Real World Careers

Security · CIO / ISSO

FedRAMP is not authorized. Here is the boundary anyway.

Commercial SaaS on Cloudflare. The buying agency decides whether its use is inside FedRAMP scope. This page is an architecture and control statement, not an ATO.

Authorization boundary

Public origin realworldcareers.com (Cloudflare Pages) plus APIs on Cloudflare Workers, D1, and R2 in ALA’s Cloudflare account. Checkout: Stripe. Transactional email: Mailgun. No agency-hosted component. No mobile app store binary in this SKU.

Data flow

  1. Agency admin sends roster CSV to ALA (work email).
  2. Participant opens HTTPS invite, answers 50 items in the browser.
  3. Worker scores the session; D1 stores credential, scores, and completion metadata.
  4. Participant and agency admin retrieve HTML reports and CSV export over HTTPS.
  5. Card data goes only to Stripe. ALA does not store PAN.

Subprocessors

VendorRoleData
Cloudflare, Inc.CDN, Workers, D1, R2, DNS, WAFSession, scores, roster emails, logs/IP at the edge
Stripe, Inc.PaymentPayer email and card (Stripe)
Mailgun (Sinch)Transactional emailInvite and notice addresses

Controls we operate

  • TLS in transit; HSTS on the public origin.
  • Permissions-Policy: no camera, microphone, or geolocation on public pages.
  • Admin access to Cloudflare and Stripe behind provider MFA. No participant passwords in this SKU (unique links).
  • Secrets kept in Worker secrets / vault — not in client HTML.
  • Backups: Cloudflare D1/R2 commercial durability; 7-day business snapshot process exists at company level.
  • Vulnerability testing: no current third-party pentest report to attach. Honest gap. Code and dependency review is internal.

What we do not claim

  • No FedRAMP authorization (Moderate in progress — not authorized).
  • No agency SSO/SAML/PIV in this SKU.
  • No continuous monitoring package equivalent to an authorized CSP.

Incident notification

On confirmed unauthorized access involving that agency’s roster or scores, ALA notifies the named agency contact within 72 hours by email and phone (1-317-751-5444). Security contact: team@advancedlearning.academy. After-hours: same number, voicemail to Carol Roberts office path.

FedRAMP 2026 scope. Agency risk acceptance remains with the agency.