Skip to content
Pennant

Security & Trust

Written for the people who review vendors. The short version: Pennant is an analytics layer that never stores student PII, and the architecture — not a policy document — is what enforces that.

Get the printable one-pager for your IT review

Privacy by design

The no-PII architecture

Pennant's analytics run on pseudonymous CRM record IDs, dates, statuses, and attribution. Identity stays in your CRM, where it already lives. If a Pennant database were read in full, it would contain no student names, emails, phone numbers, or addresses — because none are ever ingested.

What Pennant stores

  • Pseudonymous CRM record IDs
  • Funnel stage dates and statuses
  • Source and attribution fields
  • Campaign and spend data from ad platforms
  • Campus, program, and channel dimensions

What Pennant never stores

  • Student names
  • Email addresses
  • Phone numbers
  • Mailing addresses
  • Any other student contact or identity data

Platform controls

Access, encryption, and accountability

Encryption at rest

Connector credentials are encrypted at rest with AES-256-GCM.

Role-based access control

Permissions are role-based, so users see only the institutions and functions appropriate to their role.

Full audit log

Administrative and data-affecting actions are recorded in a full audit log.

Per-tenant isolation

Each institution's data is isolated per tenant. Agencies see a portfolio rollup only across the tenants they manage.

Sync-health monitoring

Automated syncs are monitored continuously, with alerting when a connector needs attention.

Data lifecycle

Right to erasure and retention

Right to erasure. Erasure is built in, not a support ticket. When a record is erased, a re-import suppression ensures the same record does not return on the next sync from your CRM.

Retention. Data retention follows a documented retention policy.

Where identity lives. Because Pennant holds only pseudonymous record IDs, a subject's identity can only be resolved inside your CRM, under your existing controls.

Questions from your IT or privacy team?

Bring them to the demo — we're happy to walk through the architecture in whatever depth your reviewers need.