How we protect your data.
MyPass LMS is built on secure, enterprise-grade cloud infrastructure with encryption, access controls, and a complete audit trail. This page summarizes our security posture and the agreements we make available to customers.
Hosted on AWS.
MyPass runs entirely on Amazon Web Services. AWS's infrastructure is independently certified to FedRAMP (Moderate and High baselines), SOC 2 Type II, ISO 27001, and GDPR. MyPass operates its own security controls aligned to these frameworks on top of that foundation.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest. Learner records, course content, and analytics are protected throughout every interaction.
Role-based access control
Access to data is scoped by role. Administrators see only what their permissions allow, and every privileged action is logged.
Immutable audit trail
Every learner and admin action is time-stamped and logged. Reports include the full evidence chain — enrollment, logins, activity, quiz attempts, and certificate issuance.
High availability
99.9% uptime SLA backed by AWS, with automatic failover and redundancy across availability zones.
Agreements we make with customers.
- We sign Data Processing Agreements (DPAs) where required for GDPR and equivalent regimes.
- We sign Business Associate Agreements (BAAs) for customers with HIPAA obligations.
- Customer Data is retained for the life of the subscription and 30 days after termination for export.
- We never sell personal data. Sub-processors (hosting, payment processing, email delivery) operate under data-protection agreements.
See our Privacy Policy and Terms of Service for the full detail.
Where we stand.
The AWS infrastructure MyPass is hosted on holds FedRAMP, SOC 2 Type II, ISO 27001, and GDPR certifications. MyPass LMS operates its own controls aligned to these frameworks.
Have a security or compliance question?
Our team can walk your security reviewers through our infrastructure, controls, and available documentation.