
Application data is stored in a managed PostgreSQL database hosted by Supabase in the United States. Pages are served by Netlify's content delivery network. We do not move data outside the United States.
All traffic is encrypted in transit (HTTPS with HSTS). Data is encrypted at rest by the database provider. Pages send a content security policy that limits scripts, frames, and connections to our own services.
Every login, logout, message, record change, status change, outcome update, export, tool opened, settings change, and permission change is written to an activity log by the database itself, with who, when, and from what browser. Admins can filter and export it. The log is retained for seven years after the event unless the organization requests a different period in writing.
The database is backed up daily by the provider with point-in-time recovery available. Our recovery time objective is four hours and our recovery point objective is 24 hours (one hour where point-in-time recovery is enabled for the organization's plan).
Our target is 99.5 percent monthly availability for the application, excluding announced maintenance. Maintenance is scheduled outside 7 a.m. to 7 p.m. Eastern on weekdays and announced to organization owners by email at least 48 hours ahead. Current status and incident history are available on request.
If we detect or are told of a security incident affecting an organization's data, we contain it, assess what was affected, notify the organization's owner by email within 72 hours of confirmation (sooner where the law or the organization's contract requires), and provide a written summary with the cause and the steps taken.
Organizations can export every record at any time in Excel or CSV and can delete participant records themselves. When an organization closes its account, we provide a full export on request and delete the organization's data within 30 days, except for records we are required to keep by law or by the organization's funder.
OutcomesPath is built to WCAG 2.2 Level AA. Every screen is checked with automated tools and keyboard testing before release: color contrast, headings, labels, focus order, dialogs that hold focus, and layouts that work from 320-pixel phones to desktops. If you find something that does not work with your assistive technology, email us and we will fix it or provide the information another way.
Supabase (database, authentication, storage), Netlify (hosting), Resend (transactional email), Stripe (payments), Google Fonts and public code libraries (page display). The free training tools load from AdultSkilledTrades.com and YouthSkilledTrades.com, which we operate.
Security questionnaires, data processing agreements, and accessibility statements: info@outcomespath.com.