generated: '2026-08-12' method: searched probe: true source: https://empowerly.com/security url: https://empowerly.com/security name: Empowerly Security Commitments kind: security-commitments-page note: >- Empowerly publishes a single public security page rather than a hosted trust center (no trust.empowerly.com, no Vanta/Drata/SafeBase portal — trust.empowerly.com does not resolve and /trust and /compliance both return 404). The page names one certification and one contact, and describes the program in prose. There is no downloadable artifact: the SOC 2 report is released only on request by email. certifications: - name: SOC 2 Type 2 status: compliant evidence: '"Empowerly is SOC 2 Type 2 Compliant."' report_access: on request via security@security-contact (see contact below) public_artifact: false contact: email: security@empowerly.com purpose: SOC 2 report requests program: - area: penetration testing and vulnerability scanning claim: >- Annual penetration testing to prevent data breaches and unauthorized access; PR-based code review with vulnerability scanner audits; vulnerabilities patched by severity level. - area: endpoint protection claim: >- All devices centrally managed with MDM tooling — disk encryption, automatic screen locks, up-to-date software, active endpoint monitoring. - area: vendor risk management claim: >- Vendors assessed on data access, customer-facing integration and potential organizational impact, with a residual risk rating calculated per vendor. - area: security awareness training claim: Employees and contractors are both required to complete annual security training. - area: business continuity and incident response claim: Annual business continuity and security incident exercises and audits. not_found: - claim: ISO 27001 result: not named on the page - claim: PCI DSS result: not named on the page - claim: HIPAA result: not named on the page - claim: FedRAMP result: not named on the page - claim: FERPA / COPPA / GDPR / CCPA result: >- not named on the security page, despite Empowerly serving minors in US K-12 college admissions — a notable gap for an edtech provider. Not asserted here because it was not published. evidence: - url: https://empowerly.com/security http_status: 200 fetched: '2026-08-12' - url: https://empowerly.com/trust http_status: 404 - url: https://empowerly.com/compliance http_status: 404