How we handle your participants' data
This page is maintained by Workforce Ascend to answer the security, privacy, and procurement questions our partners ask. It describes what the platform does today — it is not an independent audit or certification.
Current compliance status — stated plainly
- SOC 2: not audited. No report is available.
- FERPA: we will sign school official / data-sharing terms, but we have no third-party FERPA attestation.
- HIPAA: not applicable. Do not place protected health information in the platform.
- WCAG: built to accessible patterns, no formal third-party audit completed.
If a certification is a hard requirement for your procurement, tell us during scoping rather than after contracting.
Access & authentication
- Sign-in is email and password or Google, handled by our authentication provider — we never store passwords ourselves.
- Every record is scoped to an organization. Program staff only see participants in their own workspace.
- Roles separate what an administrator and a participant can view or change.
- Single sign-on (SAML / OAuth) is available on enterprise engagements.
Data we hold
- Participant name, email, cohort membership, assessment responses and readiness scores, lesson progress, credentials issued, and any outcome or referral records your staff enter.
- Organization records: your program details, seat allocation, employer partners, and regional targets.
- We do not collect Social Security numbers, financial account data, or health information, and the platform is not designed to store them.
Hosting & subprocessors
- The application and database run on managed cloud infrastructure in the United States.
- Transactional email is delivered through an email service provider.
- AI coaching features send the participant's message and program context to a hosted model provider to generate a reply.
- A current subprocessor list is available on request during procurement.
Retention, exports & deletion
- You can export participant, outcome, credential, and impact data as CSV at any time.
- Data is retained for the life of your agreement. On termination we will export your data and delete it on request.
- Individual participant records can be removed on request from your program lead.
Agreements & procurement
- We will review and sign your data processing agreement, data-sharing agreement, or student data privacy terms.
- We complete standard security questionnaires and public procurement paperwork.
- Accessibility: the platform is built with semantic markup and keyboard navigation; we have not completed a formal third-party WCAG audit.
Incidents & reporting
- Report a security concern or suspected vulnerability to info@workforceascend.com and we will acknowledge within one business day.
- If a security incident affects your participants' data, we will notify your program lead directly with what we know and what we are doing about it.
Procurement pack
Two documents your legal and IT reviewers usually ask for. Both describe the platform as it operates today and are written for your counsel to mark up — we will also sign your own agreement instead.
Shared responsibility
We are responsible for the platform: access controls, hosting, availability, and exports. Your organization is responsible for who you invite, what participant data you choose to enter, the accuracy of outcome records, and the agreements you are bound by. Participants are responsible for keeping their own sign-in credentials private.
