Integrity Advocate Achieves SOC 2 Type II Certification for the Third Consecutive Year
Integrity Advocate has achieved SOC 2 Type II certification for the third consecutive year, verified by auditors at the Johanson Group and supported by security partner Carbide. This post explains what SOC 2 Type II involves, why annual recertification matters more than a one-time audit, and what it means for organizations using Integrity Advocate to handle sensitive learner data.
Integrity Advocate has completed SOC 2 Type II certification for the third consecutive year, with support from auditors at the Johanson Group and security partner Carbide.
SOC 2 Type II compliance represents an ongoing commitment to security, privacy, and the responsible handling of sensitive data. For partners, clients, and learners, it means the systems and processes protecting their information have been independently verified under real-world operating conditions, not just reviewed on paper.
What SOC 2 Type II Certification Involves
SOC 2 Type II is not a one-time audit. It is an extended review conducted over several months that evaluates how effectively an organization's security and privacy controls perform under actual operating conditions. The process includes defining security controls, implementing appropriate policies, conducting risk assessments, and continuously monitoring systems to ensure those controls hold up over time.
The Type II designation is significant. Where Type I confirms that controls exist at a point in time, Type II confirms that those controls operated effectively over an extended period. It is the higher standard, and the one that matters most to organizations evaluating a vendor's security posture.
SOC 2 Type II certification is commonly obtained by SaaS vendors to demonstrate effective security controls to enterprise clients and partners. At Integrity Advocate, the motivation goes further than that.
Data security is a responsibility, not a checkbox. Integrity Advocate handles sensitive data on behalf of clients every day, including government-issued ID images, biometric data, and session recordings. The people whose data this is should never have to wonder whether it is being handled securely. SOC 2 certification is one way of demonstrating that the answer is yes, backed by independent verification rather than self-assertion.
Trust is earned through consistent practice. SOC 2 Type II measures controls over time, not at a single moment. Achieving it three consecutive years reflects a sustained commitment to maintaining security standards as threats evolve, not a one-time effort to pass an audit.
Certification makes partnership easier. SOC 2 Type II is recognized across industries as a universal standard based on proven security practices. For organizations in higher education, professional certification, industrial training, and corporate learning evaluating a proctoring vendor, SOC 2 certification provides independent confirmation that Integrity Advocate's security controls meet the standard their own compliance teams require.
The Partners Behind the Process
Throughout the certification process, Integrity Advocate worked closely with auditors from the Johanson Group, whose expertise guided the audit with transparent communication and a shared commitment to rigorous standards. Integrity Advocate also leveraged Carbide as its security platform to support the process.
What This Means for Clients and Partners
For Integrity Advocate clients and partners, SOC 2 Type II certification is straightforward confirmation that the platform handling your learners' data meets independently verified security standards. It sits alongside Integrity Advocate's 12-plus years of operation with zero data breaches and 98% client retention as part of a consistent track record, not a single credential.
For more information about how Integrity Advocate handles data security and privacy, visit the Privacy page.
{{post-cta}}
Three Consecutive Years of SOC 2 Type II Certification
Independent verification of security controls, zero data breaches across 12 years of operation, and 98% client retention. Integrity Advocate is built to be the partner your security and compliance teams can point to with confidence.
Let us walk you through how IA helps with scalable proctoring in 30 minutes.
Book a demo
Keep reading
Blogs & articles
Is Your Proctoring Solution a Security and Privacy Threat?
August 27, 2023
|
5 min read
The US Department of Education's Privacy Technical Assistance Center has documented how data breaches and malware attacks have affected education systems across every sector. Most online proctoring services require browser extensions or plugins that create exactly the kind of installation-based malware vector that security researchers flag as high risk. This post examines the threat, what organizations should require from their proctoring vendors, and why a no-installation approach eliminates the risk at the source.
The US Department of Education's Privacy Technical Assistance Center published a presentation titled Security Threats: Education Systems in the Crosshairs, in which security advisor Mike Tassey documented how data breaches, hacks, and privacy incidents have affected organizations across virtually every sector, from NASA and Citigroup to local school systems.
The warning is directly relevant to any organization using online proctoring. The data that proctoring services collect, including names, government-issued ID, biometric images, and session recordings, is exactly the kind of information that makes education systems a target.
The Threat Landscape Has Changed
Cyber-theft has become fully commoditized. There is an active black market for personal data, and an underground economy where over two million pieces of malware are built and sold every year. This malware is designed to gather precisely the kind of information proctoring platforms collect: Social Security numbers, addresses, birth dates, and identity credentials.
Tassey specifically noted that children's identities are particularly valued by data thieves because they are, in his words, fresh. A child's identity may go undetected for years before the theft is discovered, making it a high-value target for long-term fraud.
The alarming part is how malware typically gets onto devices. It is not usually through pirated software or poor security settings. It enters through plugins and browser extensions that users install themselves, often for legitimate purposes. The installation is the vector.
Why Proctoring Plugins Create Specific Risk
Most online proctoring services require users to install browser extensions or plugins to enable monitoring. Each of these installations represents an opportunity for malware to enter the device, either during the initial installation or through a subsequent update, without the user's knowledge or permission.
Tassey's research notes that on average there are one to five bugs for every 1,000 lines of code. For organizations that have not completed independent code reviews of the proctoring software they deploy, those bugs represent an unexamined attack surface. Malware can be introduced into code updates without detection, meaning a plugin that was clean at installation may not remain so.
At minimum, organizations should be instructing learners to disable or uninstall proctoring plugins and extensions immediately after use. The risk does not end when the exam does.
What a Code Review Should Cover
Organizations that require learners to install proctoring software should conduct, or require their vendor to provide evidence of, a code review that addresses:
Potential malware embedded in the plugin or extension code
Errors or vulnerabilities that could be exploited by third parties
Whether the software receives automatic updates, and what review process governs those updates
What data the software transmits, to where, and under what conditions
If a vendor cannot provide clear answers to these questions, the software should not be deployed on learner devices.
The Case for No-Installation Proctoring
The most effective way to eliminate installation-based security risk is to remove the installation requirement entirely. Integrity Advocate's platform is browser-based and requires no plugin, extension, or application installation in most cases. There is nothing to install, nothing running in the background after the session ends, and no update mechanism that could introduce malware without the user's knowledge.
For use cases that do require a lockdown browser, Integrity Advocate's solution uses fully open source code, does not accept automatic updates after installation, and does not transmit data beyond what is required for the session. The code is publicly available for inspection.
The US Department of Education's guidance on protecting student privacy points to the same principle: the safest data handling approach minimizes what is collected, minimizes how long it is retained, and minimizes the software footprint on learner devices.
Why Most Remote Proctoring Companies Don't Want You to Read Their Privacy Policy
September 15, 2020
|
5 min read
Most proctoring companies collect far more personal data than test takers realize, and their privacy policies say so explicitly. This post breaks down what proctoring providers are actually collecting, shares four real privacy policy excerpts that should concern any organization, and explains how Integrity Advocate's Privacy by Design approach limits collection, mandates deletion, and keeps learner data out of the hands of third parties.
Consider two scenarios.
In the first, security cameras in a school record a student walking through the hallways and interacting with friends. The school stores the recording indefinitely as part of the student record and shares it with other organizations.
That feels wrong.
In the second scenario, cameras capture the same student bullying a younger student. Only the portion of the recording showing the behavior is retained, and it is shared with the organizations responsible for taking appropriate action.
That feels reasonable. There is a legitimate purpose, a proportionate response, and a clear limit on what gets shared and why.
Remote proctoring technology is an extension of the same principle. The question is whether the companies providing it are applying that principle, or ignoring it entirely.
What Proctoring Companies Are Actually Collecting
Most people assume online proctoring captures what it needs to verify identity and monitor an assessment session. The reality, based on the privacy policies of many proctoring providers, is considerably broader.
Many proctoring services collect, intentionally and unintentionally, personal information that includes:
Social security numbers, driver's license numbers, and passport numbers
Biometric information including facial geometry, physiological and behavioral characteristics, and genetic data
IP addresses and device identifiers
Full browsing history, search history, and records of interactions with websites and applications
Medical information including physical and mental health conditions
Drug use history and political affiliations
Footage of children, spouses, and other individuals who happen to be in the same space as the person being proctored
This is not a hypothetical. This is what the privacy policies say.
Four Things You Will Find in Proctoring Privacy Policies
The following are real excerpts from proctoring company privacy policies currently in use. Read them carefully.
1. "By accessing and using our Services, you consent to allow free exchange of proctoring information between [Proctoring Service Company] and your educational institution. We, or vendors on our behalf, may track the websites you visited before and after our websites as part of the traffic data described above for our internal business purposes."
2. "If your institution has consented, we may also use third-party solutions to process selected data."
3. "We may disclose information, including video and audio recording of your exam session, to your educational institution/certifying entity upon request. Your information may be sold or transferred as part of that transaction."
4. "We cannot ensure or warrant the security of any information you transmit to us or store on the Services, and you do so at your own risk."
Students and workers taking online assessments are required to submit to proctoring. They do not have the option to choose a different provider or opt out. That disparity in power makes these policies more than a legal formality. It makes them an ethical issue.
Why Privacy by Design Is the Only Acceptable Standard
The school camera analogy holds here too. We expect schools to share footage of students only when there is a legitimate reason and only to the extent necessary. We should expect the same from proctoring technology.
Privacy by Design is not a compliance label. It is an architectural commitment — the decision to build data minimization, purpose limitation, and deletion into the product from the start, rather than adding privacy language to a policy document after the fact.
That is how Integrity Advocate is built.
What Integrity Advocate Collects and What It Deletes
Integrity Advocate collects only what is necessary to verify a learner's identity and confirm whether they followed the rules set by the organization running the assessment. Nothing more.
The approach is similar to how PayPal operates as an intermediary in a financial transaction, protecting both parties without either side needing to expose more than is required. Integrity Advocate sits between the organization and the test taker's personal data, sharing only what is needed and only when there is a documented reason.
In practice, that means:
With the exception of a single identity photo, all recordings of the user and their desktop are deleted within 24 hours if no rule violations are found
When a session is flagged, only the minimum information required to document the concern is shared with the organization
As a Canadian company, Integrity Advocate operates outside US government jurisdiction. In the unlikely event of a compelled disclosure, the data available on the vast majority of users would be limited to a first and last name and a facial image represented as a string of code
Read the privacy policies of other proctoring providers and ask how many of them can say the same.
What to Look for Before Choosing a Proctoring Provider
Before signing a contract with any proctoring platform, your organization should be able to answer the following questions from their privacy policy and data processing documentation:
What personal information is collected, and is collection limited to what is necessary?
Is data sold, transferred, or shared with third parties beyond the assessment organization?
How long is data retained, and what triggers deletion?
Is the vendor subject to US government data requests, and what would they be required to disclose?
Is there a human review process, or are automated findings shared directly with the institution?
If the answers are not clearly documented, that is an answer in itself.
Balancing Assessment Security and Privacy Within Modern Online EdD Programs
May 22, 2026
|
5 min read
Online EdD programs face a growing tension: assessments must be secure, but doctoral learners expect their privacy to be respected. In this guest post, Research.com's Stephanie Dion explores how institutions can move beyond surveillance-heavy models toward verification-based systems, risk-based authentication, and faculty preparedness that protect both academic integrity and learner trust.
The rapid growth of doctoral-level education delivered through digital platforms has transformed how institutions design, deliver, and evaluate learning. While flexibility and accessibility have improved, new challenges have emerged around maintaining academic integrity without compromising learner privacy. Programs must now navigate a complex balance between safeguarding assessments and respecting personal data boundaries.
Modern online learning environments—especially within advanced doctoral pathways—require systems that are both secure and ethically designed. Achieving this balance is critical not only for institutional credibility but also for learner trust.
The Evolving Landscape of EdD Assessment Integrity
Doctoral programs have always emphasized rigorous evaluation standards. However, the shift to remote delivery has introduced new vulnerabilities, from identity fraud to unauthorized collaboration. Within an EdD context, where research-based outputs and professional practice are central, the stakes are even higher.
Institutions are increasingly turning to layered assessment strategies that combine human oversight with technological safeguards. Yet, implementing these systems without overstepping privacy expectations remains a nuanced challenge.
Key Risks in Modern Assessment Environments
Unverified identities can undermine the credibility of academic credentials, making it essential to confirm that enrolled learners are the ones completing assessments.
Over-surveillance can erode student trust and engagement, particularly when monitoring tools feel intrusive or disproportionate to the assessment type.
Data storage vulnerabilities increase institutional liability, especially when sensitive learner information is collected and retained unnecessarily.
Balancing these risks requires thoughtful system design and governance.
The Role of Digital Credential Verification Systems
One of the most effective approaches to maintaining integrity without excessive monitoring is the use of digital credential verification systems. These tools enable institutions to validate learner achievements and identities through secure, traceable methods.
Rather than relying solely on real-time surveillance, verification systems focus on verifying the authenticity of outcomes. This shift allows institutions to uphold standards while reducing reliance on invasive monitoring practices. Similar conversations around the importance of verified credentials and accountability are explored in Integrity Advocate’s article on the case for verified credentials in private security.
How Verification Systems Strengthen Trust
Blockchain-backed credentials create tamper-proof academic records, ensuring that qualifications remain verifiable over time without requiring constant oversight.
Decentralized identity frameworks give learners greater control over their data, allowing them to share only necessary information during verification processes.
Automated validation processes reduce administrative burden, enabling institutions to scale securely while maintaining accuracy.
Research Insight: Data, Trust, and Digital Education
Recent findings from the OECD highlight that trust in digital education systems is strongly correlated with transparency in data usage and governance. A 2023 report emphasizes that learners are more likely to engage fully when they understand how their data is collected, stored, and protected.
This insight reinforces the importance of designing systems that prioritize both security and transparency, particularly within online doctoral programs.
Designing Privacy-Conscious Assessment Frameworks
Creating secure yet respectful assessment environments requires a shift from surveillance-heavy models to privacy-conscious frameworks. Institutions must evaluate each tool and process through both a security and ethical lens, particularly when balancing the need for security with the responsibility of protecting learners and institutional reputation.
How to Build Balanced Assessment Systems
Adopt risk-based authentication methods that adjust security levels based on assessment type, ensuring that high-stakes exams receive stricter controls while lower-risk tasks remain less intrusive.
Limit data collection to essential information only to reduce exposure to privacy risks and align with global data protection regulations.
Provide clear communication about monitoring practices, helping learners understand what is being tracked and why.
Expert Tips for Implementation
Engage stakeholders, including students and faculty, in system design discussions, ensuring that solutions reflect real-world concerns and expectations.
Regularly audit assessment technologies for compliance and effectiveness, identifying opportunities to improve privacy without weakening security.
Integrate ethical guidelines into institutional policies to create a consistent framework for decision-making across departments.
Financial and Sociological Considerations
Over-investment in intrusive monitoring tools can lead to diminishing returns, as student resistance may reduce engagement and performance.
Transparent systems can improve retention rates, as learners feel more confident in the program’s fairness and integrity.
Efficient processes reduce administrative costs, allowing institutions to allocate resources toward teaching and research.
These considerations highlight the need for balanced, sustainable solutions.
Online Proctoring: Finding the Middle Ground
Remote assessment monitoring remains a critical component of many programs, but it must be implemented thoughtfully. Online proctoring technologies can provide valuable oversight when used appropriately, yet they often raise concerns about privacy and data usage.
Institutions are now exploring hybrid models that combine automated monitoring with human review, reducing reliance on invasive techniques. Recent findings discussed in AI and online exams: what the data reveals about assessment security further highlight how institutions are adopting smarter, risk-based approaches to digital assessment monitoring.
For a deeper look into how monitoring technologies are evolving, the discussion on online proctoring offers valuable industry insights.
Best Practices for Ethical Proctoring
Use AI-driven monitoring selectively to flag anomalies rather than continuously surveil learners, allowing human evaluators to make final decisions.
Offer alternative assessment formats where possible, such as open-book exams or project-based evaluations that reduce the need for strict monitoring.
Ensure compliance with regional data protection laws, protecting both institutions and learners from legal risks.
Why is faculty preparedness essential for secure online EdD assessments?
Technology alone cannot ensure assessment integrity within modern doctoral education. Faculty members and program administrators play a central role in creating ethical, secure, and privacy-conscious evaluation environments. Without proper training, even advanced assessment systems may be implemented inconsistently, increasing both security risks and learner concerns.
Online EdD programs often involve complex assignments such as research projects, reflective analysis, and applied leadership evaluations. These formats require instructors to understand not only digital assessment tools but also ethical data practices, accessibility considerations, and evolving academic integrity standards.
Institutions that invest in faculty preparedness can improve consistency across assessment processes while strengthening learner trust. Professional development initiatives frequently include training in secure assessment design, responsible use of proctoring technologies, and privacy-focused communication practices. As online doctoral education continues to expand, many academic leaders are also exploring accelerated pathways for advanced educational leadership training through resources such as the Research.com list of shortest online EdD programs, which highlights flexible options for professionals pursuing doctoral advancement.
Key benefits of faculty preparedness include:
More consistent implementation of assessment security policies
Improved communication regarding privacy and monitoring practices
Reduced misuse of intrusive technologies during evaluations
Stronger alignment between institutional ethics and assessment methods
Greater student confidence in the fairness of online learning environments
By prioritizing faculty readiness alongside technological safeguards, institutions can create more balanced online EdD programs that protect both academic integrity and learner privacy.
The Future of Digital Credential Verification Systems
As education continues to evolve, digital credential verification systems will play an increasingly central role in maintaining trust. These systems offer a scalable solution that aligns with both security requirements and privacy expectations.
Emerging technologies such as decentralized identity and zero-knowledge proofs are set to further enhance verification processes, allowing institutions to confirm authenticity without exposing sensitive data.
Decentralized verification models will reduce reliance on centralized databases, minimizing the risk of large-scale data breaches.
Integration with global credential networks will improve portability, enabling learners to share verified achievements across institutions and employers.
Advanced encryption techniques will strengthen data protection, ensuring long-term security for academic records.
These developments signal a shift toward more ethical and efficient systems.
Key Insights
Balancing security and privacy requires a shift from surveillance-heavy models to transparent, verification-based systems.
Thoughtful implementation of technology enhances both institutional credibility and learner trust.
Future-ready programs will integrate security seamlessly into design rather than treating it as an add-on.