Data Security & Compliance
We are a small vendor, so we will be specific rather than vague. Below is exactly what we do, what we do not do, and what we have not yet done — so your business office can evaluate us honestly.
Security Features
Encrypted in Transit and at Rest
All traffic to the assistant uses HTTPS/TLS. Stored conversation and inquiry data is encrypted at rest by our managed database provider.
Admissions Scope Only
The assistant answers prospective-family inquiries. It is not connected to your SIS and never accesses enrolled-student education records.
Managed US Cloud Hosting
Runs on managed US cloud infrastructure. We do not currently offer a contractual uptime SLA — ask us and we will tell you our actual measured uptime.
Least-Privilege Access
Production data is accessible only to ElevateChat's operator. Administrative endpoints require an authentication token.
Automated Monitoring
A synthetic check runs continuously against the assistant and its inquiry-capture path, and alerts us the moment either stops working.
No SOC 2 Audit Yet
We have not completed a SOC 2 audit and will not claim one. We are happy to complete your vendor security questionnaire and sign your data protection addendum.
Compliance Standards
How FERPA Applies
FERPA governs the education records of enrolled students. ElevateChat is deliberately scoped so it does not touch them.
- We process prospective-family inquiries, not education records
- No connection to your student information system
- If you ever ask us to handle enrolled-student data, we will sign a school official agreement first
- Inquiry data is yours; we return or delete it on request
How COPPA Applies
The assistant is intended for parents, guardians and other adults evaluating your school.
- Written and configured for an adult audience
- We do not knowingly collect personal information from children under 13
- Any such information found is deleted on discovery
- The assistant identifies itself as an AI at the start of every conversation
Data Rights and Deletion
Whichever privacy law applies to your families, the practical commitments are the same.
- Access, correction and deletion requests honored within 30 days
- The school owns its inquiry data and can export it at any time
- Conversation logs deleted on a retention window you choose
- We will notify you promptly if we ever become aware of a breach
Comprehensive Security Statement
Data Protection Standards
ElevateChat handles a narrow, deliberately limited slice of your data — the inquiries prospective families send you:
- We collect what a family volunteers in conversation: name, contact details, the student's grade of interest, and what they asked about
- We do not collect Social Security numbers, financial-aid data, health records or academic records, and the assistant is instructed to decline them
- Captured inquiries are delivered to an inbox your school nominates
- The school owns this data, can export it at any time, and can have it deleted on request
Data Encryption and Storage
We employ multiple layers of encryption to protect your data:
- In Transit: All traffic to the website and the assistant is served over HTTPS/TLS
- At Rest: Conversation and inquiry data is encrypted at rest by our managed database provider
- Secrets: API keys and database credentials are stored as host-managed environment secrets, never in source control
- Not yet in place: application-level field encryption and customer-managed keys. We will say so rather than imply otherwise.
Access Controls and Authentication
We implement strict access controls to ensure only authorized personnel can access your data:
- ElevateChat is operated by a single named individual; production access is limited to that operator
- The operator's hosting, database and email accounts are protected by multi-factor authentication
- Administrative and inquiry-export endpoints require a bearer token
- Your staff do not need an ElevateChat account — captured inquiries are delivered to an inbox you nominate
Infrastructure Security
Our infrastructure is built on enterprise-grade cloud services with comprehensive security measures:
- Hosted on managed US cloud platforms, which provide DDoS protection and physical data-center security
- An automated synthetic check exercises the assistant and its inquiry-capture path continuously and alerts on failure
- Dependencies are patched on a regular cadence
- Not yet in place: third-party penetration testing and a formal 24/7 on-call rotation. ElevateChat has not been independently pen-tested, and we will not claim it has been.
Data Retention and Deletion
We maintain clear data retention policies that respect your privacy and comply with legal requirements:
- Data is retained only as long as necessary for service provision
- Automatic deletion of conversation logs after 12 months (configurable)
- Secure data destruction using industry-standard methods
- Right to deletion honored within 30 days of request
- Legal hold procedures for litigation or regulatory requirements
Incident Response and Breach Notification
We do not operate a staffed security operations center, and we will not pretend to. What we commit to is this:
- Automated alerting notifies the operator when the service or its inquiry-capture path fails
- We will notify any affected school within 72 hours of becoming aware of a breach involving their data
- We will tell you what happened, what data was involved, and what we changed
- We will cooperate with your own notification obligations and with law enforcement where appropriate
Who Operates ElevateChat
ElevateChat is built and operated by one person. That is a real fact about your risk profile, so we state it plainly rather than writing as though we were a large company:
- There are no other employees and no contractors with access to your data
- Exactly one person can reach production systems, and that access is protected by multi-factor authentication
- We will sign a confidentiality agreement and your data protection addendum
- The trade-off is honest: you get a responsive vendor who answers the phone, and you do not get the redundancy of a larger organization. Weigh both.
Subprocessors
These are the third parties that can process your inquiry data. We will keep this list current and give you notice before adding to it:
- Vercel — website hosting
- Render — assistant backend and database hosting (US region)
- OpenAI — generates the assistant's replies. Conversation content is sent to OpenAI's API. Under their API terms, this data is not used to train their models.
- Microsoft 365 — email delivery of captured inquiries
- We do not sell personal data and we do not share it with advertisers
Contact Our Security Team
Security and privacy questions go to the person who built the system. Send your vendor security questionnaire and we will complete it:
Security & Privacy: security@elevatechatsolutions.com
Phone: +1 (919) 592-3422
We aim to respond within one business day.