Privacy and security
This work asks leaders to be truthful about hard things. The technology exists to protect that honesty. Here is exactly how your reflections are kept private, who can see what, and the safeguards in place for every person who uses this portfolio.
Our four promises
Your reflections, journals, and 360 are visible only to you and the coach you are paired with. No one browses your work.
This is a mirror, not a scorecard. Nothing you write is used in performance evaluation, hiring, or compliance. Ever.
Everything is encrypted in transit and at rest. Access requires authentication, and every entry is tied to your account alone.
You own your portfolio. Export it or delete it at any time, and it leaves with you when the Institute ends.
Who can see what
| Your data | You | Your coach | CFR facilitators |
|---|---|---|---|
| I AM, Racial Autobiography, Cycle of Socialization | Full | If you share | No |
| Journal entries and intersession commitments | Full | If you share | No |
| Compass check-ins | Full | Trend only | No |
| WSC and Anti-Blackness 360 results | Full | If you share | No |
| Your name and identity | Full | Full | No |
| Cohort patterns, no names | No | No | Aggregate |
Full means you see everything. If you share means visible to your coach only when you choose to. Aggregate means pooled patterns across the cohort, with no individual identified. No means not visible.
How Fortress protects it
Row-level security the database itself enforces that a record can only be read by its owner and authorized coach.
Authentication on every request no public endpoints; identity is checked at the door and at the data layer.
Anonymity by default facilitator and intelligence views see pooled, de-identified patterns, never an individual’s words.
Audit logging every access to sensitive data is recorded, so we can always answer who saw what, and when.
FERPA-aligned posture no student information is collected; the portfolio holds adult professional reflection only.
Export and delete on request your data rights are built in, not bolted on.
The intelligence layer reads only what you share and only to give you back insight, never to grade you.
No data sold, ever there is no advertising, no third-party data sharing, no secondary use.
Independently audited every release
Every version passes a security audit before it ships.
Before any release reaches participants, the build is run through a deep automated security review (gstack /cso) that probes the data-export and personal-information paths specifically. A release does not go live until that audit is clean.
Last audited June 2026: no critical findings, and row-level security verified on every table that holds a reflection.
What this means for you
For participants
For the CFR facilitation team