MyEvaluationPal Trust Center

Security. Privacy.
Reliability. Trust.

MyEvaluationPal is committed to protecting the information entrusted to us. Our security program combines organizational governance, technical safeguards, operational controls, and continuous improvement.

We maintain a security and compliance program designed to protect the confidentiality, integrity, and availability of information entrusted to us.

AICPA SOC 2 badge
SOC 2® Type II
Independent examination completed

MyEvaluationPal has successfully completed a SOC 2 Type II examination, providing independent assurance regarding the design and operating effectiveness of applicable controls during the examination period.

Report typeSOC 2 Type II
Service organizationMyEvaluationPal / Byte Brain AI LLC
Examination period[from final report]

SOC 2 is a registered trademark of the American Institute of CPAs (AICPA).

SOC 2 Type II
Independent examination
Security
Defense-in-depth security controls
Access Control
Least privilege & controlled access
Incident Response
Defined detection, response & recovery
Business Continuity
Backup & disaster recovery controls
Security review

Start your security review

Whether you're evaluating MyEvaluationPal for your organization or conducting an annual vendor assessment, we're here to provide the information you need.

Our Security & Compliance team responds to documentation requests, security questionnaires, and program questions at security@myevaluationpal.com.

01
Review what's published here

Our compliance status, security controls, privacy practices, and resilience program are documented on this page.

02
Request the documents you need

Our SOC 2 Type II report and penetration testing summary are available to customers and qualified prospects on request.

03
Complete confidentiality requirements

Access to confidential documentation may require an executed NDA.

04
Send us your questionnaire

If your review requires a completed security questionnaire, email it to our Security & Compliance team.

Compliance

Compliance & Assurance

Our compliance program provides a structured approach to managing information security risks and maintaining effective controls.

SOC 2 Type II
Completed

MyEvaluationPal has completed an independent SOC 2 Type II examination covering the applicable Trust Services Criteria identified in our report.

Report typeSOC 2 Type II
Examination period[insert exact period]
Service organizationMyEvaluationPal / Byte Brain AI LLC
Trust Services Criteria[insert criteria]

Note for publication: scope, period, and criteria terminology must match the final SOC 2 report exactly before this page goes live.

Security

Security at MyEvaluationPal

Security is incorporated throughout our organization, technology, and operational processes.

Identity & Access Management

Controlled access mechanisms designed to ensure access to systems and information is granted according to business requirements and authorized responsibilities.

  • Multi-factor authentication
  • Role-based access control
  • Least-privilege principles
  • User access reviews
  • Account provisioning and deprovisioning
  • Administrative access controls
Data Security

Safeguards designed to protect information throughout its lifecycle.

  • Encryption
  • Secure transmission
  • Access controls
  • Data classification
  • Backup and recovery
  • Logging and monitoring
  • Secure secrets management
Application Security

Security is incorporated into the software development lifecycle.

  • Secure development practices
  • Dependency monitoring
  • Vulnerability management
  • Application security testing
  • Code review practices
  • Container security
  • Security testing and remediation
Security Monitoring

Security events and relevant system activities are monitored to support detection and investigation of potential security issues.

Employee Security

Personnel receive security awareness training and are expected to follow MyEvaluationPal's security policies and procedures.

Product

Product Security

MyEvaluationPal applies security controls throughout the application lifecycle.

Authentication

Access to MyEvaluationPal systems is protected through authentication and access-control mechanisms appropriate to the system and user role.

Authorization

Access is restricted according to authorized roles and business requirements.

Audit & Logging

Relevant security and system activities are logged and monitored to support operational security and investigation.

Secure Development

Development teams follow security practices designed to identify and remediate security weaknesses during the development lifecycle.

Vulnerability Management

Security vulnerabilities are identified, evaluated, prioritized, tracked, and remediated according to their severity and risk.

Data

Protecting Customer Information

We recognize that customer information — including student credentials and academic records — requires appropriate protection.

Encryption

Information is protected using appropriate encryption mechanisms during transmission and, where applicable, while stored.

Access Monitoring

Access to sensitive systems and information is controlled and monitored according to established security requirements.

Data Retention

Information is retained according to applicable business, contractual, and organizational requirements.

Secure Deletion

Data is removed according to applicable retention and deletion requirements.

Access

Access Control & Least Privilege

MyEvaluationPal follows access-control principles designed to limit access to systems and information to authorized personnel.

Role-based accessLeast privilegeMulti-factor authenticationPeriodic access reviewsAccess approvalJoiner / mover / leaver processesPrivileged access restrictions
Development

Secure Software Development

Security is incorporated into our software development and change management processes.

Secure coding standards
Source-code access controls
Dependency monitoring
Vulnerability scanning
Application security testing
Change management
Code review
Production deployment controls

We continuously evaluate opportunities to strengthen our development security practices.

Infrastructure

Secure Infrastructure

MyEvaluationPal uses cloud infrastructure and security controls designed to support secure and resilient operations.

Identity and access management
Network security controls
Cloud configuration management
Security logging
Backup and recovery
Vulnerability management
Infrastructure monitoring
Access restrictions
Provider-specific architecture details are shared through controlled security documentation.
Vulnerabilities

Vulnerability Management

MyEvaluationPal maintains a vulnerability management process designed to identify, assess, prioritize, and remediate security vulnerabilities.

  1. Vulnerability identification
  2. Risk assessment
  3. Severity classification
  4. Assignment of remediation ownership
  5. Remediation tracking
  6. Verification
  7. Escalation of significant unresolved findings
Security Testing

Security testing is performed based on organizational risk and applicable security requirements. MyEvaluationPal's platform has been independently penetration tested.

Incidents

Security Incident Response

MyEvaluationPal maintains an incident response process designed to detect, contain, investigate, eradicate, and recover from security incidents.

DetectAnalyzeContainEradicateRecoverReview
Report a security incident

If you believe you've identified a security incident or vulnerability involving MyEvaluationPal, contact us with enough information for our security team to understand and investigate the issue.

security@myevaluationpal.com
Privacy

Privacy & Data Protection

We are committed to responsible handling of personal and customer information, including the academic records processed through our platform.

Data collection
Data use
Data access
Data protection
Data retention
Data deletion
Third-party processing
Subprocessors
Customer privacy responsibilities
Read Privacy Policy
Third parties

Third-Party & Subprocessor Management

Third-party service providers may support the operation of MyEvaluationPal. We maintain processes designed to assess and manage third-party security risks.

Depending on the provider's risk and services, our assessment may consider:
Security certificationsSOC reportsData protection practicesPrivacy requirementsSecurity controlsData accessContractual obligationsOngoing monitoring
Resilience

Resilience & Availability

MyEvaluationPal maintains business continuity and disaster recovery processes designed to support the continued operation and recovery of critical services.

Business continuity planning
Disaster recovery planning
Backup procedures
Data recovery
Recovery testing
Defined recovery responsibilities
Incident escalation
Executive oversight
AI

AI Security & Responsible AI

MyEvaluationPal recognizes that AI-enabled technologies introduce unique security, privacy, accuracy, and operational considerations. We take a risk-based approach to the use of AI technologies within our platform.

AI Security

We evaluate AI-related security considerations including:

  • Data protection
  • Access control
  • Model and service security
  • Third-party AI provider risk
  • Input and output handling
  • Security monitoring
  • Appropriate human oversight
Third-Party AI Services

Where third-party AI services are used, MyEvaluationPal evaluates providers based on applicable security, privacy, contractual, and operational requirements.

Human Oversight

AI-assisted processing does not eliminate appropriate human review where accuracy, validation, or business requirements require additional oversight.

Governance

Security Governance & Risk Management

Our information security program is supported by organizational governance and oversight. MyEvaluationPal maintains processes for:

Information security governance
Risk assessment
Risk treatment
Policy management
Security reporting
Security awareness
Third-party risk management
Compliance monitoring
Management oversight

Security risks are reviewed and managed according to their potential impact on the organization and its customers.

People

Security Starts With Our People

Personnel receive security awareness training covering areas such as:

Phishing and social engineeringPassword and authentication securityData protectionIncident reportingAcceptable usePrivacyRemote work securitySecure handling of information

Security responsibilities are incorporated into our employee policies and onboarding processes.

Documents

Security Documentation

We provide security documentation to customers and qualified prospects where appropriate.

Document
Access
SOC 2 Type II Report
Penetration Testing Summary
Privacy Policy
Security Contact Information
Updates

Trust Center Updates

[Publish date]
SOC 2 Type II Report Available

MyEvaluationPal is pleased to announce the completion of its SOC 2 Type II examination. The report provides independent assurance regarding the operating effectiveness of applicable controls during the examination period.

FAQ

Frequently Asked Questions

Is MyEvaluationPal SOC 2 compliant?+

MyEvaluationPal has completed a SOC 2 Type II examination. Please refer to our SOC 2 report for the exact scope, Trust Services Criteria, examination period, and auditor information.

Can I obtain a copy of the SOC 2 report?+

Yes. Customers and qualified prospects may request access to the report, subject to appropriate confidentiality requirements.

How do I report a security issue?+

Contact security@myevaluationpal.com with enough detail for our security team to understand and investigate the issue.

Does MyEvaluationPal use third-party service providers?+

Yes. MyEvaluationPal uses third-party providers where necessary to support its services. Applicable providers are subject to our vendor and third-party risk management processes.

How is customer information protected?+

We use organizational, technical, and administrative safeguards designed to protect customer information from unauthorized access, disclosure, alteration, or loss.

Does MyEvaluationPal have business continuity and disaster recovery processes?+

Yes. MyEvaluationPal maintains business continuity and disaster recovery processes designed to support the resilience and recovery of critical services.

Can I request additional security documentation?+

Yes — use the document request above and our Security & Compliance team will follow up.

Contact

Questions about our security program?

Our Security & Compliance team is available to support customer and prospective-customer security reviews.

Security documentation
Report a security concern
Report Security Issue