Alethia

How Alethia handles applicant data.

Applicant files are among the most sensitive records a university holds. This page says what Alethia does with them, what it does not do, and what we will put in writing for your security review.

Our commitments

  • Used only to verifyAn applicant's data is used to verify that applicant's claims. It is not used to build profiles, train general models, or inform any other applicant's outcome.
  • The institution owns the recordVerification records belong to the institution. They can be exported in full and deleted on request.
  • Every check is loggedEach search, each outreach message, each reply, and each reader decision is written down with its time and its source. The log is part of the record you own.
  • Outreach is transparentReferences are told which institution is asking, on whose behalf, and why. Alethia contacts only the people the applicant listed and asks only about what the applicant claimed.
  • Humans can override anythingNo outcome is final until a reader accepts it. Overrides are recorded alongside the original finding.

What Alethia looks at, and what it leaves alone

Checked

  • Public records: competition results, registries, journal indexes, league archives, organization pages, published news.
  • Replies from references the applicant listed, after the sender is verified.
  • Documents the applicant or the institution chooses to provide.

Not touched

  • Private social media accounts and personal messages.
  • Protected characteristics, or any inference about them.
  • Anyone the applicant did not list as a reference.
  • Scoring, ranking, or predicting an applicant's success.

Compliance and controls

Items below are listed the way Alethia lists an applicant's claims: with their current status, not with a promise. Where a status reads to be confirmed, ask us and we will answer in writing.

ItemDetailStatus
SOC 2 Type IIIndependent audit of security, availability, and confidentiality controls.To be confirmed
FERPAHandling of education records on behalf of the institution as a school official.To be confirmed
Data residencyRegion in which applicant data is stored and processed.To be confirmed
RetentionHow long verification records are kept after a cycle closes, and how deletion is requested.To be confirmed
EncryptionData encrypted in transit and at rest.To be confirmed
Access reviewWho at Alethia can access institutional data, and how that access is logged and reviewed.To be confirmed
Statuses are maintained by Alethia and updated as audits complete.

Reporting a vulnerability

If you believe you have found a security issue in Alethia, write to[email protected]. We acknowledge reports and keep you informed until the issue is resolved.

Security review packet

Procurement questionnaires, architecture summaries, and data-flow diagrams are available on request for institutions evaluating Alethia.

Request the packet

Ask us the hard questions.

Security review is part of every university procurement. Send yours and we will answer each item in writing.