Skip to main content
CompetencyLabsCompetencyLabs

Trust Center

Security

A summary of the controls we operate to protect Competency Labs accounts, assessment data, and the credential system.

Infrastructure

  • HostingManaged cloud infrastructure with regional isolation and vendor-managed patching.
  • Encryption in transitTLS 1.2+ enforced across all public endpoints and internal service calls.
  • Encryption at restDatabase and object storage encrypted at rest using provider-managed keys.
  • BackupsPoint-in-time recovery on primary databases with periodic backup verification.

Access control

  • Row-level securityEvery user-scoped table enforces row-level security so only the account owner and authorized reviewers can read records.
  • Role separationReviewer, admin, and support roles are stored in a dedicated authorization table separate from user profiles to prevent privilege escalation.
  • Audit logsAdministrative actions, role changes, and reviewer decisions are captured to an internal audit log.
  • Least privilegeEmployee access to production data is scoped, approved, and logged; production keys are rotated on defined intervals.

Secure development

Code changes go through review and automated checks. Dependencies are monitored for known vulnerabilities. Security-relevant changes to authentication, authorization, or credential issuance require additional review.

Reporting a vulnerability

If you believe you have found a vulnerability, please email security@competencylabs.com. We ask that you avoid privacy violations, data destruction, and interruption of service while investigating.

Competency Labs does not currently hold SOC 2 or ISO 27001 attestation. When any formal attestation is completed, we will publish the report scope and date here.

Maintained by Competency Labs. Contact support@competencylabs.com for corrections or questions.

Contact us