Compliance & Assurance
Our compliance program provides a structured approach to managing information security risks and maintaining effective controls.
MyEvaluationPal has completed an independent SOC 2 Type II examination covering the applicable Trust Services Criteria identified in our report.
Note for publication: scope, period, and criteria terminology must match the final SOC 2 report exactly before this page goes live.
Security at MyEvaluationPal
Security is incorporated throughout our organization, technology, and operational processes.
Controlled access mechanisms designed to ensure access to systems and information is granted according to business requirements and authorized responsibilities.
- Multi-factor authentication
- Role-based access control
- Least-privilege principles
- User access reviews
- Account provisioning and deprovisioning
- Administrative access controls
Safeguards designed to protect information throughout its lifecycle.
- Encryption
- Secure transmission
- Access controls
- Data classification
- Backup and recovery
- Logging and monitoring
- Secure secrets management
Security is incorporated into the software development lifecycle.
- Secure development practices
- Dependency monitoring
- Vulnerability management
- Application security testing
- Code review practices
- Container security
- Security testing and remediation
Security events and relevant system activities are monitored to support detection and investigation of potential security issues.
Personnel receive security awareness training and are expected to follow MyEvaluationPal's security policies and procedures.
Product Security
MyEvaluationPal applies security controls throughout the application lifecycle.
Access to MyEvaluationPal systems is protected through authentication and access-control mechanisms appropriate to the system and user role.
Access is restricted according to authorized roles and business requirements.
Relevant security and system activities are logged and monitored to support operational security and investigation.
Development teams follow security practices designed to identify and remediate security weaknesses during the development lifecycle.
Security vulnerabilities are identified, evaluated, prioritized, tracked, and remediated according to their severity and risk.
Protecting Customer Information
We recognize that customer information — including student credentials and academic records — requires appropriate protection.
Information is protected using appropriate encryption mechanisms during transmission and, where applicable, while stored.
Access to sensitive systems and information is controlled and monitored according to established security requirements.
Information is retained according to applicable business, contractual, and organizational requirements.
Data is removed according to applicable retention and deletion requirements.
Access Control & Least Privilege
MyEvaluationPal follows access-control principles designed to limit access to systems and information to authorized personnel.
Secure Software Development
Security is incorporated into our software development and change management processes.
We continuously evaluate opportunities to strengthen our development security practices.
Secure Infrastructure
MyEvaluationPal uses cloud infrastructure and security controls designed to support secure and resilient operations.
Vulnerability Management
MyEvaluationPal maintains a vulnerability management process designed to identify, assess, prioritize, and remediate security vulnerabilities.
- Vulnerability identification
- Risk assessment
- Severity classification
- Assignment of remediation ownership
- Remediation tracking
- Verification
- Escalation of significant unresolved findings
Security testing is performed based on organizational risk and applicable security requirements. MyEvaluationPal's platform has been independently penetration tested.
Security Incident Response
MyEvaluationPal maintains an incident response process designed to detect, contain, investigate, eradicate, and recover from security incidents.
If you believe you've identified a security incident or vulnerability involving MyEvaluationPal, contact us with enough information for our security team to understand and investigate the issue.
Privacy & Data Protection
We are committed to responsible handling of personal and customer information, including the academic records processed through our platform.
Third-Party & Subprocessor Management
Third-party service providers may support the operation of MyEvaluationPal. We maintain processes designed to assess and manage third-party security risks.
Resilience & Availability
MyEvaluationPal maintains business continuity and disaster recovery processes designed to support the continued operation and recovery of critical services.
AI Security & Responsible AI
MyEvaluationPal recognizes that AI-enabled technologies introduce unique security, privacy, accuracy, and operational considerations. We take a risk-based approach to the use of AI technologies within our platform.
We evaluate AI-related security considerations including:
- Data protection
- Access control
- Model and service security
- Third-party AI provider risk
- Input and output handling
- Security monitoring
- Appropriate human oversight
Where third-party AI services are used, MyEvaluationPal evaluates providers based on applicable security, privacy, contractual, and operational requirements.
AI-assisted processing does not eliminate appropriate human review where accuracy, validation, or business requirements require additional oversight.
Security Governance & Risk Management
Our information security program is supported by organizational governance and oversight. MyEvaluationPal maintains processes for:
Security risks are reviewed and managed according to their potential impact on the organization and its customers.
Security Starts With Our People
Personnel receive security awareness training covering areas such as:
Security responsibilities are incorporated into our employee policies and onboarding processes.
Security Documentation
We provide security documentation to customers and qualified prospects where appropriate.
Trust Center Updates
MyEvaluationPal is pleased to announce the completion of its SOC 2 Type II examination. The report provides independent assurance regarding the operating effectiveness of applicable controls during the examination period.
Frequently Asked Questions
Is MyEvaluationPal SOC 2 compliant?
MyEvaluationPal has completed a SOC 2 Type II examination. Please refer to our SOC 2 report for the exact scope, Trust Services Criteria, examination period, and auditor information.
Can I obtain a copy of the SOC 2 report?
Yes. Customers and qualified prospects may request access to the report, subject to appropriate confidentiality requirements.
How do I report a security issue?
Contact security@myevaluationpal.com with enough detail for our security team to understand and investigate the issue.
Does MyEvaluationPal use third-party service providers?
Yes. MyEvaluationPal uses third-party providers where necessary to support its services. Applicable providers are subject to our vendor and third-party risk management processes.
How is customer information protected?
We use organizational, technical, and administrative safeguards designed to protect customer information from unauthorized access, disclosure, alteration, or loss.
Does MyEvaluationPal have business continuity and disaster recovery processes?
Yes. MyEvaluationPal maintains business continuity and disaster recovery processes designed to support the resilience and recovery of critical services.
Can I request additional security documentation?
Yes — use the document request above and our Security & Compliance team will follow up.
Questions about our security program?
Our Security & Compliance team is available to support customer and prospective-customer security reviews.

