Trust Center
Security, privacy & compliance
Last updated: 2026-06-24
Eduspera is built so organisations can trust it with their learners’ data. This page summarises how we protect that data, who our sub-processors are, and the documents available for vendor assessment and procurement.
Data residency
Primary data — accounts, courses, progress and uploads — is stored in the European Union (Frankfurt, Germany). Where a sub-processor operates outside the EU/EEA, transfers are covered by a Data Processing Agreement and EU Standard Contractual Clauses (SCCs). See the sub-processors list below.
Security measures
| Area | Control |
|---|---|
| Encryption | TLS 1.2+ in transit everywhere; data encrypted at rest at the database and storage layer. |
| Tenant isolation | PostgreSQL Row Level Security on every table isolates each school’s data; cross-tenant access is only possible through audited, service-role admin paths. |
| Authentication | Hashed credentials, optional Google SSO, and email-based 2FA with 30-day device trust on the admin/creator zone. |
| Least privilege | The public client is read-only; all mutations go through server-side handlers with input validation. Service-role keys never reach the browser. |
| File access | Private uploads (e.g. submissions) are served via short-lived signed URLs, not public links. |
| Hardening | Rate limiting on authentication endpoints, secret management outside the codebase, and bot/abuse protection at the edge. |
Sub-processors
We use a small set of vetted providers to deliver the service. We update this list before adding or replacing a sub-processor that handles personal data.
| Sub-processor | Purpose | Region | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt, Germany | EU hosting; DPA |
| Bunny.net (Bunny Stream) | Video hosting, captions delivery, CDN | EU + global edge | DPA; SCCs |
| Cloudflare | DNS, CDN, TLS, WAF / bot protection | Global edge | DPA; SCCs |
| Emailit | Transactional & academy email delivery | EU | DPA |
| Stripe | Payments and billing | EU / US | DPA; SCCs; PCI-DSS |
| OpenAI | Speech-to-text (automatic captions) | US | DPA; SCCs; no training on our data |
| Optional sign-in (OAuth) and, with consent, Analytics | US | DPA; SCCs; consent-gated | |
| Hosting (self-managed, Coolify) | Application runtime | EU | EU data centre |
Data processing agreement (DPA)
A GDPR Article 28 Data Processing Agreement, including the sub-processor list and EU Standard Contractual Clauses, is available for signature on request. Email [email protected]. The data controller and contracting entity is Design Excellent Group SL (NIF B02759603), Calle Blanquerna 53, 07003 Palma de Mallorca, Spain.
Backups & resilience
- Continuous database backups with point-in-time recovery.
- Recovery objectives: RPO ≤ 24h, RTO ≤ 8h for a major incident (targets, kept under review as we formalise our SLA).
- Infrastructure is reproducible from version control and deploys through an automated pipeline.
Incident response
We maintain an incident-response process. In the event of a personal-data breach, we will notify affected controllers/customers without undue delay and, where required, within 72 hours of becoming aware, in line with GDPR Article 33.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to [email protected]. We will acknowledge your report, keep you updated, and we will not pursue or support legal action against good-faith research that respects user privacy and avoids service disruption.
Compliance & accessibility
- GDPR — EU data residency, DPA available, data-subject rights honoured (see Privacy Policy).
- Accessibility — WCAG 2.2 Level AA as a product requirement; see our Accessibility Conformance Report (VPAT/ACR).
- SOC 2 — on our roadmap; a formal programme will be initiated to support enterprise customers. We are happy to complete security questionnaires (e.g. CAIQ-Lite) in the meantime.
Higher education security questionnaire (HECVAT)
Universities assess vendors with the EDUCAUSE HECVAT. We publish the substance of our answers — hosting and data location, tenant isolation, encryption, backups, incident response, SSO and SCIM, audit logging, FERPA and attestations — so a security reviewer can qualify us before the questionnaire is ever sent. Where we do not meet an expectation yet, we say so.
HECVAT Lite is completed and available under NDA. See our full HECVAT answers, or email [email protected] from an institutional address and we will send the document together with the security one-pager. Institutions planning a pilot can start from the university pilot kit.
Documents
- Accessibility Conformance Report (ACR / VPAT) — published at /accessibility/conformance; WCAG 2.2 AA, EN 301 549 and Section 508, self-assessed, third-party audit in progress.
- Data Processing Agreement (DPA) — GDPR Article 28, with a FERPA “school official” clause for student records; on request at [email protected].
- HECVAT Lite — on request under NDA; public summary of the answers at /trust/hecvat.
- Security one-pager — a one-page summary of the controls on this page; on request.
Compliance documents
Everything below is generated from the product repository and re-issued with each release, so it is never older than the software it describes.
| Document | What it is |
|---|---|
| Accessibility Conformance Report (PDF) | ITI VPAT® 2.5 INT — WCAG 2.2 A/AA, EN 301 549 and Section 508. Report version 2.0, 2026-09-03, product version 0.1.0. Also readable at /accessibility/conformance. |
| Accessibility changelog | Every accessibility-relevant change shipped, with the WCAG success criteria it affects. |
| System status | Live checks of the application, database/authentication and video delivery; incident history once external monitoring has collected real data. |
| Retention & erasure | Learners and academies can export their data at any time (JSON, audit-logged). A deletion request is fulfilled by an automated erasure that anonymises the identity, removes uploaded files, preferences and accessibility declarations, revokes sessions and e-mails a receipt. Payment and invoice records are kept for 10 years (tax law) and enrollment/certificate records are kept so issued certificates stay verifiable — both with anonymised references. Audit logs are append-only with per-academy retention of 1–7 years (default 2), archived to a private bucket before purge. Details in the Data Classification & Handling Policy. |
| SOC 2 readiness | Policies are in place and published below; controls (change management through reviewed pull requests and CI, immutable audit log, 2FA-gated admin zone, encrypted secrets vault, vendor DPAs, EU hosting) are operating. A SOC 2 Type I audit is commissioned on contract with the first customer that requires it, followed by Type II after the observation period. |
Policies
- Access Control Policy — Who can reach production systems and customer data, how access is granted, verified and removed.
- Business Continuity & Disaster Recovery Policy — How the service keeps running or is restored after a major failure.
- Change Management Policy — How code and infrastructure changes are proposed, reviewed, tested and deployed.
- Data Classification & Handling Policy — What kinds of data we hold, how sensitive each is, and the handling rules that follow.
- Incident Response Policy — How security incidents and personal-data breaches are detected, handled and communicated.
- Vendor Management Policy — How we choose, contract with and review the providers that process customer data.
Contact
Security, privacy and data requests: [email protected]