Last updated: August 27, 2026
Tiwaar Academy is a subsidiary of Tiwaar Inc., headquartered in the United States. This document provides an overview of the security policies, practices, and compliance posture of the Tiwaar Academy platform. It is provided to satisfy the security review requirements of integration partners including Zoom Video Communications, Inc.
Tiwaar Academy follows a defense-in-depth security approach. All platform data is transmitted over TLS-encrypted channels and stored encrypted at rest. Access to production systems is restricted to authorized personnel using role-based access controls (RBAC) and multi-factor authentication (MFA).
The platform is built on a managed cloud infrastructure that is SOC 2 Type II compliant. Authentication, authorization, and session management are handled by built-in security services that follow OWASP best practices.
Academy data is multi-tenant isolated — each academy's data is segregated using row-level security (RLS) policies enforced at the database layer. One academy cannot access another academy's student, course, or financial data under any circumstance.
Tiwaar Academy maintains a vulnerability management process that includes:
Data is retained for as long as an academy account is active. Academy owners may request export or deletion of their data at any time via support@tiwaar.com.
Full details are available in our Privacy Policy.
Tiwaar Academy follows a structured incident response process:
Tiwaar Academy is hosted on a managed cloud platform. Infrastructure management responsibilities are shared:
Tiwaar Academy's underlying infrastructure is SOC 2 Type II compliant. This covers the security, availability, and confidentiality trust service criteria. Tiwaar Academy inherits these controls as a tenant of the platform.
SOC 2 compliance is maintained by the infrastructure provider through annual third-party audits. Tiwaar Academy's application-level security controls (data isolation, OAuth token management, webhook verification) are designed to align with SOC 2 control objectives.
Tiwaar Academy is not currently ISO 27001 certified. However, our security practices are designed to align with ISO 27001 control objectives, including access control (A.9), cryptography (A.10), operations security (A.12), and information security incident management (A.16). We are evaluating formal ISO 27001 certification as part of our growth roadmap.
The Tiwaar Academy Zoom integration follows Zoom's security best practices:
meeting:write, meeting:read, and user:read.For security questions, vulnerability reports, or compliance documentation requests, contact us at support@tiwaar.com or through our contact form.
This document is provided for informational purposes and does not constitute a legal warranty. Tiwaar Inc. reserves the right to update its security practices at any time. © 2026 Tiwaar Inc.