OutcomesPath

Security, Availability, and Accessibility

Effective October 3, 2026. How OutcomesPath is run, in plain language, for the people who have to approve it.

Where your data lives

Application data is stored in a managed PostgreSQL database hosted by Supabase in the United States. Pages are served by Netlify's content delivery network. We do not move data outside the United States.

How access is controlled

Encryption and headers

All traffic is encrypted in transit (HTTPS with HSTS). Data is encrypted at rest by the database provider. Pages send a content security policy that limits scripts, frames, and connections to our own services.

Audit trail

Every login, logout, message, record change, status change, outcome update, export, tool opened, settings change, and permission change is written to an activity log by the database itself, with who, when, and from what browser. Admins can filter and export it. The log is retained for seven years after the event unless the organization requests a different period in writing.

Backups and recovery

The database is backed up daily by the provider with point-in-time recovery available. Our recovery time objective is four hours and our recovery point objective is 24 hours (one hour where point-in-time recovery is enabled for the organization's plan).

Availability

Our target is 99.5 percent monthly availability for the application, excluding announced maintenance. Maintenance is scheduled outside 7 a.m. to 7 p.m. Eastern on weekdays and announced to organization owners by email at least 48 hours ahead. Current status and incident history are available on request.

Incident response

If we detect or are told of a security incident affecting an organization's data, we contain it, assess what was affected, notify the organization's owner by email within 72 hours of confirmation (sooner where the law or the organization's contract requires), and provide a written summary with the cause and the steps taken.

Data requests and deletion

Organizations can export every record at any time in Excel or CSV and can delete participant records themselves. When an organization closes its account, we provide a full export on request and delete the organization's data within 30 days, except for records we are required to keep by law or by the organization's funder.

Accessibility

OutcomesPath is built to WCAG 2.2 Level AA. Every screen is checked with automated tools and keyboard testing before release: color contrast, headings, labels, focus order, dialogs that hold focus, and layouts that work from 320-pixel phones to desktops. If you find something that does not work with your assistive technology, email us and we will fix it or provide the information another way.

Subprocessors

Supabase (database, authentication, storage), Netlify (hosting), Resend (transactional email), Stripe (payments), Google Fonts and public code libraries (page display). The free training tools load from AdultSkilledTrades.com and YouthSkilledTrades.com, which we operate.

Questions

Security questionnaires, data processing agreements, and accessibility statements: info@outcomespath.com.