CUelevate public information
ElevateU Vendor Security & Due Diligence Overview
Last Reviewed September 6, 2026
Provider and contact
Provider: CUelevate LLC
Product: ElevateU
Vendor/security contact: training@cuelevate.com
Service description
ElevateU is a business-to-business employee training and professional-development platform. It is not a core processor, a financial transaction processor for a credit union, a member-facing financial service, or a provider operating a credit union’s critical financial systems. Each credit union determines its own vendor classification and risk assessment.
Systems not accessed in normal operation
The current ElevateU implementation has no integration with, credentialed access to, or normal operational need for a customer’s core processing, online or mobile banking, lending, account-opening, member databases, general ledger, internal network, employee workstations, internal identity infrastructure, member credentials, or privileged credit-union system credentials.
Member information
ElevateU does not require or intentionally collect member information. Customer organizations and users should not submit actual member information to ElevateU. The Platform is not intended to collect member account numbers, Social Security numbers, balances, transaction histories, loan data, credit reports, member credentials, or member financial records. Training scenarios use simulated information.
Organization information
ElevateU uses organization name and business information; tax ID where needed for tax administration; tax-exemption documentation where applicable; billing and order information; payment status; seat quantities; and related administrative records.
Authorized-user and training information
ElevateU uses authorized-user name, business email, organization and role relationship (such as learner, manager, or Organization Admin), manager relationship where needed, enrollment and activation information, course progress, assessment and completion information, certificate records, and authentication, security, and audit records.
ElevateU does not need employee Social Security numbers, dates of birth, home addresses, personal phone numbers, salary, personnel files, benefits data, disciplinary information, or detailed job titles to operate the Platform.
Payments
ElevateU uses an established third-party payment processor for its approved ACH payment flow. CUelevate does not store customer bank-login credentials. Sensitive banking and payment-authorization information is handled within the payment processor’s environment. ElevateU retains business records needed to administer a transaction, including order and payment status, transaction references, amounts, and related payment events.
Implemented security controls
ElevateU uses role-based access controls, privileged-access authentication, session controls, audit logging, protected administrative workflows, request protections, and controlled private-document delivery. Access is scoped to the relevant organization and role. CUelevate applies security controls appropriate to the Platform’s implemented service boundaries.
This overview is not a SOC report, independent security certification, or certification of any particular control framework.
Business continuity context
An interruption of ElevateU could delay employee training. It would not itself prevent a credit union from processing member transactions, accessing member accounts, lending, accepting deposits, processing payments, operating its core system, providing online or mobile banking, opening or operating the credit union, or performing other core financial functions.
Support responsibilities
Learners with verification-email delivery problems should contact their organization’s IT department. Learners with training questions should contact their manager. Managers and Organization Admins may use training@cuelevate.com as appropriate. Organization Admins also have an admin-only phone-support option inside the Platform. ElevateU does not provide a general public or direct learner telephone help desk.
Third-party service categories and additional due diligence
CUelevate uses established third-party service providers for application hosting, storage, payment processing, email delivery, and related platform services. Specific provider information and supporting due-diligence materials may be made available to qualified prospective or current customer organizations upon request and subject to appropriate review or confidentiality controls.
Depending on the request and materials maintained for the service, nonpublic information may include provider or service information, security questionnaires, architecture information, insurance documentation, contracts or service information, independent reports or certifications if they exist, and other due-diligence evidence. CUelevate does not represent that every requested record exists or will be provided. Where a requested record is not maintained for this service and risk profile, the response may be Not Applicable, Outside the scope of the service, or Not maintained for this service/risk profile.
Security incidents
CUelevate investigates suspected incidents affecting ElevateU, takes reasonable containment and correction steps, and notifies affected organizations when appropriate or legally required.
Customer responsibilities
Customer organizations are responsible for maintaining accurate authorized-user information, managing employee access, maintaining the security of their email environment and endpoints, assigning appropriate managers and Organization Admins, avoiding unnecessary member or confidential information in the Platform, and notifying CUelevate of suspected unauthorized ElevateU access.
Important limitations
This document assists with vendor due diligence only. It does not determine a credit union’s vendor-risk classification, is not an NCUA approval, is not a SOC report, is not an independent security certification, is not legal advice, and does not create obligations beyond applicable agreements.
