Trust & Compliance Center

Built for schools.
Compliant by design.

District-procurement-ready. Download the signed DPA and Security One-Pager, review the full subprocessor list, security architecture, and SOC 2 status. Everything documented. Nothing to hide.

✓ COPPA-Aligned ✓ FERPA-Compliant ✓ US Data Residency ⚙ SOC 2 Roadmap GDPR-K Considerations Documented
⬇ Jump to Documents

Download for your records

Both documents are current as of the date you download them. Every download is logged for audit trail (see subprocessor table). For a countersigned copy, email trust@cyberheroeshq.com.

📋

Data Processing Agreement (DPA)

FERPA school-official exception framing, COPPA authorization mechanism, data categories, retention schedule, deletion workflow, security commitments, and the full subprocessor list — suitable for district legal review.

Last updated
2026-07-15
Audit
Logged for procurement
🔒

Security One-Pager

Auth model, encryption in transit & at rest, data residency, access controls, incident-response SLA, backup & recovery objectives, and vulnerability-disclosure policy — for district IT and CISO review.

Last updated
2026-07-15
Audit
Logged for procurement

Accessibility (WCAG 2.1 AA)

Full conformance statement covering every role dashboard and the mission gameplay SPA. Scope, methodology, screen-reader pass results, and out-of-scope vendors — for Section 508 / IDEA-driven district reviews.

Audit date
2026-07-19
Conformance
WCAG 2.1 AA
Routes audited
51
✓ WCAG 2.1 AA · 51 routes audited
SOC 2 readiness control inventory: ⬇ SOC 2 Readiness Control Inventory (PDF) · CC 0% · A 0% · C 0%
Need a custom security questionnaire? Email security@cyberheroeshq.com with your format (HECVAT, SIG, custom). We aim to respond within 5 business days.
📦 One-click Procurement Pack Download a single ZIP containing the DPA, Security One-Pager, Subprocessor List, Insurance Summary, and a W-9 template — ready to forward to procurement and legal. ⬇ Download Procurement Pack (ZIP)

Independent assurance — current status

Type 1
Pre-engagement
A Type 1 report attests to the design of our controls at a point in time. Our readiness control inventory is published at the bottom of this section so districts can audit which Trust Services Criteria we will be attesting. Engagement letter, target dates, and audit firm are kept current here.
Type 2
Pending Type 1
A Type 2 report covers operating effectiveness over a 6–12 month window. We do not start Type 2 work until Type 1 is delivered so districts see a clean operational baseline.
Auditor
Selection in progress
We have not engaged an auditor yet. Districts that require a controls attestation narrative today can request one from security@cyberheroeshq.com.
Status
Scoping
Readiness by TSC: CC 0% · A 0% · C 0%. 0 open remediations.
Districts respect honesty over theater. We will not claim SOC 2 status we do not yet have. This page is the source of truth — when the report lands, it will be linked here first.

Frameworks we operate against

Independent certifications appear with the certifying body's name and are linked where available. Pending items are marked honestly with the target date.

FERPA 34 CFR § 99.31
COPPA 16 CFR § 312.5
SOPIPA California SB-1177
SOPPA Illinois 105 ILCS 85
CSDPA Colorado HB 16-1423
SOC 2 Type 1 — Pre-engagement
Common Sense Privacy Evaluation in progress
iKeepSafe Application pending

How we keep student data safe

The same controls listed in our Security One-Pager, summarized here for quick procurement review. For the full one-pager, see the Security PDF.

🔐

Encryption in transit

TLS 1.2+ enforced on every public endpoint. HSTS preloaded. No weak ciphers permitted.

🗄️

Encryption at rest

AES-256 on all database storage. Backups encrypted with rotating keys.

🔑

Authentication

bcrypt (cost ≥ 12) for all credentials. Session cookies are HttpOnly, Secure, SameSite=Lax. Role-based access control on every route.

💾

Backup cadence

Daily encrypted backups with 35-day retention. Point-in-time recovery available. Backups stored in a separate region.

🚨

Incident response SLA

24-hour notification for confirmed breaches affecting customer data. Full postmortem published within 72 hours.

🛡️

Pen-test cadence

Annual third-party penetration test against the production platform. Findings tracked to remediation in our public Hall of Fame.

📧

Coordinated vulnerability disclosure

Researchers: report findings to security@cyberheroeshq.com. Our policy (90-day SLA, safe harbor, no legal threat) is at /security.

Third-party vendors & data shared

Every subprocessor that touches student or teacher data. We will notify schools of any material change at least 30 days in advance. DPA on file ↔ a signed data-processing agreement is in place with the named vendor.

Subprocessor Purpose Data Category Region DPA on file
Render Application hosting & deployment Application code; request logs (IP, timestamp); no student PII in logs. 🇺🇸 US (Oregon) DPA on file
Neon PostgreSQL database hosting All platform data (encrypted at rest, AES-256). 🇺🇸 US-East (AWS) DPA on file
Postmark Transactional email (teacher & parent notifications) Teacher email, parent email (opt-in only), student hero username in subject lines only. 🇺🇸 US DPA on file
OpenAI AI mentor (Cipher follow-on, content generation) Session-scoped, anonymized prompt content. No PII forwarded — no name, email, or student ID. 🇺🇸 US DPA on file
Anthropic Fallback AI mentor (Cipher primary) Session-scoped, anonymized input only. No PII forwarded. Anthropic does not train on or store customer data under our DPA. 🇺🇸 US DPA on file
Stripe Payment processing (Family & District subscriptions) Billing email, payment card data (held by Stripe — never stored by us). No student data is shared. 🇺🇸 US DPA on file
Google OAuth (teacher & parent sign-in only) OAuth tokens for sign-in. No student data flows through Google — student accounts use teacher-provisioned codes. 🇺🇸 US Limited scope
Distribute further? We will notify districts at least 30 days before any new subprocessor starts processing customer data. Request a vendor security questionnaire via trust@cyberheroeshq.com.

Student Data Privacy Consortium (SDPC) & CSPA

CyberHeroesHQ aligns with the Student Data Privacy Consortium (SDPC) national standard contract clauses and the California Student Privacy Alliance (CSPA) framework. The clauses listed below are honored in our standard DPA.

1

Purpose limitation & data minimization

Processor uses Student Personal Information only to deliver the educational service described in the contract, and never for any other commercial purpose.

2

No third-party advertising / no profiling

No behavioral advertising, no cross-context tracking, no building of personal profiles for any purpose other than the named educational service.

3

Subprocessor notification & change control

30-day notice before a new subprocessor begins processing customer data. Subprocessors list is part of the DPA and refreshed at /trust#subprocessors.

4

Deletion on request, audit cooperation, indemnification

Hard purge within 30 days of written Controller request. Annual security-questionnaire responses and DPA-section review. Indemnification clauses in the standard DPA mirror SDPC national terms.

Cross-jurisdiction reciprocity: signed CSPA / SDPC states are recognized in our standard DPA. For a cross-jurisdiction clause table, email trust@cyberheroeshq.com.

How a student's data moves through the platform

Telemetry, anonymized before reaching AI vendors. All retention windows listed below are the maximum — shorter on account close or soft delete.

Student → HTTPS (TLS 1.2+)
Cloudflare edge · WAF + DDoS · 🇺🇸 US region TLS termination
Render app server · 🇺🇸 Oregon · route handlers + parameterized SQL only
Neon PostgreSQL · 🇺🇸 US-East (AWS) · AES-256 at rest · AWS KMS
AI mentor
Anonymized mission context → Anthropic (Claude) or OpenAI. No PII forwarded · 7-day session TTL · DPA forbids training.
Email
Transactional notifications → Postmark. No marketing email flows. 🇺🇸 US.
Payments
Billing → Stripe (PCI-DSS L1). No student data shared.
Active session
real-time only
Session record
7 days TTL after mission end
Student record
pilot term + 90-day export window

Encryption posture

Encryption covers data in transit, at rest, in backups, and in session cookies. Session and credential secrets are managed out-of-band of source control.

In transit

TLS 1.2+ enforced on every public endpoint. HSTS preloaded. HTTP requests 301-redirected to HTTPS automatically.

At rest

AES-256 on all database storage via AWS-managed KMS. Backups encrypted with rotating keys.

Credentials

bcrypt at cost ≥ 12. Session cookies are HttpOnly, Secure, SameSite=Lax.

Secrets

Session secrets and platform credentials managed as platform-injected env vars — never in source or version control.

Breach notification protocol

In the event of a confirmed security incident involving Student Personal Information, we notify our district and school customers via the security@cyberheroeshq.com contact chain.

72-hour notification SLA

Confirmed breaches involving Student Personal Information are reported to affected schools and districts within 72 hours of confirmed discovery, via the designated security contact (with copy to the district CIO/IT lead where on file). Notification includes the nature of the data exposed, the categories and approximate number of records affected, the likely consequences, the measures taken to contain, and the remediation timeline.

Retention & deletion policy

Three explicit timelines govern Student Personal Information. They are honored across primary, replica, and backup storage.

  • Active subscription: Data retained for the term of the subscription plus a 90-day export grace period. During that window the Controller may export via the Teacher Portal or the Family Dashboard.
  • 30-day soft delete (grace): After account closure or pilot end, data is soft-deleted for 30 days. During this window the Controller may restore the classroom with no questions asked.
  • Hard purge: All Student Personal Information purged from primary, replica, and backup storage within 30 days of a written Controller request or the end of the soft-delete window — whichever comes first. Confirmed by written acknowledgement from Processor.

What we collect — and what we don't

We collect the minimum necessary to run a classroom. No PII beyond classroom-assigned identifiers. No behavioral advertising. No third-party data sharing.

✓ What we collect

  • Hero username (chosen by student or teacher — never legal name)
  • Mission progress, quiz scores, XP earned, badges unlocked
  • Pre/post-assessment results (topic-level)
  • Classroom join code used (links student to teacher dashboard)
  • Session data: IP address + browser type (transient, not linked to identity)
  • Parent email (optional, only if teacher or student provides it for family reporting)

✕ What we never collect

  • Legal name, date of birth, or government ID
  • Physical location (GPS, precise address, or school address tied to student)
  • Biometric data of any kind
  • Behavioral advertising profiles or cross-context tracking
  • Health or disability information
  • Social Security number or financial data
🇺🇸

Data Residency: United States only

All student and teacher data is stored in US-based infrastructure (Neon PostgreSQL on AWS US-East, application hosting on Render Oregon). No data is transferred outside the United States.

COPPA compliance for parents

CyberHeroesHQ is designed for children ages 8–18. For under-13, COPPA requires verifiable parental consent before collecting information — obtained at family account creation via an explicit consent checkbox.

✓ Data we collect from children

  • Hero name (chosen by the child — no real name required)
  • Grade band (K-2, 3-5, 6-8, or 9-12)
  • Avatar selection
  • Mission progress, quiz scores, XP earned, and badges
  • AI mentor interactions with Cipher (anonymized, 7-day TTL)

✕ We never collect from children

  • Real name, date of birth, or government ID
  • Precise geolocation or school address
  • Biometric or health data
  • Social media or contact lists
  • Behavioral advertising profiles
Your parental rights (COPPA):

District & school responsibilities

CyberHeroesHQ operates as a school official under the FERPA school official exception (34 C.F.R. § 99.31(a)(1)). The school or district remains the data controller.

1

Teacher-managed accounts

All student accounts are created and managed by teachers through the Teacher Portal. Students join via classroom code (CYBER-XXXX format) issued by their teacher.

2

School as data controller

The school or district controls which students are enrolled, which classrooms exist, and when accounts are terminated. CyberHeroesHQ processes data only as directed.

3

COPPA parental consent

For under-13, schools act in loco parentis under the COPPA school authorization mechanism (16 C.F.R. § 312.5(b)(1)). By enrolling under-13 students, the school represents it has authority to consent.

4

Roster maintenance

Schools are responsible for removing students who should no longer have access. Deletion requests can be submitted at privacy@cyberheroeshq.com.

Questions procurement always asks

Answered directly, without weasel words.

Do you sell student data?
No. Revenue comes from school and family subscriptions — not data monetization.
Do you serve ads to students?
No. Zero advertising, no ad networks, no cross-site tracking.
Are AI mentors trained on student data?
No. The subprocessor DPAs forbid training on or retention of customer input. We forward anonymized mission context only.
SOC 2 — when?
Type 1 is targeted for Q4 2026; Type 2 for Q4 2027. Until then, we operate the same controls listed in our Security PDF — no independent report exists yet.
Security Review

Request a security review

For districts that need a deeper architectural conversation — bring your own questionnaire, your DPA template, or just an introductory call. We respond within 2 business days.

  • Walk-through of our security architecture with a Polsia engineer
  • Custom security questionnaire responses (HECVAT, SIG, internal formats)
  • Countersigned DPA wired to your template
  • Compliance crosswalk against your state's student-privacy law
  • Reference contacts from active district customers

Or email directly: compliance@cyberheroeshq.com

Request a security review

Request our full Trust Package

For districts that want the comprehensive bundle — a countersigned DPA, security questionnaire responses, compliance crosswalk, and reference contacts.