Security & Privacy One-Pager
Pennant is an enrollment marketing analytics layer for higher education. This page summarizes its security posture for IT and privacy reviewers. Architecture details: pennant — Security & Trust.
| Area | Posture |
|---|---|
| Student PII | Never stored. No names, emails, phone numbers, or addresses. Analytics run on pseudonymous CRM record IDs, funnel-stage dates, statuses, and attribution fields. |
| Data ingested | Pseudonymous CRM record IDs and funnel data via connectors (Salesforce incl. related objects, HubSpot, LeadSquared, Google Sheets); campaign and spend data from Google Ads (incl. agency MCC) and Meta Ads. Hourly automated syncs; historical backfills. |
| Encryption at rest | Connector credentials are encrypted at rest with AES-256-GCM. |
| Access control | Role-based permissions scope users to appropriate institutions and functions. |
| Audit logging | Full audit log of administrative and data-affecting actions. |
| Tenancy | Per-tenant isolation for each institution. Agency/portfolio rollups span only the tenants that organization manages. |
| Right to erasure | Built-in erasure with re-import suppression — an erased record does not return on subsequent CRM syncs. |
| Retention | Data retention follows a documented retention policy. |
| Monitoring | Sync-health monitoring with alerting on connector failures. |
The one-sentence summary
If a Pennant database were read in full, it would contain no student names, emails, phone numbers, or addresses — because none are ever ingested. Identity stays in your CRM, under your existing controls.
Questions for our team? Schedule a call — we'll walk through the architecture in whatever depth your review requires.