District-procurement-ready. Download the signed DPA and Security One-Pager,
review the full subprocessor list, security architecture, and SOC 2 status.
Everything documented. Nothing to hide.
✓ COPPA-Aligned✓ FERPA-Compliant✓ US Data Residency⚙ SOC 2 RoadmapGDPR-K Considerations Documented
Both documents are current as of the date you download them. Every download is logged
for audit trail (see subprocessor table). For a countersigned
copy, email trust@cyberheroeshq.com.
📋
Data Processing Agreement (DPA)
FERPA school-official exception framing, COPPA authorization mechanism, data categories,
retention schedule, deletion workflow, security commitments, and the full subprocessor list —
suitable for district legal review.
Auth model, encryption in transit & at rest, data residency, access controls,
incident-response SLA, backup & recovery objectives, and vulnerability-disclosure
policy — for district IT and CISO review.
Full conformance statement covering every role dashboard and the mission gameplay SPA.
Scope, methodology, screen-reader pass results, and out-of-scope vendors — for
Section 508 / IDEA-driven district reviews.
Need a custom security questionnaire?
Email security@cyberheroeshq.com
with your format (HECVAT, SIG, custom). We aim to respond within 5 business days.
📦 One-click Procurement PackDownload a single ZIP containing the DPA, Security One-Pager, Subprocessor List, Insurance Summary, and a W-9 template — ready to forward to procurement and legal.
⬇ Download Procurement Pack (ZIP)
SOC 2 Posture
Independent assurance — current status
Type 1
Pre-engagement
A Type 1 report attests to the design of our controls at a point in time.
Our readiness control inventory is published at the bottom of this section
so districts can audit which Trust Services Criteria we will be attesting.
Engagement letter, target dates, and audit firm are kept current here.
Type 2
Pending Type 1
A Type 2 report covers operating effectiveness over a 6–12 month window.
We do not start Type 2 work until Type 1 is delivered so districts see a
clean operational baseline.
Auditor
Selection in progress
We have not engaged an auditor yet. Districts that require a controls
attestation narrative today can request one from
security@cyberheroeshq.com.
Status
Scoping
Readiness by TSC: CC 0% ·
A 0% ·
C 0%.
0 open remediations.
Districts respect honesty over theater.
We will not claim SOC 2 status we do not yet have. This page is the source
of truth — when the report lands, it will be linked here first.
Compliance Posture
Frameworks we operate against
Independent certifications appear with the certifying body's name and are linked
where available. Pending items are marked honestly with the target date.
✓FERPA
34 CFR § 99.31
✓COPPA
16 CFR § 312.5
✓SOPIPA
California SB-1177
✓SOPPA
Illinois 105 ILCS 85
✓CSDPA
Colorado HB 16-1423
⏳SOC 2
Type 1 — Pre-engagement
⏳Common Sense Privacy
Evaluation in progress
⏳iKeepSafe
Application pending
Security Architecture
How we keep student data safe
The same controls listed in our Security One-Pager, summarized here for quick
procurement review. For the full one-pager, see the
Security PDF.
🔐
Encryption in transit
TLS 1.2+ enforced on every public endpoint. HSTS preloaded. No weak ciphers permitted.
🗄️
Encryption at rest
AES-256 on all database storage. Backups encrypted with rotating keys.
🔑
Authentication
bcrypt (cost ≥ 12) for all credentials. Session cookies are HttpOnly, Secure, SameSite=Lax. Role-based access control on every route.
💾
Backup cadence
Daily encrypted backups with 35-day retention. Point-in-time recovery available. Backups stored in a separate region.
🚨
Incident response SLA
24-hour notification for confirmed breaches affecting customer data. Full postmortem published within 72 hours.
🛡️
Pen-test cadence
Annual third-party penetration test against the production platform. Findings tracked to remediation in our public Hall of Fame.
Every subprocessor that touches student or teacher data. We will notify schools
of any material change at least 30 days in advance. DPA on file ↔ a
signed data-processing agreement is in place with the named vendor.
Subprocessor
Purpose
Data Category
Region
DPA on file
Render
Application hosting & deployment
Application code; request logs (IP, timestamp); no student PII in logs.
Session-scoped, anonymized prompt content. No PII forwarded — no name, email, or student ID.
🇺🇸 US
DPA on file
Anthropic
Fallback AI mentor (Cipher primary)
Session-scoped, anonymized input only. No PII forwarded. Anthropic does not train on or store customer data under our DPA.
🇺🇸 US
DPA on file
Stripe
Payment processing (Family & District subscriptions)
Billing email, payment card data (held by Stripe — never stored by us). No student data is shared.
🇺🇸 US
DPA on file
Google
OAuth (teacher & parent sign-in only)
OAuth tokens for sign-in. No student data flows through Google — student accounts use teacher-provisioned codes.
🇺🇸 US
Limited scope
Distribute further? We will notify districts at least 30 days before any new subprocessor
starts processing customer data. Request a vendor security questionnaire via
trust@cyberheroeshq.com.
SDPC Alignment
Student Data Privacy Consortium (SDPC) & CSPA
CyberHeroesHQ aligns with the Student Data Privacy Consortium (SDPC)
national standard contract clauses and the California Student Privacy
Alliance (CSPA) framework. The clauses listed below are honored in
our standard DPA.
1
Purpose limitation & data minimization
Processor uses Student Personal Information only to deliver the educational service described in the contract, and never for any other commercial purpose.
2
No third-party advertising / no profiling
No behavioral advertising, no cross-context tracking, no building of personal profiles for any purpose other than the named educational service.
3
Subprocessor notification & change control
30-day notice before a new subprocessor begins processing customer data. Subprocessors list is part of the DPA and refreshed at /trust#subprocessors.
4
Deletion on request, audit cooperation, indemnification
Hard purge within 30 days of written Controller request. Annual security-questionnaire responses and DPA-section review. Indemnification clauses in the standard DPA mirror SDPC national terms.
Cross-jurisdiction reciprocity: signed CSPA / SDPC states are recognized
in our standard DPA. For a cross-jurisdiction clause table, email
trust@cyberheroeshq.com.
Data Flow
How a student's data moves through the platform
Telemetry, anonymized before reaching AI vendors. All retention windows listed
below are the maximum — shorter on account close or soft delete.
Student → HTTPS (TLS 1.2+)
↓
Cloudflare edge · WAF + DDoS · 🇺🇸 US region TLS termination
↓
Render app server · 🇺🇸 Oregon · route handlers + parameterized SQL only
Anonymized mission context → Anthropic (Claude) or OpenAI. No PII forwarded · 7-day session TTL · DPA forbids training.
Email
Transactional notifications → Postmark. No marketing email flows. 🇺🇸 US.
Payments
Billing → Stripe (PCI-DSS L1). No student data shared.
Active session
real-time only
Session record
7 days TTL after mission end
Student record
pilot term + 90-day export window
Encryption
Encryption posture
Encryption covers data in transit, at rest, in backups, and in session cookies.
Session and credential secrets are managed out-of-band of source control.
In transit
TLS 1.2+ enforced on every public endpoint. HSTS preloaded. HTTP requests 301-redirected to HTTPS automatically.
At rest
AES-256 on all database storage via AWS-managed KMS. Backups encrypted with rotating keys.
Credentials
bcrypt at cost ≥ 12. Session cookies are HttpOnly, Secure, SameSite=Lax.
Secrets
Session secrets and platform credentials managed as platform-injected env vars — never in source or version control.
Incident Response
Breach notification protocol
In the event of a confirmed security incident involving Student Personal
Information, we notify our district and school customers via the
security@cyberheroeshq.com
contact chain.
72-hour notification SLA
Confirmed breaches involving Student Personal Information are reported to affected
schools and districts within 72 hours of confirmed discovery, via the
designated security contact (with copy to the district CIO/IT lead where on
file). Notification includes the nature of the data exposed, the categories
and approximate number of records affected, the likely consequences, the
measures taken to contain, and the remediation timeline.
Retention
Retention & deletion policy
Three explicit timelines govern Student Personal Information. They are honored
across primary, replica, and backup storage.
Active subscription: Data retained for the term of the subscription plus a 90-day export grace period. During that window the Controller may export via the Teacher Portal or the Family Dashboard.
30-day soft delete (grace): After account closure or pilot end, data is soft-deleted for 30 days. During this window the Controller may restore the classroom with no questions asked.
Hard purge: All Student Personal Information purged from primary, replica, and backup storage within 30 days of a written Controller request or the end of the soft-delete window — whichever comes first. Confirmed by written acknowledgement from Processor.
Student Data
What we collect — and what we don't
We collect the minimum necessary to run a classroom. No PII beyond classroom-assigned
identifiers. No behavioral advertising. No third-party data sharing.
✓ What we collect
Hero username (chosen by student or teacher — never legal name)
Mission progress, quiz scores, XP earned, badges unlocked
Pre/post-assessment results (topic-level)
Classroom join code used (links student to teacher dashboard)
Session data: IP address + browser type (transient, not linked to identity)
Parent email (optional, only if teacher or student provides it for family reporting)
✕ What we never collect
Legal name, date of birth, or government ID
Physical location (GPS, precise address, or school address tied to student)
Biometric data of any kind
Behavioral advertising profiles or cross-context tracking
Health or disability information
Social Security number or financial data
🇺🇸
Data Residency: United States only
All student and teacher data is stored in US-based infrastructure (Neon PostgreSQL on AWS US-East, application hosting on Render Oregon). No data is transferred outside the United States.
Family Plan — Children's Privacy
COPPA compliance for parents
CyberHeroesHQ is designed for children ages 8–18. For under-13, COPPA requires
verifiable parental consent before collecting information — obtained at family
account creation via an explicit consent checkbox.
✓ Data we collect from children
Hero name (chosen by the child — no real name required)
Grade band (K-2, 3-5, 6-8, or 9-12)
Avatar selection
Mission progress, quiz scores, XP earned, and badges
AI mentor interactions with Cipher (anonymized, 7-day TTL)
✕ We never collect from children
Real name, date of birth, or government ID
Precise geolocation or school address
Biometric or health data
Social media or contact lists
Behavioral advertising profiles
Your parental rights (COPPA):
View data: Download a JSON export of your child's data from the Family Dashboard
Delete data: Permanently delete all your child's data from the Family Dashboard
CyberHeroesHQ operates as a school official under the FERPA
school official exception (34 C.F.R. § 99.31(a)(1)). The school or district
remains the data controller.
1
Teacher-managed accounts
All student accounts are created and managed by teachers through the Teacher Portal. Students join via classroom code (CYBER-XXXX format) issued by their teacher.
2
School as data controller
The school or district controls which students are enrolled, which classrooms exist, and when accounts are terminated. CyberHeroesHQ processes data only as directed.
3
COPPA parental consent
For under-13, schools act in loco parentis under the COPPA school authorization mechanism (16 C.F.R. § 312.5(b)(1)). By enrolling under-13 students, the school represents it has authority to consent.
4
Roster maintenance
Schools are responsible for removing students who should no longer have access. Deletion requests can be submitted at privacy@cyberheroeshq.com.
FAQ
Questions procurement always asks
Answered directly, without weasel words.
Do you sell student data?
No. Revenue comes from school and family subscriptions — not data monetization.
Do you serve ads to students?
No. Zero advertising, no ad networks, no cross-site tracking.
Are AI mentors trained on student data?
No. The subprocessor DPAs forbid training on or retention of customer input. We forward anonymized mission context only.
SOC 2 — when?
Type 1 is targeted for Q4 2026; Type 2 for Q4 2027. Until then, we operate the same controls listed in our Security PDF — no independent report exists yet.
Security Review
Request a security review
For districts that need a deeper architectural conversation — bring your own
questionnaire, your DPA template, or just an introductory call. We respond
within 2 business days.
Walk-through of our security architecture with a Polsia engineer
For districts that want the comprehensive bundle — a countersigned DPA, security
questionnaire responses, compliance crosswalk, and reference contacts.