TAGD Logo
Security & Privacy Threat Assessment & Threat Management Platform
HIPAA & FERPA Compliant

Security, Privacy & Compliance Safeguards

TAGD is engineered from the ground up to protect sensitive behavioral evaluations, threat assessments, and multidisciplinary case records. The safeguards below summarize the concrete technical controls in place across the platform.

Five Security Pillars

Data Encryption at Rest

FERPA & HIPAA aligned controls

All sensitive behavioral evaluations, student case histories, behavioral timelines, and administrative records are encrypted at rest using industry-standard AES-256-GCM encryption. Cryptographic keys are securely managed and rotated using AWS Key Management Service (KMS).

  • Encryption format: AES-256-GCM (authenticated encryption)
  • Key management: AWS KMS (wrapped data keys, controlled access)
  • Secrets and configuration: AWS Secrets Manager

Secure File Transit & S3 Storage

Secure transport & controlled file access

All uploaded case documents (behavioral reports, student notes, PDFs, DOCX) are stored in private, isolated Amazon S3 buckets. S3 policies strictly enforce SSL/TLS in transit. Document access is restricted exclusively through short-lived, pre-signed HTTPS URLs that expire automatically after 15 minutes (900 seconds).

  • TLS encryption for all browser and API requests
  • S3 bucket policy blocks non-HTTPS (SecureTransport enforcement)
  • Document access uses pre-signed HTTPS URLs with a strict 900s expiry

Tamper-Evident Case Audit Trails

Accountability & access traceability

Every administrative and investigator action is recorded in a centralized, read-only audit log. This includes login attempts, document uploads, report generation, and case file views. Any unauthorized attempt to view restricted student files triggers an immediate security event.

  • Login attempts, case actions, uploads, and document access are logged
  • Unauthorized access attempts raise security flags and log events
  • Audit integrity checks include sequence continuity, timestamps, and IP validation

Continuous Infrastructure Monitoring

Availability & security alerting

Automated monitoring audits platform health and security signals continuously to keep case management workflows available for multidisciplinary teams.

  • CPU, memory, and disk checks run every 5 minutes
  • Alerts delivered via Amazon SNS to the engineering team
  • Incident response and rollback procedures are documented and ready

Intrusion Prevention & Rate Limiting

Abuse prevention for administrative accounts

Rate limits reduce brute-force and automated abuse risk on the login portal and API endpoints that protect administrative accounts and threat assessment records.

  • Login protection blocks after 5 failed attempts per IP window
  • API endpoints enforce throttling (e.g., 100 requests/minute per key)
  • Throttled requests return HTTP 429 and are recorded for review
Privacy Commitment
TAGD is fully committed to maintaining the highest standards of threat assessment, educational administrative privacy (FERPA), and multidisciplinary data security (HIPAA). If you have questions about safeguards or data handling, contact support@tagdai.com.