Blacklink
  • Home
  • About
  • Our Brands
  • Legal
Get Started
← Back to Legal Center

Security Overview

Security Overview

Blacklink, Inc. implements comprehensive security measures to protect student data, educational records, and platform integrity. Our security program follows industry best practices and complies with educational privacy regulations including FERPA, COPPA, and applicable state laws.

Security Principles

  • Defense in Depth: Multiple layers of security controls
  • Zero Trust: Verify every user and device
  • Privacy by Design: Security built into every system
  • Continuous Monitoring: 24/7 threat detection
  • Incident Response: Rapid response to security events

Data Protection

Encryption

  • Data in Transit: TLS 1.3 encryption for all data transmission
  • Data at Rest: AES-256 encryption for stored data
  • Database Encryption: Transparent data encryption for databases
  • Key Management: Hardware security modules for key storage

Access Controls

  • Multi-Factor Authentication: Required for all administrative access
  • Role-Based Access: Principle of least privilege
  • Session Management: Secure session tokens with automatic expiration
  • API Security: OAuth 2.0 and JWT tokens for API access

Data Classification

  • Highly Sensitive: Student records, assessment data, personal information
  • Sensitive: Usage analytics, technical logs, platform metadata
  • Internal: Business data, documentation, support tickets
  • Public: Marketing materials, public documentation

Infrastructure Security

Cloud Security

  • SOC 2 Type II: Compliant cloud infrastructure
  • Network Segmentation: Isolated environments for different data types
  • Firewalls: Next-generation firewalls with intrusion prevention
  • DDoS Protection: Distributed denial of service mitigation
  • Regular Patching: Automated security updates

Application Security

  • Secure Development: Security integrated into development lifecycle
  • Code Reviews: Security-focused peer review process
  • Vulnerability Scanning: Automated scanning of applications and infrastructure
  • Penetration Testing: Annual third-party security assessments
  • Dependency Management: Regular updates of third-party libraries

Monitoring and Detection

  • SIEM System: Security information and event management
  • Intrusion Detection: Network and host-based monitoring
  • Anomaly Detection: Machine learning-based threat detection
  • Log Management: Centralized logging with retention policies
  • Threat Intelligence: External threat feeds and indicators

Incident Response

Incident Response Team

  • Security Operations Center: 24/7 monitoring and response
  • Incident Commander: Designated response leader
  • Technical Team: System administrators and developers
  • Legal/Compliance: Privacy and legal expertise
  • Communications: Stakeholder notification and updates

Response Procedures

  • Detection: Automated alerts and monitoring systems
  • Analysis: Threat assessment and impact evaluation
  • Containment: Immediate isolation of affected systems
  • Eradication: Removal of threats and vulnerabilities
  • Recovery: Restoration of normal operations
  • Lessons Learned: Post-incident review and improvements

Breach Notification

In case of a data breach affecting educational records or personal information:

  • Immediate assessment within 1 hour of discovery
  • Notification to affected institutions within 24 hours
  • Regulatory notifications as required by law
  • User notifications when legally required
  • Detailed incident report within 72 hours

Business Continuity

Backup and Recovery

  • Automated Backups: Daily encrypted backups of all critical data
  • Geographic Redundancy: Backups stored in multiple regions
  • Recovery Testing: Regular disaster recovery drills
  • RTO/RPO Targets: 4-hour recovery time, 1-hour data loss maximum

High Availability

  • Load Balancing: Traffic distribution across multiple servers
  • Auto-scaling: Dynamic resource allocation
  • Failover Systems: Automatic switching to backup systems
  • Uptime Monitoring: Real-time availability tracking

Compliance and Auditing

Regular Assessments

  • Annual Security Audit: Independent third-party assessment
  • Compliance Reviews: FERPA, COPPA, and state law compliance
  • Risk Assessments: Quarterly security risk evaluation
  • Vendor Assessments: Security review of all third-party services

Certifications and Standards

  • SOC 2 Type II: Annual attestation for security controls
  • ISO 27001: Working toward certification
  • NIST Framework: Alignment with cybersecurity framework
  • Student Data Privacy: Adherence to educational privacy standards

Employee Security

Security Training

  • Onboarding Training: Security awareness for all new employees
  • Annual Refresher: Updated security training requirements
  • Phishing Simulations: Regular testing and education
  • Incident Response Training: Specialized training for response teams

Access Management

  • Background Checks: Required for all employees with data access
  • Onboarding/Offboarding: Secure provisioning and deprovisioning
  • Regular Reviews: Quarterly access reviews and updates
  • Confidentiality Agreements: Legal obligations for data protection

User Security

Account Security

  • Strong Passwords: Complexity requirements and recommendations
  • Multi-Factor Authentication: Available for enhanced security
  • Session Management: Automatic logout and concurrent session limits
  • Suspicious Activity Detection: Automated monitoring of unusual access

Security Best Practices for Users

  • Use strong, unique passwords for your account
  • Enable multi-factor authentication when available
  • Keep your browser and devices updated
  • Never share your login credentials
  • Report suspicious activity immediately
  • Log out when using shared computers

Vulnerability Management

Vulnerability Assessment

  • Continuous Scanning: Automated vulnerability detection
  • Penetration Testing: Annual ethical hacking assessments
  • Bug Bounty Program: Reward program for security researchers
  • Responsible Disclosure: Clear process for reporting vulnerabilities

Patch Management

  • Critical Patches: Applied within 24-48 hours
  • High Priority: Applied within 1 week
  • Medium Priority: Applied within 30 days
  • Change Management: Controlled deployment process

Report Security Issues

If you discover a security vulnerability or have security concerns:

  • Email: [email protected]
  • Response Time: Within 24 hours
  • Encrypted Communication: PGP key available upon request
  • Responsible Disclosure: Please allow reasonable time for fixes