Security · CIO / ISSO
FedRAMP is not authorized. Here is the boundary anyway.
Commercial SaaS on Cloudflare. The buying agency decides whether its use is inside FedRAMP scope. This page is an architecture and control statement, not an ATO.
Authorization boundary
Public origin realworldcareers.com (Cloudflare Pages) plus APIs on Cloudflare Workers, D1, and R2 in ALA’s Cloudflare account. Checkout: Stripe. Transactional email: Mailgun. No agency-hosted component. No mobile app store binary in this SKU.
Data flow
- After payment, the agency receives an organization wallet by email. The agency types an ID it already uses (employee number, seat code — never a legal name, never SSN).
- The agency sends that seat’s assessment link in its own mail. ALA does not receive a name roster.
- The completer answers 50 items in the browser over HTTPS.
- Worker scores the session. D1 stores the agency-typed ID, credential, scores, and completion metadata — not a personnel file.
- The agency retrieves the HTML report and CSV by ID over HTTPS. Card data goes only to Stripe. ALA does not store PAN.
Subprocessors
| Vendor | Role | Data |
|---|---|---|
| Cloudflare, Inc. | CDN, Workers, D1, R2, DNS, WAF | Agency-typed IDs, scores, buyer admin email, logs/IP at the edge |
| Stripe, Inc. | Payment | Payer email and card (Stripe) |
| Mailgun (Sinch) | Transactional email | Invite and notice addresses |
Controls we operate
- TLS in transit; HSTS on the public origin.
- Permissions-Policy: no camera, microphone, or geolocation on public pages.
- Admin access to Cloudflare and Stripe behind provider MFA. No participant passwords in this SKU (unique links).
- Secrets kept in Worker secrets / vault — not in client HTML.
- Backups: Cloudflare D1/R2 commercial durability; 7-day business snapshot process exists at company level.
- Vulnerability testing: vendor-conducted application security assessment dated 29 Aug 2026 — ASA-RWC-FED-2026-08-29. No independent 3PAO pentest. Honest residual. Control narrative: SSP-lite.
What we do not claim
- No FedRAMP authorization (Moderate in progress — not authorized).
- No agency SSO/SAML/PIV in this SKU.
- No continuous monitoring package equivalent to an authorized CSP.
Incident notification
On confirmed unauthorized access involving that agency’s IDs or scores, ALA notifies the named agency contact within 72 hours by email and phone (1-317-751-5444). A breach of our store cannot yield legal names or SSNs because we do not collect them. Security contact: team@advancedlearning.academy. After-hours: same number, voicemail to Carol Roberts office path.
FedRAMP 2026 scope. Agency risk acceptance remains with the agency.