For your organisation’s review
Security and privacy at TEEI
How we manage data, operate our platforms and use AI across TEEI programmes. Access technical checks, processing information and documentation for your organisation’s review.
15 checks run on every visit · raw responses · commands to reproduce
theeducationalequalityinstitute.org · run on this visit · started 22:20:47 UTC
5 services · 8 web and email · 2 registers · 0 notes
System status and technical checks
Check service availability, web security headers, email authentication and organisational registration records. Each result includes a timestamp, the source response and a command to reproduce the check.
Website, TEEI Language, TEEI Mentorship and CSR Cockpit.
0 of 5Security headers, email authentication records and our published security contact.
0 of 8Registration details from Brønnøysund and the IRS.
0 of 2Security and operational policies
The policies TEEI operates under, from software releases and incident response to data protection, AI use, whistleblowing and volunteer screening. Each entry shows its owner, version and review date, and the policies it relies on.
OPS-001 Change Management PolicyPlatform Administrator v1.2 In force
Changes move through staging before promotion to versioned production deployments, with rollback procedures built into the release process.
Purpose, from the documentThis policy defines how changes to the CSR Cockpit platform are categorised, authorised, tested, deployed, traced, and rolled back. The goal is to keep production changes intentional, reviewable, tested, and reversible.
SectionsPurpose · Scope · Change Categories · Validation and Release Gates · Production Deployment Path · Approval Requirements by Change Type · Database Migration Process · Rollback Procedures · Rollback Drill Procedure · Traceability and Audit Trail · Roles and Responsibilities · Review Cadence · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 22 July 2026
- Next review
- 27 February 2027
IRP-001 Incident Response PlanPlatform Administrator v1.1 In force
Our incident response plan defines how we handle security and personal-data incidents, including responsibilities, escalation and external notifications.
Purpose, from the documentThis policy defines how TEEI detects, assesses, contains, recovers from, and learns from security incidents affecting CSR Cockpit. It is a control policy, not evidence that monitoring, an on-call rotation, a tabletop, or a notification has occurred.
SectionsPurpose And Approval Boundary · Scope · Severity · Roles · Response Phases · Personal-Data Breach Assessment · Communications · Evidence And Exercises · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 19 July 2026
- Next review
- 27 February 2027
BCP-001 Business Continuity PlanPlatform Administrator v1.2 In force
Our continuity plan sets out recovery procedures for the Cloudflare Workers services that support TEEI’s platforms.
Purpose, from the documentThis Business Continuity Plan (BCP) defines the recovery objectives, resilience architecture, backup strategy, recovery procedures, and communication protocols that keep the CSR Cockpit platform recoverable after planned maintenance, application defects, database incidents, or supporting-service outages.
SectionsPurpose · Scope · Recovery Objectives · Infrastructure Resilience · Backup Strategy · Recovery Procedures · Rollback Drill Procedure · BCP Test Schedule · Communication Plan During Outages · Roles and Responsibilities · Review Cadence · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 22 July 2026
- Next review
- 27 February 2027
PRIV-001 Data Retention PolicyPlatform Administrator v1.1 In force
Our retention policy defines how long CSR Cockpit records are kept, with requirements for different record types, consent events and partnership deliverables.
SectionsStatus And Authority · Scope · Current Executable Schedule · HRIS-synchronised employee records · Open Decisions And Reconciliation Gaps · Execution And Verification · Data Subject Requests · Backups And Providers · Evidence · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 19 July 2026
- Next review
- 27 February 2027
SEC-002 Penetration Testing CadencePlatform Administrator v1.1 In force
Our testing policy specifies annual independent web and API penetration testing, annual threat-model reviews and additional reviews following material architecture changes.
Purpose, from the documentThis policy defines when CSR Cockpit requires independent penetration testing, how scope is derived, and how findings are evidenced and remediated. Historical internal reports are not substitutes for a current external test of the Router Cloudflare Worker runtime.
SectionsPurpose · Current Scope Baseline · Cadence And Triggers · Engagement Controls · Required Coverage · Remediation · Evidence And Retention · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 19 July 2026
- Next review
- 27 February 2027
SEC-003 Security Awareness Training ProgrammePlatform Administrator v1.1 In force
Our security awareness programme defines training for the people who operate TEEI’s systems.
Purpose, from the documentThis document defines the security awareness training programme for all team members who develop, operate, or have administrative access to the CSR Cockpit platform. The programme ensures that personnel understand their security responsibilities, recognise common attack vectors, and follow secure practices when handling personal data and operating the platform.
SectionsPurpose · Scope · Training Structure · Annual Assessment and Certification · Training Records · Roles and Responsibilities · Review Cadence · Cross-References
- Owner
- Platform Administrator
- Applies to
- CSR Cockpit
- Effective
- 27 February 2026
- Last updated
- 19 July 2026
- Next review
- 27 February 2027
SEC-001 Information Security PolicyExecutive Director v1.0 In force
Purpose, from the documentThe Educational Equality Institute, TEEI, protects the confidentiality, integrity and availability of information entrusted to it. This policy establishes the organisation-wide requirements for managing information-security risk across TEEI programmes, the public website, the shared platform and CSR Cockpit. It is the umbrella policy for the information-security policy family.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-004 Access Control and Identity PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy ensures that only authorised people and approved services can access TEEI information and systems. Identity and access controls protect participants, volunteers, partners, staff and TEEI operations from unauthorised access, accidental disclosure and avoidable privilege.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-005 Acceptable Use PolicyExecutive Director v1.0 In force
Purpose, from the documentThis policy sets the conditions for using TEEI systems, accounts, information and communications. It supports a safe and reliable remote working environment while respecting the responsibilities TEEI has to participants, volunteers, partners and colleagues.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-006 Secure Development PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy establishes security requirements for software, infrastructure configuration, scripts and integrations developed or changed for TEEI. Secure development reduces the likelihood that a change exposes information, weakens safeguards or disrupts a service used by participants, volunteers, partners or colleagues.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-007 Logging and Monitoring PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy establishes requirements for recording and reviewing security-relevant activity. Appropriate logging and monitoring helps TEEI detect failures, investigate suspected incidents, protect the availability of services and account for administrative activity without collecting more information than is necessary.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-008 Encryption and Key Management PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy protects TEEI information, credentials and cryptographic material against unauthorised disclosure, modification and use. Encryption and sound key management are required controls for the remote, cloud-based systems that TEEI uses to deliver its programmes and administrative services.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-009 Vulnerability and Patch Management PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy requires TEEI to identify, assess, prioritise and remediate security vulnerabilities in its systems, dependencies, configurations and approved services. Prompt and proportionate patch management reduces the likelihood that known weaknesses harm participants, volunteers, partners, information or service availability.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-010 Backup and Recovery PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy requires TEEI to maintain recoverable copies of information and system components needed to restore services after accidental deletion, corruption, service failure, security incident or other disruption. Backups support continuity of the public website, programme platforms, CSR Cockpit and administrative services, but they do not replace the continuity arrangements in BCP-001 or incident handling in IRP-001.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-011 Third-Party and Vendor Risk PolicyData Protection Lead v1.0 In force
Purpose, from the documentThis policy requires TEEI to assess and manage security, privacy, continuity and transfer risks arising from third-party services. Suppliers are important to TEEI's remote, cloud-based operations, but their use does not transfer TEEI's responsibility to protect information and make proportionate decisions.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
SEC-012 Endpoint and Device PolicyPlatform Administrator v1.0 In force
Purpose, from the documentThis policy sets minimum security requirements for devices used to access TEEI systems or information. TEEI works through a fully remote and asynchronous team. Endpoints therefore form an important boundary between TEEI accounts, participant information, programme operations and the environments in which people work.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
PRIV-002 Data Protection PolicyData Protection Lead v1.0 In force
Purpose, from the documentThis policy sets the organisation-wide requirements for personal-data processing by The Educational Equality Institute (TEEI). It supports lawful, fair and transparent treatment of people whose data TEEI handles, including participants, volunteers, donors, team members and partner employees. It applies alongside the GDPR, the Norwegian Personal Data Act, applicable US charity obligations, and the public Privacy Policy.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
PRIV-003 Data Classification and Handling PolicyData Protection Lead v1.0 In force
Purpose, from the documentThis policy defines how TEEI classifies information and how each class must be handled. Its purpose is to make the protection needed by a record clear before it is collected, stored, shared or disposed of. Classification is based on the sensitivity of the information, the people it concerns and the harm that could result from misuse, loss or inappropriate disclosure.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
- Owner
- Data Protection Lead
- Applies to
- TEEI-wide
- Effective
- 1 December 2025
- Last updated
- 16 September 2026
- Next review
- 1 December 2026
- Related
- PRIV-001PRIV-002PRIV-005PRIV-007Safeguarding Policy
PRIV-004 Data Protection Impact Assessment ProcedureData Protection Lead v1.0 In force
Purpose, from the documentThis procedure ensures that TEEI identifies and addresses high risks to people before starting or materially changing processing that is likely to affect their rights and freedoms. A data protection impact assessment, or DPIA, is a documented assessment of necessity, proportionality, risks and safeguards. It supports informed decisions; it does not replace the ordinary requirements in PRIV-002.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
PRIV-005 Personal Data Breach ProcedureData Protection Lead v1.0 In force
Purpose, from the documentThis procedure defines how TEEI identifies, contains, assesses, records and notifies personal-data breaches. It is designed to protect people and to support TEEI's legal duties. It supplements IRP-001, which governs the technical incident response. It does not replace safeguarding escalation requirements where a breach also creates a safeguarding concern.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
- Owner
- Data Protection Lead
- Applies to
- TEEI-wide
- Effective
- 1 December 2025
- Last updated
- 16 September 2026
- Next review
- 1 December 2026
- Related
- IRP-001PRIV-002PRIV-003PRIV-006Safeguarding Policy
PRIV-006 Data Subject Rights ProcedureData Protection Lead v1.0 In force
Purpose, from the documentThis procedure sets out how TEEI receives, verifies, assesses, fulfils and records requests from people exercising rights over their personal data. It supports the rights of access, rectification, erasure, restriction, portability and objection under applicable data-protection law. It also supports fair, secure and consistent handling when TEEI must limit or refuse a request under a lawful exemption.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
- Owner
- Data Protection Lead
- Applies to
- TEEI-wide
- Effective
- 1 December 2025
- Last updated
- 16 September 2026
- Next review
- 1 December 2026
- Related
- PRIV-002PRIV-003PRIV-005PRIV-007Privacy Policy
PRIV-007 Organisation-wide Records Retention PolicyData Protection Lead v1.0 In force
Purpose, from the documentThis policy sets the organisation-wide retention requirements for TEEI records. It extends PRIV-001, which applies to CSR Cockpit, to the other TEEI programmes, public website and internal functions. TEEI retains records only for defined purposes and then deletes or anonymises them unless a lawful retention duty, legal hold, safeguarding need or active investigation requires continued retention.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
AI-001 Responsible AI Use PolicyExecutive Director v1.0 In force
Purpose, from the documentThis policy sets the requirements for responsible use of artificial intelligence by The Educational Equality Institute (TEEI). TEEI uses AI only for defined support tasks, with human responsibility for decisions and appropriate protection for people and their data. This policy applies to AI features used in programmes, public services, CSR Cockpit, administration and software development.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-001 Code of ConductExecutive Director v1.0 In force
Purpose, from the documentThis policy sets the conduct requirements for people acting for The Educational Equality Institute (TEEI). It protects participants, colleagues and organisational resources by making expectations and accountability explicit. It must be read with the policies identified above; it does not replace their specialist reporting or decision procedures.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-002 Whistleblowing PolicyBoard of Directors v1.0 In force
Purpose, from the documentThis policy enables people to report suspected wrongdoing connected with The Educational Equality Institute (TEEI) and requires protection from retaliation. It establishes independent handling and accountable records. It also supports accurate answers to governance questions in IRS Form 990. This draft must not be represented as an adopted policy or evidence that its requirements already operate.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-003 Conflict of Interest PolicyBoard of Directors v1.0 In force
Purpose, from the documentThis policy requires decisions for The Educational Equality Institute (TEEI) to serve its charitable purposes rather than private interests. It provides practical requirements for the duty of loyalty in the Norwegian association and the conflict policy required by Article VIII of the US bylaws. It supports accurate reporting of policy adoption, disclosure and monitoring in IRS Form 990 Part VI without treating a written draft as evidence of implementation.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-004 Document Retention and Destruction PolicyExecutive Director v1.0 In force
Purpose, from the documentThis policy governs the retention and authorised destruction of organisational records of The Educational Equality Institute (TEEI). It requires records to support governance, financial accountability, legal obligations and defensible decisions. It addresses the organisational policy considered in IRS Form 990. Personal-data retention requirements are governed by PRIV-007; PRIV-001 retains its specific CSR Cockpit scope.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-005 Anti-Harassment and Equal Opportunity PolicyExecutive Director v1.0 In force
Purpose, from the documentThis policy requires fair access to opportunities and prohibits harassment, discrimination and retaliation in The Educational Equality Institute (TEEI). It sets requirements for prevention, reporting, investigation and outcomes. It supports the non-discrimination commitment in Article XII of the US bylaws without claiming that one jurisdiction's employment rules apply identically to every contributor.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
GOV-006 Volunteer Screening and Vetting PolicyProgramme Lead v1.0 In force
Purpose, from the documentThis policy sets requirements for selecting, approving and supervising volunteers for The Educational Equality Institute (TEEI). Screening must support safe and appropriate role assignments while respecting applicants' rights. It must not be represented as a guarantee of future conduct or complete knowledge of an applicant's history.
SectionsPurpose · Scope · Policy · Roles and responsibilities · Procedures · Exceptions · Enforcement · Review
Public Safeguarding PolicyOn this site Public
Safe environments. No exceptions. Applies to all TEEI activities regardless of location, including in-person events, online interactions, and communications through any channel.
- Applies to
- Everyone TEEI works with
- Effective
- December 2025
Public Privacy PolicyOn this site Public
Minimal data. Never sold. What personal data we collect, why we collect it, and how we protect it.
- Applies to
- Everyone TEEI works with
- Effective
- December 2025
Public Cookie PolicyOn this site Public
Few cookies. Off by default. Which cookies the site sets, what they do, and how to change your choice.
- Applies to
- Everyone TEEI works with
- Effective
- 7 July 2026
Public Accessibility StatementOn this site Public
Accessible by design. The platforms TEEI uses to deliver its programmes, and how we keep them usable for everyone.
- Applies to
- Everyone TEEI works with
- Effective
- December 2025
Public How We WorkOn this site Public
Fully remote. Async-first. Contributors across 50+ countries. No office, no fixed hours - just meaningful work in education, mentoring, and language access.
- Applies to
- Everyone TEEI works with
Public Vulnerability Disclosure PolicyOn this site Public
Scope, what we ask of researchers, what we do with a report, and how to send one.
- Applies to
- Everyone TEEI works with
Data storage and processing
Records live in Ireland. AI, video and captions for TEEI Language and Mentorship run in AWS EU regions. Email, analytics, report drafting and transcription run in the United States. Every provider is in the register below.
- 1Meeting control, errors, translation · Germany
- 2Records, AI, video · Ireland, AWS eu-west-1
- 3Email, analytics, reports, transcription · United States
- 4Registered office · Oslo
- 5Registered office · New York
The sub-processor register lists every provider that processes personal data for TEEI: purpose, processing location and transfer basis, reconciled against the code on 2026-09-16.
View the sub-processor register
Turso (libSQL)
Amazon Bedrock
Amazon Chime SDK
Amazon Transcribe
AWS Lambda and S3
Sentry
DeepL
Cloudflare
Resend
Sinch (Mailjet)
Google Gemini API
Google Workspace APIs
Google Analytics 4 and Ads
PostHog
Hotjar
WorkOS
Microsoft
FundraiseUp
OpenAI Whisper
Coursera
AI use and human review
TEEI uses AI for application review, chat safeguarding, live captions, translation, report drafting and transcription. Each use, its provider and where it runs is listed here.
Amazon Bedrock · EU
volunteer applications→Amazon Bedrock, EU→structured first assessment→a person reviews and approves
TEEI Language and Mentorship use Amazon Bedrock to produce a structured first assessment of volunteer applications. A person reviews the assessment and makes the approval decision.
Learner admissions follow programme eligibility rules.
Amazon Bedrock · EU
group-chat messages→Amazon Bedrock, EU→safeguarding flag→a person reviews flagged messages
Messages in programme group chats are screened for safeguarding concerns. Flagged messages go to a person; nothing is removed or acted on by the model alone.
Amazon Transcribe · EU
spoken audio in a session→Amazon Transcribe, EU→captions on screen
Shared video sessions can show live captions. The transcript is produced in the EU and shown to the participants in the session.
DeepL · Germany
WBP chat message→DeepL, Germany→translated message
WBP translates buddy and participant chat messages with DeepL. Google Gemini is the fallback when DeepL does not answer.
Google Gemini · United States
recorded programme data→Google Gemini, United States→impact reports and case studies→dedicated review and approval step
CSR Cockpit uses Google Gemini to draft impact reports and case studies from recorded programme data. The reporting workflow includes a dedicated review and approval step.
OpenAI Whisper · United States
uploaded voice and interview recordings→OpenAI Whisper, United States→transcript
CSR Cockpit uses OpenAI Whisper to transcribe uploaded voice and interview recordings.
Documentation for your review
Access our published privacy information or request documentation for your legal, data protection and security teams.
For vendor questionnaires and document requests, contact partnerships@theeducationalequalityinstitute.org.
Request documentationContacts
- Security
- Report a security issue to security@theeducationalequalityinstitute.org. Our published
security.txtprovides the security contact details.- Scope
theeducationalequalityinstitute.org and its subdomains, including
language.,mentorship.andcockpit. - We ask
Test only with accounts you own. Do not access, change or keep other people’s data. No denial of service and no social engineering.
- We do
We confirm receipt by email, keep you informed while we fix the issue, and take no legal action against research that stays within this scope and these rules.
- Report
Send the affected URL, the steps to reproduce and any proof to the address above.
- Scope
- Partnership reviews
- Contact partnerships@theeducationalequalityinstitute.org for contracts, data processing documentation and questionnaires.
- Personal data requests
- Use our data request form to contact TEEI about your personal data.
security.txt · RFC 9116 · valid until 2027-05-09 · policy: /trust/#vulnerability-disclosure
Legal entities
Norway
The Educational Equality Institute
Organisation number 928 776 719
Registered, checked on this visit
United States
The Educational Equality Institute Inc.
501(c)(3) public charity · EIN 33-2331817
In the IRS Business Master File, checked on this visit