Skip to content
AdminformaticsAdminformatics
Security

How we secure the platform.

This page covers the infrastructure, application, and operational controls Adminformatics maintains to protect the research administration platforms institutions depend on. For compliance posture, data handling policies, and subprocessors, see the Trust & Security page.

01

Infrastructure security

  • US-based hosting — All production infrastructure runs in audited AWS regions located in the United States.
  • Encryption at rest — AES-256 encryption applied to all data stored in our systems, including database storage and backup files.
  • Encryption in transit — TLS 1.2 or higher enforced on all connections. HTTP is not accepted.
  • Network segmentation — Production systems are isolated in private network segments. Public-facing services are limited to what is operationally required.
  • Redundancy and backups — Tenant data is backed up on a daily basis. Backups are encrypted and stored separately from production systems.
02

Application security

  • Tenant isolation — Each institution's data is logically isolated at the application and database layer. Cross-tenant data access is not architecturally possible.
  • Dependency management — Third-party dependencies are monitored for known vulnerabilities. Critical patches are applied on an expedited basis.
  • Secure development practices — Code changes go through peer review. Deployments are gated on automated checks including security linting.
  • OWASP alignment — Development practices and security reviews are informed by the OWASP Top 10.
03

Access control

  • Role-based access control — Access to institution data is governed by roles defined by your administrators. Principle of least privilege is applied throughout.
  • Single sign-on — Shibboleth and Microsoft Entra (SAML 2.0 / OAuth 2.0) supported for all products. Institutions can enforce their own MFA and session policies through their identity provider.
  • Adminformatics staff access — Internal access to production systems is restricted to personnel who require it for support and operations. All access is logged.
  • Audit logging — Comprehensive audit logs cover administrative actions, data access, and configuration changes. Logs are retained and available to your institution on request.
04

Monitoring and incident response

Production systems are monitored continuously for anomalous activity, availability issues, and error patterns. Alerts are routed to on-call staff with defined escalation paths.

In the event of a security incident that affects your institution's data, Adminformatics will notify affected institutions within 72 hours of confirming the incident's scope and nature. Notification will include the nature of the incident, data affected, and steps being taken to contain and remediate.

Post-incident reviews are conducted after any significant event. Findings inform process improvements and are shared with affected institutions where relevant.

05

Responsible disclosure

If you believe you've discovered a security vulnerability in any Adminformatics product, please report it to our security team. We ask that you:

  • Not access, modify, or delete data belonging to other institutions.
  • Not disclose the vulnerability publicly before we have had a reasonable opportunity to address it.
  • Provide sufficient detail for us to reproduce and investigate the issue.

We acknowledge reports within two business days and will keep you informed of our progress. Verified disclosures are credited at the reporter's preference.

security@adminformatics.com