Data Security & Compliance

We are a small vendor, so we will be specific rather than vague. Below is exactly what we do, what we do not do, and what we have not yet done — so your business office can evaluate us honestly.

Security Features

Encrypted in Transit and at Rest

All traffic to the assistant uses HTTPS/TLS. Stored conversation and inquiry data is encrypted at rest by our managed database provider.

Admissions Scope Only

The assistant answers prospective-family inquiries. It is not connected to your SIS and never accesses enrolled-student education records.

Managed US Cloud Hosting

Runs on managed US cloud infrastructure. We do not currently offer a contractual uptime SLA — ask us and we will tell you our actual measured uptime.

Least-Privilege Access

Production data is accessible only to ElevateChat's operator. Administrative endpoints require an authentication token.

Automated Monitoring

A synthetic check runs continuously against the assistant and its inquiry-capture path, and alerts us the moment either stops working.

No SOC 2 Audit Yet

We have not completed a SOC 2 audit and will not claim one. We are happy to complete your vendor security questionnaire and sign your data protection addendum.

Compliance Standards

FERPA

How FERPA Applies

FERPA governs the education records of enrolled students. ElevateChat is deliberately scoped so it does not touch them.

  • We process prospective-family inquiries, not education records
  • No connection to your student information system
  • If you ever ask us to handle enrolled-student data, we will sign a school official agreement first
  • Inquiry data is yours; we return or delete it on request
COPPA

How COPPA Applies

The assistant is intended for parents, guardians and other adults evaluating your school.

  • Written and configured for an adult audience
  • We do not knowingly collect personal information from children under 13
  • Any such information found is deleted on discovery
  • The assistant identifies itself as an AI at the start of every conversation
Rights

Data Rights and Deletion

Whichever privacy law applies to your families, the practical commitments are the same.

  • Access, correction and deletion requests honored within 30 days
  • The school owns its inquiry data and can export it at any time
  • Conversation logs deleted on a retention window you choose
  • We will notify you promptly if we ever become aware of a breach

Comprehensive Security Statement

Data Protection Standards

ElevateChat handles a narrow, deliberately limited slice of your data — the inquiries prospective families send you:

  • We collect what a family volunteers in conversation: name, contact details, the student's grade of interest, and what they asked about
  • We do not collect Social Security numbers, financial-aid data, health records or academic records, and the assistant is instructed to decline them
  • Captured inquiries are delivered to an inbox your school nominates
  • The school owns this data, can export it at any time, and can have it deleted on request

Data Encryption and Storage

We employ multiple layers of encryption to protect your data:

  • In Transit: All traffic to the website and the assistant is served over HTTPS/TLS
  • At Rest: Conversation and inquiry data is encrypted at rest by our managed database provider
  • Secrets: API keys and database credentials are stored as host-managed environment secrets, never in source control
  • Not yet in place: application-level field encryption and customer-managed keys. We will say so rather than imply otherwise.

Access Controls and Authentication

We implement strict access controls to ensure only authorized personnel can access your data:

  • ElevateChat is operated by a single named individual; production access is limited to that operator
  • The operator's hosting, database and email accounts are protected by multi-factor authentication
  • Administrative and inquiry-export endpoints require a bearer token
  • Your staff do not need an ElevateChat account — captured inquiries are delivered to an inbox you nominate

Infrastructure Security

Our infrastructure is built on enterprise-grade cloud services with comprehensive security measures:

  • Hosted on managed US cloud platforms, which provide DDoS protection and physical data-center security
  • An automated synthetic check exercises the assistant and its inquiry-capture path continuously and alerts on failure
  • Dependencies are patched on a regular cadence
  • Not yet in place: third-party penetration testing and a formal 24/7 on-call rotation. ElevateChat has not been independently pen-tested, and we will not claim it has been.

Data Retention and Deletion

We maintain clear data retention policies that respect your privacy and comply with legal requirements:

  • Data is retained only as long as necessary for service provision
  • Automatic deletion of conversation logs after 12 months (configurable)
  • Secure data destruction using industry-standard methods
  • Right to deletion honored within 30 days of request
  • Legal hold procedures for litigation or regulatory requirements

Incident Response and Breach Notification

We do not operate a staffed security operations center, and we will not pretend to. What we commit to is this:

  • Automated alerting notifies the operator when the service or its inquiry-capture path fails
  • We will notify any affected school within 72 hours of becoming aware of a breach involving their data
  • We will tell you what happened, what data was involved, and what we changed
  • We will cooperate with your own notification obligations and with law enforcement where appropriate

Who Operates ElevateChat

ElevateChat is built and operated by one person. That is a real fact about your risk profile, so we state it plainly rather than writing as though we were a large company:

  • There are no other employees and no contractors with access to your data
  • Exactly one person can reach production systems, and that access is protected by multi-factor authentication
  • We will sign a confidentiality agreement and your data protection addendum
  • The trade-off is honest: you get a responsive vendor who answers the phone, and you do not get the redundancy of a larger organization. Weigh both.

Subprocessors

These are the third parties that can process your inquiry data. We will keep this list current and give you notice before adding to it:

  • Vercel — website hosting
  • Render — assistant backend and database hosting (US region)
  • OpenAI — generates the assistant's replies. Conversation content is sent to OpenAI's API. Under their API terms, this data is not used to train their models.
  • Microsoft 365 — email delivery of captured inquiries
  • We do not sell personal data and we do not share it with advertisers

Contact Our Security Team

Security and privacy questions go to the person who built the system. Send your vendor security questionnaire and we will complete it:

Security & Privacy: security@elevatechatsolutions.com

Phone: +1 (919) 592-3422

We aim to respond within one business day.