Data & Security
Defined access. Clear responsibilities.
The controls below describe the website as implemented. Engagement-specific data handling is agreed in writing before source files are shared.
Access
Administrative routes require an authenticated, allowlisted administrator. Course content is checked against enrollment on the server, not just hidden in the interface.
Authentication
Learners use a time-limited email code for an enrolled address. Session tokens are stored as hashes on the server. Revoking course access also revokes the learner’s sessions and pending codes. Administrators use a separate authenticated access path.
Data Transfer
Do not send bank credentials, full account numbers, patient records, or other sensitive source files through the public inquiry form. The file list and transfer method are agreed before an engagement begins.
Storage
The website is hosted through OpenAI Sites. Application records use its Cloudflare D1 database; uploaded course and published archive assets use object storage. Stripe processes payments, and Resend delivers transactional email. The site does not store full payment-card numbers.
Retention & Deletion
There is no published automatic deletion schedule for engagement records. Retention requirements are agreed in the engagement terms. Contact info@keystonereportinggroup.com to request review or deletion of personal information, subject to transaction records and other applicable retention requirements.
Ownership
Ownership, permitted use of source files, and deliverable rights are set out in the engagement letter. Clients should share only information they have authority to provide.
Confidentiality
The engagement letter defines confidentiality, approved use, and permitted disclosures. Website service providers process information needed to operate the requested features, as described in the Privacy notice.
No SOC 2 certification, independent security certification, or compliance-framework accreditation is claimed.
