Our Commitment to Security
Encoura is committed to the highest standards of information security. We recognize the responsibility that comes with handling sensitive data on behalf of educational institutions, students, and families, and we maintain rigorous safeguards to ensure the confidentiality, integrity, and availability of that information across our entire organization.
Our security program is built on industry-recognized frameworks and validated through independent, third-party audits and government authorization programs. We continuously monitor, test, and improve our controls to stay ahead of an evolving threat landscape, and we embed security and privacy considerations into the design, development, and operation of every product we deliver.
Certifications & Compliance Reports
Encoura maintains the following certifications and attestations across our product portfolio. Each represents a rigorous, independent evaluation of our security and compliance practices.
ISO/IEC 27001
International Standard for Information Security Management
A globally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Scope: MyEncoura, Reach, Engage, Encompass, Raise
SOC 2
Service Organization Control Type II Report
An auditing framework developed by the AICPA that evaluates a service organization's controls based on the Trust Services Criteria, including security, availability, and confidentiality. A Type II report covers the operating effectiveness of those controls over a defined period.
Scope: MyEncoura, Reach
PCI DSS
Payment Card Industry Data Security Standard
A set of security standards established by the Payment Card Industry Security Standards Council, applicable to organizations that store, process, or transmit payment card data.
Scope: Encompass, RNL Engage, ScaleFunder
TX-RAMP
Texas Risk and Authorization Management Program
A state program administered by Texas that establishes a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing services used by state agencies and institutions of higher education.
Scope: Encompass — Level 2 Certified |MyEncoura — Level 2 Certified
GovRAMP
Government Risk and Authorization Management Program
A standardized authorization program that provides a reusable framework of security control baselines for cloud services used by state and local government and education entities.
Scope: Reach — GovRAMP Moderate Authorization |Student Success — GovRAMP Progressing (Snapshot)
How We Protect Your Data
Our layered approach to security includes:
• Encryption of data in transit and at rest using industry-standard protocols.
• Role-based access controls and the principle of least privilege across all systems.
• Continuous security monitoring, logging, and threat detection.
• Regular vulnerability assessments and independent penetration testing.
• Formal incident response and business continuity plans, tested regularly.
• Mandatory security and privacy awareness training for all employees.
• Vendor risk management to ensure our partners meet our security standards.
Requesting Compliance Documentation
Current customers and prospective partners may request copies of our audit reports and attestations, including our SOC 2 Type II report, subject to a non-disclosure agreement. To request documentation or ask questions about our security and compliance program, please contact our compliance team.