What Data Privacy and Security Practices are Followed?

What Data Privacy and Security Practices are Followed?

Data Privacy

Veracity adheres to the EU-U.S. Data Privacy Framework to help satisfy General Data Protection Regulation (GDPR) requirements and maintain an annual certification. Please review our online privacy policy for more information about what is covered, what information we collect, and your rights to access and transfer your personal data. You can also view our certification for the Privacy Shield Principles and Program.  

Information Security Practices

Veracity offers our LRS in an approved FEDRAMP environment and has been granted an Authority to Operate (ATO) in several other DoD environments. The Veracity team has several staff members that maintain a CompTIA Security+ certification and follow a Written Information Security Program (WISP). We also employ third-party annual vulnerability penetration testing.

Security and compliance are a shared responsibility between Veracity and the cloud service providers used for Veracity Learning. AWS manages the security of the cloud, MongoDB Atlas manages the security of the database, and Veracity manages Veracity Learning’s application security. The AWS cloud infrastructure that hosts the Veracity Learning SaaS product and the MongoDB Atlas cloud infrastructure that hosts the databases both conform with many security frameworks. 

To protect against unforeseen service outages, data that is lost or stolen, and other potential security incidents, Veracity carries both Errors & Omissions and Cyber Liability insurance. The E&O coverage applies to professional services, and the Cyber Liability coverage applies to a wrongful act or data breach occurring under a data privacy or network security incident.

Veracity can offer security artifacts to customers upon request.


    • Related Articles

    • What are Different Ways xAPI Data Can Flow from an LMS to an LRS?

      Client Side This is the most common case. This is usually the approach taken if you create your content in a commercial authoring tool and export the content to xAPI/TinCan. The content package sends xAPI data directly to the LRS. The content package ...
    • How Do I Send xAPI Data to an LRS?

      If you want to send xAPI to an LRS, then you'll need to give your content or application the proper credentials to store the data in the LRS. You'll need the following: The xAPI Endpoint for the LRS. LRS credentials: Key and Secret (i.e., username ...
    • What xAPI Data is Generated by Articulate Storyline and Rise?

      Veracity customers often ask questions like: “What xAPI data does my authoring tool send to the LRS?” and “What metrics can I track with my authoring tool?" Articulate has two courseware products that emit xAPI statements: Storyline and Rise. Both ...
    • What Types of Metrics and Dashboards Can I Create with Articulate Storyline and Rise xAPI Data?

      What features do Articulate Storyline and Rise offer that make good use cases for the Veracity Learning LRS dashboard to help analyze learning performance metrics? In this article, the star ratings show the degree to which Articulate offers xAPI to ...
    • Where do I install the LRS MCP, and why?

      Some of our users asked, “The AI Integration directions list code generators, not AI agents; why?” Or “Why must I install a code generator to use the MCP?” What the MCP Does A Model Context Protocol (MCP) helps an AI agent work with another system — ...