SECURITY AT ALMA LEARNING
Universities and organizations trust Alma Learning with their courses and their learners' data. Protecting that data is a core commitment, not an afterthought. This page describes the security practices we maintain and the commitments we make to our customers.
Last updated: July 2026
Compliance
Alma Learning is currently undergoing a SOC 2 Type II examination by an independent auditor, covering our security controls over time. We maintain FERPA-aligned practices for handling student education records on behalf of our institutional clients, and we support our clients' own compliance obligations. Upon completion, our SOC 2 report will be available to customers and prospects under NDA on request.
Where your data lives
The Alma platform is hosted in data centers located in the United States, operated by our cloud infrastructure provider, which maintains its own independent physical and environmental security controls and certifications. We serve US-based clients, and customer data is stored and processed in the United States.

Encryption
  • In transit: all traffic between users and the Alma platform is encrypted using TLS 1.2 or higher.
  • At rest: customer data is encrypted at rest using industry-standard encryption.
Access control
  • Multi-factor authentication and single sign-on are enforced for Alma Learning employees on production systems and key internal services.
  • Access to production systems and customer data is limited to authorized personnel who require it to perform their role, and access is revoked promptly when no longer needed.
  • Employees complete security awareness training.
What data we handle
Depending on the services an institution engages us for, Alma Learning may process: learner personal information (PII), education records covered by FERPA, grades and assessment results, LMS learning analytics, and video and voice recordings of instructors used to produce avatar-delivered lectures. We process this data solely to provide our services to the client institution — we do not sell customer or learner data, and we do not use it for advertising.
Data retention and deletion
  • Customer and learner data is retained for as long as required by applicable law and, at minimum, for the duration of the learner's enrollment in the relevant program.
  • Upon contract termination, we delete client data within the minimum timeframe permitted by applicable legal and record-keeping requirements.
  • Clients may direct the return of their data prior to deletion.
Incident response
We maintain a documented incident response plan covering detection, containment, remediation, and communication. In the event of a security incident affecting customer data, we will notify affected customers without undue delay and provide the information they need to meet their own notification obligations.
Secure development
Changes to the Alma platform go through code review before release, development and production environments are separated, and we monitor our dependencies for known vulnerabilities and apply patches in a timely manner.
Subprocessors
We use a limited set of vetted service providers to deliver our services. Subprocessors that may process customer or learner data include:
  • Cloud infrastructure provider — hosting (US data centers)
  • OpenAI — AI language models powering learning experiences
  • Google (Gemini) — AI language models powering learning experiences
  • Mistral — AI language models powering learning experiences
  • Soniox — speech recognition
  • Lemonslice — avatar video generation
We will update this list as our subprocessors change.
Reporting a vulnerability
If you believe you have found a security vulnerability in an Alma Learning product or website, please report it to hello@almalearning.ai. We will acknowledge your report, investigate, and keep you informed. We ask that you give us a reasonable opportunity to remediate before public disclosure.
Our commitment to you
The practices on this page are commitments we make to our customers. We will notify customers promptly of any material changes to these commitments, and the current version of this page, with its revision date, will always be available here.
Questions
For security questionnaires, documentation requests (including our SOC 2 report upon completion), or any other security questions, contact hello@almalearning.ai.
Made on
Tilda