Security
Ledly is designed with security and compliance as foundational principles. This section provides documentation for security reviewers, compliance teams, and IT administrators evaluating Ledly for their institution.
Ledly processes student lead data for higher education institutions. We maintain SOC 2 Type II compliance and follow industry best practices for data protection.
Enterprise SSO
Ledly supports enterprise SSO integration with major identity providers. SSO provides centralized access control, automatic user provisioning, and seamless authentication for your team. Learn more about SSO
Security Documentation
| Document | Description |
|---|---|
| Enterprise SSO | Single Sign-On configuration with Okta, Azure AD, Google Workspace, and Auth0 |
| Security Whitepaper | Comprehensive security documentation covering infrastructure, data protection, authentication, API security, and compliance considerations |
| Data Flow Diagram | Detailed overview of how data flows through Ledly, including ingestion, CRM sync, webhooks, and storage architecture |
| HECVAT Assessment | Higher Education Cloud Vendor Assessment Tool responses for institutional security reviews |
Security Highlights
| Area | Implementation |
|---|---|
| Encryption in Transit | TLS 1.3 for all connections |
| Encryption at Rest | AES-256 for database and backups |
| Authentication | JWT tokens (users), API keys (vendors), Enterprise SSO (SAML/OIDC) |
| Authorization | Role-based access control (RBAC) |
| Data Isolation | Row-level security by organization |
| Webhook Security | HMAC-SHA256 signatures with replay protection |
| Credential Storage | bcrypt (passwords), AES-256 (tokens) |
Compliance
Ledly maintains the following compliance certifications and assessments:
- SOC 2 Type II - Annual audit
- GDPR - EU data protection compliance
- CCPA - California consumer privacy compliance
- FERPA - Student data protection (higher education)
- HECVAT - Higher Education Cloud Vendor Assessment Tool
Contact Security Team
For security inquiries, vulnerability reports, or to request compliance documentation:
- Security Team: [email protected]
- SOC 2 Report Requests: [email protected]