Compliance & auditing
Where to find what you need when an auditor, insurer, or board member asks "show me how you're handling cybersecurity training."
What TSNC tracks for you
- Training completion โ every staff member, every assigned module, with timestamps
- Phishing simulation results โ campaign-by-campaign catch rates, click rates, report rates
- Admin activity log โ every modifying action by every admin, peer-reviewable
- Audit log โ security-sensitive admin actions (impersonation, data exports, offboarding, payouts), retained for the lifetime of the account
Pre-built compliance reports
Cybersecurity compliance report
A multi-page PDF (also available as JSON) suitable for a board meeting or insurance review. It scores your organization against the CISA Cybersecurity Performance Goals and the USCCB Charter items, with per-requirement evidence, which TSNC features are enabled, and recommendations. Generated on demand by a Principal or IT Admin.
FERPA alignment statement
Documents how TSNC handles student-related data. Useful when you need to demonstrate FERPA compliance for vendor reviews. We're not a primary student-data system, but we touch staff communications about students, so we maintain a clear statement of practices.
Per-staff training transcript
For HR purposes โ when a teacher needs to demonstrate completed cybersecurity training (often required for state professional development hours), TSNC generates a transcript with module names, completion dates, and certificate numbers.
Audit log access
The platform-wide audit log is a TSNC-team tool reviewed by our platform admins, not an org-admin self-service tab. For your own records, org admins (Principal or IT Admin) can export your organization's full data โ staff, targets, campaign detail, reported emails, invoices, seats, and your org's audit-log rows โ via the data export. If you need a specific security-event trail for an incident, email support@thoushaltnotclick.com.
What we're aligned with vs. certified for
We're honest about this distinction because vendor questionnaires often blur it.
- SOC 2: Planned. We're building toward Type II. Not yet certified โ don't claim it on a security questionnaire.
- FERPA: Aligned. We design with FERPA in mind. We're not a school of record so we don't hold "education records" in FERPA's technical sense.
- GDPR: Aligned. We support data subject access requests, deletion, and minimal collection.
- HIPAA: Not covered. We are not a Business Associate. Don't store ePHI in TSNC.
- Penetration testing: We've started running scans (currently via Intruder.io). Independent third-party pentest is planned.