will be more, quickly. The boundary is the part that will not move: anything we add runs inside the environment your security office has already assessed, under the same access, logging and retention rules as the rest of the platform, with any third party named in our subprocessor list.

08Your part

Five things the audit puts on your side of the line.

Our SOC 2 report names five controls that belong to the institution. They are usually buried in an appendix where they read as fine print, so here they are on the page.

  • 01 The terms Comply with the terms of service. In practice this is the agreement you already signed, and nothing more.
  • 02 Your users Administer your own team's access, including approving it, removing it and reviewing the list periodically. You decide who sees which donors.
  • 03 Multi-factor Apply multi-factor authentication to your personnel where your own policy requires it. We enforce it on our side; this one is yours.
  • 04 Supervision Supervise how your personnel use the service, as you would with any system holding donor records.
  • 05 Your continuity plan Maintain your own disaster recovery and continuity planning covering a period when you cannot reach Ovrture.
Next

See it for yourself.

Book a demo and let’s think it through together. Come with whatever you are trying to solve, and we will start there.