Security Overview
Last updated 2026-10-02
CredScape is a market-intelligence data product for higher education. It is operated by CredScape Market Intelligence Inc., a corporation incorporated under the Canada Business Corporations Act and registered extraprovincially in British Columbia.
For security reviewers and procurement officers at post-secondary institutions, this page describes the platform's structure, data locations, and approach to access, encryption, recovery and incidents. Two founders run CredScape. The controls described here are all in place.
Identity and access
- Two-factor authentication. Two-factor authentication is enabled on every service account we use, including Cloudflare, Supabase, GitHub, Resend, Stripe, Zendesk, OVH, 1Password and Google Workspace.
- Company email. Google Workspace enforces 2-step verification for all users.
- Credential storage. We store all credentials in a shared 1Password Teams vault used only for CredScape and only by the two founders.
- Customer accounts. Time-based one-time password (TOTP) multi-factor authentication is available to all customer accounts.
- Passwords. Our authentication provider stores passwords only as bcrypt hashes. We require at least twelve characters, reject passwords that appear in known breach corpora, and require reauthentication to change a password.
- Sessions. Sessions expire after seven days of inactivity and after thirty days in total. Refresh tokens rotate on use.
Tenant isolation
- Row Level Security. Row Level Security is enabled on every table in our application schema. A user from one institution cannot read data belonging to another.
- Privileged credentials. We store service-role keys server-side and never expose them to browser code.
Encryption
- In transit. Traffic is encrypted with TLS. Cloudflare terminates connections at the edge using TLS 1.3.
- At rest. Databases and storage are encrypted at rest using our providers' managed encryption.
Data location
- Database and authentication. Supabase, in AWS
ca-central-1, Canada. - Search and session replay. Our own server at OVH in Beauharnois, Quebec, Canada.
- Application delivery. Cloudflare's global edge network.
- Supporting services. Email, analytics, error monitoring, billing and support involve processing outside Canada. The subprocessor list identifies each provider, the data it handles and its location.
Customer account records, the program corpus and vector indexes are stored in Canada. Data is stored in Canada, with some processing taking place elsewhere.
Backups and recovery
- Daily backups. Supabase backs up the production database daily and retains each backup for seven days.
- Off-platform backups. We keep weekly backups outside the hosting platform and retain them for ninety days.
- Restore tests. We test restores quarterly.
- Recovery objectives. Our recovery point objective and recovery time objective are each 24 hours.
Server hardening
- Search server. The OVH server accepts only key-based SSH authentication. Password login is disabled, the server has a single user account, and fail2ban is running.
- Network exposure. Only SSH listens publicly. Application traffic reaches the server through a Cloudflare Tunnel.
- Key custody. We store the SSH key in the shared 1Password vault.
- Email authentication. SPF, DKIM and DMARC (quarantine policy) are in place for our mail domains. DNSSEC is enabled, and CAA records restrict certificate issuance.
Monitoring and alerting
- Uptime and quality checks. A monitoring service runs every five minutes.
- Error monitoring. Sentry alert rules and scheduled-job check-ins cover application errors and background jobs.
- Alert routing. Alerts go to a shared mailbox that sends notifications to both founders' phones.
- Status page. Current status and incident history are available at credscape.instatus.com.
Incident response
- Procedure. We maintain a written incident response procedure covering detection, containment, risk assessment, notification and logging. Two people respond to incidents. We do not operate a 24/7 security operations centre.
- Incident register. We record every breach of security safeguards, whether or not it presents a real risk of significant harm. We retain each entry for five years.
- Notification. When a breach presents a real risk of significant harm, we notify affected individuals, affected customer organizations and the applicable regulator without delay.
Subprocessors and privacy
- Data processing agreements. We have signed data processing agreements with our subprocessors. Customers can request copies with one week's notice.
- Change notice. We give customers thirty days' notice before adding a new subprocessor.
- Privacy. Our privacy policy and privacy governance policy describe how we handle personal information. We answer access and correction requests within thirty days.
Assessments and accessibility
- HECVAT 4.1.6. Our self-assessment response is available on request.
- SecurityScorecard. CredScape holds an A rating with a perfect score of 100/100 (as of October 2, 2026). SecurityScorecard rates our public-facing security continuously; see the live badge in our trust centre.
- Accessibility. The licensed application conforms to WCAG 2.2 Level AA. See our accessibility statement.
- Certifications. CredScape does not hold SOC 2 or ISO 27001 certification and has not had an independent security audit or penetration test.
Report a vulnerability
We welcome security researchers who inspect our systems in good faith.
- Where to report. Email security@credscape.io with a description of the vulnerability and steps to reproduce it.
- Good faith. Please report findings promptly, avoid disrupting our services, and do not access, modify or destroy customer data.