Security you can trust

PaperScorer is built with security at its core. We maintain rigorous standards to protect your data and ensure compliance with industry regulations.

Compliance & Certifications

Meeting the highest standards for data security and privacy

Built to SOC 2 Controls

PaperScorer follows SOC 2 framework requirements covering security, availability, processing integrity, confidentiality, and privacy.

Regular Audits

Independent security assessments validate our adherence to industry best practices and regulatory standards.

FERPA Ready

Our platform is designed to help educational institutions maintain FERPA compliance for student data.

How we protect your data

Multiple layers of security ensure your data stays safe

Encryption

All sensitive data and PII is encrypted. TLS and SSL protocols protect data transmission across all communication channels.

Secure Infrastructure

Hosted on Linode (Akamai) and AWS with database encryption mandated for all sensitive information.

Access Controls

Role-based access controls and multi-layered authentication mechanisms protect your data, with two-factor authentication available on accounts.

Monitoring & Logging

Comprehensive activity logging with real-time alerts for suspicious activities.

Vulnerability Scanning

Regular scanning across systems, networks, and applications to identify and address potential vulnerabilities.

Disaster Recovery

Data backup and disaster recovery procedures ensure business continuity and data protection.

Our security practices

Security isn't just technology—it's a culture. Our team follows strict protocols to ensure your data is protected at every level.

  • Mandatory security awareness training for all employees
  • Background checks including criminal screening and employment verification
  • Confidentiality policies with regular audits
  • Defined roles and responsibilities across development, security, and operations
  • Secure software development lifecycle practices
  • Regular penetration testing and security assessments
Digital padlock on circuit board representing cybersecurity

Maintained, not just launched

The most common way a platform becomes insecure is by sitting still on old runtimes and unpatched dependencies. Keeping the stack current is ongoing work, not a one-time project.

Current runtimes

The scanning engine runs on Java 21 and Spring Framework 6; the application platform runs on MySQL 8.4. Major version upgrades are treated as scheduled work rather than deferred indefinitely.

Dependency currency

Core libraries are kept on supported major versions — including OpenCV 4.13 for image recognition and AWS SDK v2 for cloud services — so security patches remain available to us.

Audit remediation

Findings from security audits are tracked and worked through in the codebase, not filed and forgotten. Remediation work is part of the normal release cycle.

Your data, your control

We believe in transparency and giving you full control over your data

Data Ownership

You own your data. We only process it to provide our services.

Data Export

Export your data at any time in standard formats.

Data Deletion

Request complete deletion of your data when needed.

Have security questions?

Our security team is here to help. Contact us for more information about our security practices or to request documentation.