Launching soonCTSO Central officially launches August 24th! Join our Early Access list and be the first to experience the difference a modern platform makes.
CTSOCentral

Legal

Technical and Organizational Security Measures (TOSM)

Last updated: July 25, 2026

These Technical and Organizational Security Measures describe the security commitments Clearpoint Business Group, LLC ("Clearpoint Business Group," "we," or "us") applies to CTSO Central under the applicable customer agreement for CTSO Central (the "Agreement").

We wrote these measures to explain, in our own terms, how we design, operate, and monitor CTSO Central to protect Customer Data. They cover our security program, the controls built into the platform, the responsibilities we keep internally, and the options customers can configure for their own environments.

1. Definitions

For purposes of these Security Measures, the following terms have the meanings below. Any capitalized term not defined here has the meaning given in the Agreement.

1.1. "Cloud Provider" means Amazon Web Services (AWS), the cloud infrastructure provider we use for CTSO Central.

1.2. "Customer Data" means data submitted, uploaded, stored, or otherwise processed in CTSO Central by you or by users acting under your account.

1.3. "Data Breach" means a security breach that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Data.

1.4. "Information Security Program" means the written policies, standards, procedures, practices, and controls we maintain to protect Customer Data and CTSO Central Systems.

1.5. "CTSO Central Systems" means the infrastructure, applications, environments, tools, and internal systems we use to build, test, operate, secure, and support CTSO Central.

1.6. "Privileged User" means an employee or approved contractor of Clearpoint Business Group who has been expressly authorized to access Customer Data or CTSO Central Systems when that access is required for assigned work.

1.7. "Security Incident Response Plan" means our documented process for evaluating suspected security events and responding to confirmed Data Breaches and other security incidents.

2. Our Security Program

2.1. Program Approach. Clearpoint Business Group maintains a written Information Security Program designed to protect the confidentiality, integrity, and availability of CTSO Central and Customer Data. The program includes administrative, technical, and physical safeguards to help us identify risks, prevent and detect security events, respond to incidents, and recover services when needed. Our approach is guided by applicable data protection requirements and by recognized security frameworks, including the NIST Cybersecurity Framework, NIST SP 800-53 Revision 5, and NIST SP 800-171 Revision 2.

2.2. Program Ownership and Review. Our security team is responsible for maintaining the Information Security Program. We monitor compliance with internal security requirements, provide recurring security education, and review the program at least annually. We update the program as our business, technology, services, risks, and legal obligations evolve. We will not knowingly reduce the overall effectiveness of the safeguards described in these Security Measures.

2.3. Personnel Practices

2.3.1. Screening. We conduct industry-standard background checks for employees and for contractors who will have access to Customer Data or CTSO Central Systems.

2.3.2. Confidentiality and Security Commitments. Personnel who may access Customer Data, including Privileged Users, must agree in writing to confidentiality and information security obligations. Those obligations continue after their employment or engagement ends where permitted by law. We also maintain disciplinary processes for violations of security policies and procedures.

2.3.3. Training. Our personnel complete security training when they join Clearpoint Business Group and at least annually after that. Training covers topics such as phishing, insider risk, secure handling of Customer Data and personally identifiable information, and role-specific topics such as secure coding when relevant. Privileged Users receive additional training tied to their elevated access, and we keep records of required training.

2.4. Third-Party Providers. We review third-party service providers before they are onboarded to support CTSO Central. That review considers their security practices and controls. Providers that support CTSO Central must agree to appropriate confidentiality, security, control, and reporting obligations. We also perform targeted follow-up diligence on a quarterly basis.

2.5. Security Contact. Security questions or concerns may be submitted through your normal support channels, through help.ctsocentral.com, or by emailing support@ctsocentral.com.

3. Platform Security Controls

3.1. Hosting and Data Center Security. CTSO Central runs on AWS. AWS is responsible for the physical security of the data centers used to deliver AWS services, including the data center controls and compliance programs described at aws.amazon.com/security. At least twice per year, Clearpoint Business Group or its auditors review relevant AWS security materials, including available compliance certifications.

3.2. Encryption

3.2.1. Encryption in Transit. CTSO Central protects network traffic with Transport Layer Security (TLS). TLS is enabled by default and cannot be disabled. Customer Data transmitted to CTSO Central is encrypted in transit using TLS 1.2 or higher.

3.2.2. Key Management for Transit Encryption. Encryption in transit is supported by OpenSSL encryption modules and AWS Key Management Service (KMS). We maintain guidance for cryptography and key management and configure TLS protocols and parameters accordingly. Our practices address approved key lengths, controlled distribution and storage, replacement and recovery processes, access restrictions, key history, and activation and deactivation periods. If a key is compromised, it is revoked, retired, and replaced. TLS certificates are obtained from widely trusted public certificate authorities, and ephemeral session keys used during standard TLS negotiation are not written to disk.

3.2.3. Encryption at Rest. Customer Data is encrypted at rest using AES-256 for volume-level storage. AWS provides the underlying transparent disk encryption and manages the associated encryption keys.

3.2.4. Encryption in Use. Certain CTSO Central features, including third-party integration account configuration, use asymmetric public-private key encryption with a zero-knowledge design. For those features, CTSO Central does not possess, store, or have access to the cryptographic keys needed to decrypt the protected credentials. Clearpoint Business Group personnel cannot decrypt or access credentials protected by that design, regardless of privilege level, and you retain control of those credentials.

3.3. Network Security

3.3.1. Network Isolation. CTSO Central is built with defense-in-depth network controls, including isolated virtual private networks, layered access policies, and security group enforcement. Non-public and authenticated endpoints are protected from unauthorized access. Backend databases, file storage, and internal security tooling operate within private network boundaries and are not exposed to the public internet.

4. Access Controls

4.1. Customer Access. CTSO Central provides multiple authentication and authorization options so customers can configure access to meet their needs. You are responsible for understanding and managing the configuration choices available in your CTSO Central environment, including the CTSO Central web administrative interface ("CTSO Central UI") and supporting applications such as CTSO Central Secure Testing, CTSO Central Evaluations, and CTSO Central Transcripts.

4.1.1. CTSO Central UI. CTSO Central UI credentials are stored using industry-standard, audited one-way hashing. The CTSO Central UI supports multi-factor authentication (MFA), including security key and biometric options that allow use of hardware security keys or built-in authenticators. It also supports federated authentication through Single Sign-On (SSO) using Security Assertion Markup Language (SAML) and OpenID Connect 2.0 (OIDC 2.0).

4.1.2. CTSO Central Secure Testing. When CTSO Central creates a student exam access key, the plaintext key is shown once and then discarded. CTSO Central stores one-way cryptographic fingerprints for exam-time verification and a separately encrypted copy that authorized conference staff may retrieve for proctoring. Stored access-key records cannot be read as usable credentials through database access alone because the application encryption key is held outside the database. Access keys are encrypted using AES-256-GCM and hashed using SHA-256. Exam client communications use TLS 1.2 or higher. For secure testing, CTSO Central also applies a separate application-layer encryption process inside the TLS session: exam questions and student answers are encrypted end-to-end between our servers and the exam application using AES-256-GCM, with per-session keys established through ephemeral elliptic-curve key agreement and server identity anchored in AWS Key Management Service. This keeps exam content encrypted at the application layer even if the surrounding TLS session is terminated, inspected, or logged by intermediate infrastructure.

4.1.3. CTSO Central Evaluations. CTSO Central Evaluations uses CTSO Central's configurable authentication and authorization controls to manage access to evaluation-related data and workflows.

4.1.4. CTSO Central Transcripts. Student transcripts are protected behind a unique conference code combined with the student's unique access key or member ID. Both values are required to retrieve a transcript, so a conference code alone does not expose student records.

4.2. Clearpoint Business Group Access to CTSO Central Data

4.2.1. Privileged User Access. Clearpoint Business Group personnel are generally not authorized to access Customer Data. A limited set of Privileged Users may access CTSO Central data only when necessary to investigate or restore critical services. Data protected by zero-knowledge asymmetric encryption is not visible to those Privileged Users. We follow least-privilege principles, and any access is limited to the minimum time and scope needed for the work.

4.2.2. Credential Requirements. Privileged User accounts are used only for privileged activities. Privileged Users must use separate accounts for non-privileged work, and shared credentials are not permitted. The personnel password and MFA requirements described in Section 4.3.3 also apply to Privileged User accounts.

4.2.3. Access Review and Auditing. We review Privileged User authorizations quarterly and revoke access when it is no longer required, including within 24 hours after a Privileged User changes roles or leaves the company. We log access by Clearpoint Business Group personnel to CTSO Central data. Audit logs are retained for at least six years and include timestamp, actor, action, and output information. We review those logs using automated and human review.

4.3. Clearpoint Business Group Access to Internal Systems

4.3.1. General. Access to CTSO Central Systems is managed using role-based access control, least privilege, and separation of duties. For CTSO Central, developers are granted access only to development environments, while production access is limited to authorized Privileged Users. We review system access quarterly and review changes to Privileged User authorization immediately. When an employee leaves Clearpoint Business Group, access to CTSO Central Systems is revoked within 24 hours.

4.3.2. Production Environment Access. CTSO Central's backend production environment is accessible only to a dedicated group of Privileged Users approved by senior management. Privileged Users access the production environment through bastion hosts, and MFA is required both to log in and to establish SSH access through the bastion host.

4.3.3. Credential Requirements. Clearpoint Business Group personnel passwords must meet industry-standard complexity requirements. MFA is mandatory for Clearpoint Business Group personnel and cannot be disabled.

4.4. Physical Controls at Clearpoint Business Group Offices. Customer Data is hosted in AWS data centers, not in facilities owned or operated by Clearpoint Business Group. At our offices, we use physical security practices appropriate for the information handled and the nature of our operations. These practices include formal provisioning and approval of access cards, limiting sensitive areas to personnel with a business need, requiring visitors to sign in and be escorted in non-public areas, using surveillance for entry points from public spaces, and revoking personnel access within 12 hours after termination.

4.5. Secure Deletion of Customer Data. When data is deleted within CTSO Central, it is removed from the active customer environment. Deleted data may remain in secure backups for up to 30 days for recovery purposes only. Backup data is restorable only within the CTSO Central platform and cannot be extracted or exported by Clearpoint Business Group personnel. After the 30-day backup retention period ends, the associated data is permanently and irrecoverably purged.

5. Systems Security

5.1. Separation of Production and Non-Production Environments. CTSO Central separates production and non-production environments. Customer Data from the CTSO Central production environment is not used for non-production purposes. Development, testing, and staging take place in non-production environments. We also use firewalls and related controls to separate the CTSO Central production environment from internal networks.

5.2. Software Development Lifecycle. Security is part of our software development lifecycle. A dedicated security team, reporting to the Executive Leadership Team, leads security initiatives across product development. New products and features move through a multistage process that includes defined security acceptance criteria and is informed by NIST and OWASP guidance. Our SDLC includes code review, change tracking, source code versioning, continuous integration, static and dynamic analysis, vulnerability management, threat modeling, bug hunts, and both automated and manual source code analysis.

5.3. Monitoring and Alerting. We continuously monitor CTSO Central health and performance. We maintain centralized log collection, storage, and analysis for the CTSO Central production environment. Logs are used for health monitoring, troubleshooting, and security purposes, including intrusion detection. Log data is retained for at least six years and is monitored through automated scanning, automated alerting, and human review.

5.4. Vulnerability Management

5.4.1. Vulnerability Scanning. Clearpoint Business Group maintains a documented vulnerability management process for identifying internet-accessible company assets, scanning for known vulnerabilities, evaluating risk, and tracking remediation. At least quarterly, we scan the underlying systems used to operate CTSO Central and third-party code integrated into our products. Engineering teams evaluate known vulnerabilities in system components and set remediation timelines based on severity. We also use automated tooling, monitor relevant security bulletins, and apply patches when security issues are identified.

5.4.2. Remediation. Security issues are tracked in a central company-wide ticketing system until they are remediated. Operating system and application patches are implemented based on risk and need, including severity assessed through the Common Vulnerability Scoring System (CVSS). Patches, bug fixes, and new features are assigned to target releases and deployed to production only after required checkpoints, such as quality assurance testing, staged deployment, and management review.

5.5. Penetration Testing and Internal Risk Assessments

CTSO Central is regularly reviewed by internal security personnel.

5.5.1. Internal Testing. CTSO Central undergoes periodic internal risk assessments, including technical vulnerability discovery and business risk review. The security team also participates in source code review, architecture review, code commit peer review, and threat modeling.

6. Availability, Backups, and Recovery

6.1. High Availability and Failover. CTSO Central is deployed across multiple AWS Availability Zones. These zones are geographically distributed and physically independent data center clusters with separate power, cooling, water, and network infrastructure. If a disruption affects one data center or cluster, CTSO Central automatically routes traffic to a healthy Availability Zone to help maintain service availability.

6.2. Backups. CTSO Central uses a backup strategy that includes hourly snapshots, daily incremental backups, and weekly full backups. Backup data is stored in locations that are physically and logically isolated from the production environment. CTSO Central's database architecture also supports point-in-time recovery within the applicable retention window. CTSO Central targets a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours, meaning that in a disaster scenario no more than one hour of data is expected to be lost and service restoration is targeted within four hours.

6.3. Business Continuity and Disaster Recovery. Clearpoint Business Group maintains a documented business continuity and disaster recovery ("BCDR") plan aligned with ISO/IEC 22301:2019. The plan identifies roles and responsibilities, service availability requirements, recovery point and recovery time objectives, and backup and restoration procedures. We review, update, and test the BCDR plan at least annually.

7. Incident Response and Customer Communications

7.1. Security Incident Response Plan. Clearpoint Business Group maintains a Security Incident Response Plan as part of the Information Security Program. The plan is informed by NIST and ISO/IEC 27001:2022 and guides our response when we become aware of a Data Breach or other security incident. It defines roles and responsibilities, reporting paths, procedures for assessment, classification, containment, eradication, and recovery, notification procedures and timelines, forensic investigation and log preservation steps, and post-incident review. We review, update, and test the plan annually, including through at least one security tabletop exercise each year.

7.2. Security Incident Tracking. We maintain a security incident tracking process aligned with ISO/IEC 27001:2022. The process documents the incident type and suspected cause, whether unauthorized or unlawful access, disclosure, loss, alteration, or destruction of data occurred, categories of affected data where applicable, timing of the incident or suspected incident, and remediation actions taken.

7.3. Customer Communications. If we confirm a Data Breach, we will notify you as promptly as the circumstances allow. Our initial communication will include the information reasonably available at that time, such as the general nature of the incident, the suspected or confirmed cause when known, and the expected path to resolution. As the investigation continues, we will provide appropriate updates about root cause, potential impact, completed remediation, and any additional steps we plan to take to reduce the likelihood of a similar issue.

8. Security Questionnaires

No more than once per year, Clearpoint Business Group will complete a written security questionnaire from you regarding the controls described in these Security Measures.