How Alethia handles applicant data.
Applicant files are among the most sensitive records a university holds. This page says what Alethia does with them, what it does not do, and what we will put in writing for your security review.
Our commitments
- Used only to verifyAn applicant's data is used to verify that applicant's claims. It is not used to build profiles, train general models, or inform any other applicant's outcome.
- The institution owns the recordVerification records belong to the institution. They can be exported in full and deleted on request.
- Every check is loggedEach search, each outreach message, each reply, and each reader decision is written down with its time and its source. The log is part of the record you own.
- Outreach is transparentReferences are told which institution is asking, on whose behalf, and why. Alethia contacts only the people the applicant listed and asks only about what the applicant claimed.
- Humans can override anythingNo outcome is final until a reader accepts it. Overrides are recorded alongside the original finding.
What Alethia looks at, and what it leaves alone
Checked
- Public records: competition results, registries, journal indexes, league archives, organization pages, published news.
- Replies from references the applicant listed, after the sender is verified.
- Documents the applicant or the institution chooses to provide.
Not touched
- Private social media accounts and personal messages.
- Protected characteristics, or any inference about them.
- Anyone the applicant did not list as a reference.
- Scoring, ranking, or predicting an applicant's success.
Compliance and controls
Items below are listed the way Alethia lists an applicant's claims: with their current status, not with a promise. Where a status reads to be confirmed, ask us and we will answer in writing.
| Item | Detail | Status |
|---|---|---|
| SOC 2 Type II | Independent audit of security, availability, and confidentiality controls. | To be confirmed |
| FERPA | Handling of education records on behalf of the institution as a school official. | To be confirmed |
| Data residency | Region in which applicant data is stored and processed. | To be confirmed |
| Retention | How long verification records are kept after a cycle closes, and how deletion is requested. | To be confirmed |
| Encryption | Data encrypted in transit and at rest. | To be confirmed |
| Access review | Who at Alethia can access institutional data, and how that access is logged and reviewed. | To be confirmed |
| Statuses are maintained by Alethia and updated as audits complete. | ||
Reporting a vulnerability
If you believe you have found a security issue in Alethia, write tosecurity@alethia.website. We acknowledge reports and keep you informed until the issue is resolved.
Security review packet
Procurement questionnaires, architecture summaries, and data-flow diagrams are available on request for institutions evaluating Alethia.
Request the packetAsk us the hard questions.
Security review is part of every university procurement. Send yours and we will answer each item in writing.