1. Security governance

Career Clutch maintains an information security program designed to protect confidentiality, integrity, and availability of data.

2. Technical safeguards

  • Encryption in transit (TLS) and at rest
  • Role-based access controls
  • Secure cloud infrastructure (AWS / equivalent)
  • Regular vulnerability monitoring

3. Administrative safeguards

  • Least-privilege access for staff
  • Security training for employees
  • Background-appropriate access reviews

4. Incident response

  • Documented incident response procedures
  • Prompt investigation of suspected incidents
  • School notification without undue delay following confirmation

5. Vendor management

Third-party service providers:

  • Are contractually bound by confidentiality
  • May only access data to support Services
  • Are reviewed for security posture

6. Data retention

  • Data retained only as long as necessary
  • Secure deletion upon request or contract end
  • Backups purged per retention schedules