Working draft — pending attorney review and approval before launch.
Data Security Policy
Rise & Built Corp.
Effective: June 23, 2026
Rise & Built Corp. is committed to maintaining the confidentiality, integrity, and availability of information entrusted to us by users of our educational platform, software tools, educational programs, and related services. This Data Security Policy describes the administrative, technical, and organizational safeguards implemented to protect personal information and user-submitted materials.
1. Purpose
- Protect personal information and user-uploaded documents
- Reduce cybersecurity risks and prevent unauthorized access
- Establish security responsibilities
- Support legal and regulatory compliance
- Promote responsible handling of sensitive information
2. Scope
This Policy applies to all employees, contractors, consultants, vendors, service providers, administrators, and systems used to deliver Rise & Built services and all data processed through the Company's systems.
3. Security Principles
Confidentiality: Information should only be accessible to authorized persons.
Integrity: Information should remain accurate and protected from unauthorized modification.
Availability: Systems should remain available to authorized users whenever reasonably possible.
Least Privilege: Access rights limited to what is necessary to perform assigned responsibilities.
4. Access Control
Access to systems and information is restricted based on business need. Authorized personnel receive only the minimum access necessary.
Access privileges may be revoked immediately upon termination of employment, termination of contractor relationships, security concerns, or policy violations.
5. User Document Access
User-uploaded documents may contain sensitive financial information. Access to uploaded materials is limited to authorized personnel where reasonably necessary for: technical support; troubleshooting; cybersecurity; fraud prevention; platform maintenance; legal compliance.
Personnel are prohibited from accessing documents for the purpose of providing individualized credit repair recommendations.
All personnel with access to sensitive information must maintain confidentiality.
6. Authentication Requirements
The Company seeks to implement reasonable authentication controls including: unique user accounts; strong password requirements; secure credential management; session controls; multi-factor authentication for administrative users where feasible.
7. Encryption
Data in Transit: Sensitive information transmitted using encrypted communication protocols such as TLS/HTTPS.
Data at Rest: Sensitive information stored using commercially reasonable encryption mechanisms where feasible.
No encryption method can guarantee absolute security.
8. Logging and Monitoring
The Company may maintain logs relating to: account access; administrative actions; authentication events; platform activity; system performance; security events.
Logs may be reviewed for troubleshooting, security monitoring, fraud prevention, and compliance purposes.
9. Incident Response
The Company maintains procedures intended to address suspected security incidents including: investigation; containment; remediation; recovery; notification where required by law.
10. Data Breach Response
If the Company determines that a security incident has resulted in unauthorized access to protected information, the Company may investigate the incident, assess affected information, notify affected individuals where required, notify regulators where required, and implement corrective measures in accordance with applicable law.
11. No Absolute Security Guarantee
While Rise & Built implements reasonable safeguards, no system can guarantee complete security. Internet communications involve inherent risks; cyber threats continuously evolve; unauthorized access may occur despite safeguards.
12. Contact Information
Security Questions: security@riseandbuilt.com
Privacy Questions: privacy@riseandbuilt.com
General Support: support@riseandbuilt.com
By using the Services, you acknowledge that you have read, understood, and agreed to this Data Security Policy.