September 21–23, 2026
Internal assessmentGuna Suite security controls review
An internal review of the proposed Student Support service and the shared application and cloud controls on which it depends, covering security, availability, and confidentiality.
- Prepared by
- Guna Solutions, using automated scanning and testing tools.
- Report
- Security Controls Report, version 2.0. This page summarizes the internal report for public review.
- Assurance level
- Internal assessment. It is not a SOC 2 report or an independent third-party security assessment, and expresses no auditor opinion.
What we reviewed
- Source code, dependency vulnerabilities, and potential exposed secrets.
- Automated access-control tests, including role restrictions and protected student safety records.
- Repository authentication, database connection protections, and sampled backup records.
What the review found
- No critical or high-severity dependency advisories in the patched source scan; moderate and low tooling advisories remained.
- The tested access-control suites passed. Secure two-factor authentication enforcement was verified for the GitHub organization.
- Private, encrypted database connections and successful sampled automated backups were observed.
Follow-up and limits
At the assessment date, production deployment of the runtime patches had not been verified. Restore exercises, complete production access and data-lifecycle verification, formal policy approvals, and periodic access reviews remained open. The review did not establish operating effectiveness over a period or production readiness for district data.