Security at Pivot

Security is built into how we design, build, and operate Pivot. We protect the confidentiality, integrity, and availability of customer data with modern controls, independent testing, and clear ownership.

Data Security

Data encryption

All data to and from Pivot is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256). Encryption keys are managed in cloud KMS with strict access controls and audit trails.

Infrastructure security

Pivot runs on hardened cloud infrastructure (AWS) with Cloudflare at the edge for DDoS protection and performance. Networks are segmented, access is tightly controlled, and environments are continuously monitored.

Open, transparent development

Pivot is developed in public under a Business Source License (BSL), which invites scrutiny of our codebase and accelerates fixes for security issues across app and dependencies.

Data residency (via Private Cloud)

For organizations with residency requirements (including EU), Pivot offers Private Cloud deployment with dedicated, region-scoped infrastructure. See /security/data-residency for options and regional coverage.

System Security

Secrets management

Centralized secrets management, regular rotation, and least-privilege access reduce the exposure of credentials and sensitive configuration.

Single sign-on (SSO)

SSO (including SAML) is available for enterprise customers and used internally, helping reduce password risk and centralize access control.

Supply chain security

Automated dependency scanning, vendor due diligence, and monitored build pipelines help defend against supply-chain attacks and accidental exfiltration.

Pen testing

Independent third parties conduct annual penetration tests across app, API, and cloud layers. Findings are triaged to remediation under documented SLAs.

Vulnerability disclosure

We welcome responsible security research under a published safe-harbor policy.

Pivot Security Culture
Compliance

While we currently do not hold certifications like SOC 2 or HIPAA, we recognize their importance and are actively working towards achieving them. We are dedicated to ongoing efforts to attain key industry certifications, demonstrating our commitment to data privacy and security. Additionally, we ensure our platform aligns with evolving global standards and regulations.

Incident response and recovery

We have a comprehensive incident response plan and real-time system monitoring to quickly address any security concerns. Our team of dedicated engineers is on-call 24/7 to detect, respond to, and mitigate potential security incidents. Additionally, our robust multi-cloud backup and recovery protocols ensure your data remains protected in the event of an incident.

Continuous improvement

Our security practices are constantly evolving to meet the challenges of operating a global cloud service that supports web, desktop, and mobile applications. We collaborate with industry experts and adopt the latest security best practices to provide a secure and dependable collaboration environment.

Privacy Frameworks

GDPR / UK GDPR / Swiss FADP

Covered by our Data Processing Addendum (DPA), Technical and Organizational Measures, and

GDPR Compliance Statement.

CCPA / CPRA

We do not sell personal data and we honor access, deletion, and opt-out requests, as described in our

CCPA / LGPD / Privacy Frameworks Statement.

LGPD

Rights for Brazilian data subjects are supported through our controller/processor model and documented in the same

Privacy Frameworks Statement.

EU-U.S. Data Privacy Framework (DPF)

Cross-border data transfers to the U.S. are supported via our

EU-U.S. Data Privacy Framework Statement.

Create your own Knowledge Base

Experience the power of synchronized collaboration

Collaborate globally, instantly, together

Bring versatility to your course design

Blend community with content and learning

Unite internal and external teams

Consolidate wikis, projects, and messaging

Try dynamic multi-modal collaboration