AGENCYSCRIPT
EnterpriseBlog
๐Ÿ‘‘FoundersSign inJoin Waitlist
AGENCYSCRIPT

Governed Certification Framework

The operating system for AI-enabled agency building. Certify judgment under constraint. Standards over scale. Governance over shortcuts.

Stay informed

Governance updates, certification insights, and industry standards.

Products

  • Platform
  • Certification
  • Launch Program
  • Vault
  • The Book

Certification

  • Foundation (AS-F)
  • Operator (AS-O)
  • Architect (AS-A)
  • Principal (AS-P)

Resources

  • Blog
  • Verify Credential
  • Enterprise
  • Partners
  • Pricing

Company

  • About
  • Contact
  • Careers
  • Press
ยฉ 2026 Agency Script, Inc.ยท
Privacy PolicyTerms of ServiceCertification AgreementSecurity

Standards over scale. Judgment over volume. Governance over shortcuts.

Security

Enterprise-Grade Security

How we protect your data, accounts, and certification integrity.

Security Architecture

Defense in depth, by default

Every layer of the Agency Script platform is designed with security as a first-class concern โ€” from the edge to the database.

Authentication & Access Control

Passwords hashed with bcrypt (cost factor 12). Short-lived JWT sessions with refresh rotation. Multi-factor authentication available for all accounts. Fine-grained role-based access control across learner, instructor, and admin scopes.

Data Protection

TLS 1.3 enforced for all data in transit. AES-256 encryption at rest for sensitive fields. Strict tenant isolation at the database row level ensures no cross-account data leakage.

Audit & Compliance

Immutable, append-only audit logs for every privileged action. Hash-chain integrity verification prevents retroactive tampering. Controls aligned to SOC 2 Trust Services Criteria.

API Security

Adaptive rate limiting per endpoint and per consumer. Scoped API key management with automatic rotation reminders. Request-level abuse detection and CSRF protection on all state-changing operations.

Session Security

Short-lived access tokens (15 min) with secure, httpOnly refresh cookies. Step-up authentication required for sensitive operations like credential issuance. Instant session invalidation on password change.

Infrastructure

Deployed on Vercel edge network with automatic DDoS mitigation. Neon PostgreSQL with point-in-time recovery and automated daily backups. Environment secrets managed through encrypted vaults, never checked into source.

Compliance Posture

Frameworks we align to

We map our controls to widely recognized security and AI governance frameworks so enterprise teams can evaluate us with confidence.

SOC 2 Type II

Aligned

Controls mapped to Trust Services Criteria for security, availability, and confidentiality.

GDPR

Compliant

Data minimization, right to erasure, Data Processing Agreements available for enterprise customers.

CCPA

Compliant

Consumer rights honored: access, deletion, opt-out of sale. No personal data is sold.

EU AI Act (Article 9)

Mapped

Risk management, data governance, and transparency obligations mapped for AI-driven assessment features.

ISO 27001

Aligned

Information security management controls aligned to Annex A. Formal certification on the roadmap.

NIST AI RMF

Aligned

AI risk functions (Govern, Map, Measure, Manage) applied to our certification and assessment pipelines.

Certification Integrity

Credentials you can trust

An AI certification is only as valuable as the integrity behind it. We enforce anti-fraud measures at every stage of the assessment lifecycle.

Proctoring Session Monitoring

Timed exam sessions with activity telemetry detect anomalous patterns and flag submissions for review.

Watermark Tokens

Every lab session and exam attempt is tagged with a unique, non-removable watermark token for traceability.

Integrity Hash Verification

Submissions are SHA-256 hashed at capture time. Any post-submission modification is cryptographically detectable.

Multi-Reviewer Panel

High-tier certifications require independent review by multiple qualified assessors before credential issuance.

Credential Revocation

Credentials can be revoked instantly if fraud or policy violations are confirmed, with full audit trail.

Public Verification API

Employers and partners can verify any credential in real time through our public verification endpoint.

Data Retention & Privacy

Your data, your rights

We collect only what is necessary, retain it only as long as required, and give you full control over your information.

Retention Schedules

  • Account data retained while the account is active, deleted within 30 days of closure.
  • Certification records retained for 7 years to support credential verification.
  • Audit logs retained for 3 years. Legal hold exemptions override standard schedules when required.

Privacy Rights

  • Self-service data export in machine-readable format (JSON) from your account settings.
  • Right-to-delete requests processed within 15 business days.
  • GDPR Article 30 records of processing activities maintained and available on request for DPA signatories.

Responsible Disclosure

Report a vulnerability

We value the security research community. If you discover a vulnerability, we want to hear about it and will work with you to resolve it quickly.

Contact

security@agencyscript.com

Response time: We acknowledge reports within 2 business days and aim to provide a resolution timeline within 5 business days.

Safe harbor: We will not pursue legal action against researchers who act in good faith, follow responsible disclosure practices, and do not access or modify other users' data.

Acknowledgment: With your permission, we will recognize your contribution on our security hall of fame.

Last reviewed: March 2026

For security inquiries, Data Processing Agreements, or to request our full security documentation package, contact security@agencyscript.com.