Trust Center
Security at TEAMTrain
TEAMTrain holds training records, attestations and phishing results for organizations that are themselves being audited. Here is how that data is protected, stated plainly. Last updated September 8, 2026.
Hosting and data location
- All customer data is stored in AWS us-east-2 (Ohio). Audio narration is generated in us-east-1 and stored in Ohio.
- Each customer organization is a separate tenant. Every database read and write is scoped to the organization key of the signed-in user, enforced in the data layer rather than in individual screens.
- Point-in-time recovery is enabled on the primary database, with continuous backups covering the previous 35 days. Deletion protection is enabled.
Encryption
- Data in transit is protected with TLS 1.2 or higher on every endpoint, including the mobile apps.
- Data at rest is encrypted with AES-256 in the database and in object storage.
- Training media and certificates live in private buckets. Links are short-lived signed URLs, never public objects.
Identity and access
- Authentication is handled by Amazon Cognito. Passwords are never stored by TEAMTrain and must be at least 12 characters with mixed case, numbers and symbols.
- Single sign-on with Microsoft Entra ID (Azure AD) is available to every plan. SAML and Google Workspace sign-in are in development.
- Sessions are signed tokens verified on every request. Mobile sessions use short-lived tokens with silent refresh and optional biometric lock.
- Role-based access separates trainees, organization administrators and platform administrators. Administrator actions are written to an audit log.
Monitoring and operations
- Application logs are structured, exclude personal data, and are retained in CloudWatch.
- Audit events cover invitations, role changes, assignments, attestations, certificates, phishing campaigns and settings changes.
- Secrets are held in the hosting platform's encrypted configuration, never in source code or client bundles.
Compliance evidence for customers
- Completion records, signed attestations and certificates are timestamped, tamper-evident and exportable for auditors.
- Certificates carry a public verification URL so third parties can confirm authenticity without an account.
- Phishing simulation results and remediation assignments are retained as evidence for insurers and framework audits.
Simulated phishing safeguards
- Simulations are only sent to an organization's own enrolled users, on that organization's instruction.
- Simulated sign-in pages never store what is typed. The request body is discarded and only the fact of a submission is recorded.
- Every simulation email carries an identifying header so mail administrators can recognize it.
Subprocessors
Third parties that process customer data on our behalf. We notify customers before adding one.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, email delivery, text-to-speech | US East (Ohio and N. Virginia) |
| Stripe | Subscription billing and payment processing | United States |
| Anthropic | Program authoring, lesson tutor and compliance report generation | United States |
| Expo (EAS) | Mobile app build and delivery pipeline | United States |
Roadmap, stated honestly
- Independent penetration test. Being scheduled with a third-party firm covering the web app, API and mobile apps. The summary letter will be published here.
- SOC 2 Type I. Controls are being documented against the Trust Services Criteria; an audit window will be announced once the penetration test is complete.
- Multi-factor authentication for local accounts. Customers using Entra ID inherit their identity provider's MFA today. App-native MFA for password accounts is in development.
Vulnerability disclosure
If you believe you have found a security issue, email security@teamtrain.ai. We acknowledge reports within two business days, keep you informed, and do not pursue action against good-faith research that avoids privacy violations, data destruction and service disruption.
Machine-readable contact: /.well-known/security.txt
Questions about a security questionnaire, a data processing agreement or a customer-specific control? Email security@teamtrain.ai.