Common questions about Degreed's security practices, infrastructure, and compliance posture.
Degreed's security team performs formal risk assessments by following its Risk Assessment and Treatment Policy and maintains a risk register for all findings in Jira.
Degreed manages vulnerabilities through its Vulnerability Management Policy, as well as annual third-party penetration tests, SAST and DAST scanners, and tracking high-risk findings to resolution using its Jira ticketing system.
The plan involves procedures for identifying, prioritizing, communicating, tracking, and resolving security incidents and includes periodic testing and post-mortem meetings for improvement.
By implementing full-disk encryption, DNS filtering, advanced Endpoint Detection & Response, Mobile Device Management, and regularly monitoring for threats.
Degreed uses third-party tools to detect and auto-update vulnerable software on employees' workstations and Azure servers.
Degreed follows an asset management policy, email protection with DMARC, annual security training for employees, background checks, incident response planning, Single Sign-On, and regular penetration testing.
Degreed's infrastructure is hosted by Azure in multiple regions including the United States, Europe, and Canada.
Degreed has a formal BC/DR plan, conducts annual backup restoration testing, and monitors uptime and availability.
Customer data is encrypted at-rest using AES-256 and encrypted in-transit using TLS 1.2.
Can't find what you need?
Submit a documentation request and our security team will respond within 2 business days.