Skip to main content

Trust Center

Security, privacy & compliance

Last updated: 2026-06-24

Eduspera is built so organisations can trust it with their learners’ data. This page summarises how we protect that data, who our sub-processors are, and the documents available for vendor assessment and procurement.

Data residency

Primary data — accounts, courses, progress and uploads — is stored in the European Union (Frankfurt, Germany). Where a sub-processor operates outside the EU/EEA, transfers are covered by a Data Processing Agreement and EU Standard Contractual Clauses (SCCs). See the sub-processors list below.

Security measures

AreaControl
EncryptionTLS 1.2+ in transit everywhere; data encrypted at rest at the database and storage layer.
Tenant isolationPostgreSQL Row Level Security on every table isolates each school’s data; cross-tenant access is only possible through audited, service-role admin paths.
AuthenticationHashed credentials, optional Google SSO, and email-based 2FA with 30-day device trust on the admin/creator zone.
Least privilegeThe public client is read-only; all mutations go through server-side handlers with input validation. Service-role keys never reach the browser.
File accessPrivate uploads (e.g. submissions) are served via short-lived signed URLs, not public links.
HardeningRate limiting on authentication endpoints, secret management outside the codebase, and bot/abuse protection at the edge.

Sub-processors

We use a small set of vetted providers to deliver the service. We update this list before adding or replacing a sub-processor that handles personal data.

Sub-processorPurposeRegionSafeguard
SupabaseDatabase, authentication, file storageEU — Frankfurt, GermanyEU hosting; DPA
Bunny.net (Bunny Stream)Video hosting, captions delivery, CDNEU + global edgeDPA; SCCs
CloudflareDNS, CDN, TLS, WAF / bot protectionGlobal edgeDPA; SCCs
EmailitTransactional & academy email deliveryEUDPA
StripePayments and billingEU / USDPA; SCCs; PCI-DSS
OpenAISpeech-to-text (automatic captions)USDPA; SCCs; no training on our data
GoogleOptional sign-in (OAuth) and, with consent, AnalyticsUSDPA; SCCs; consent-gated
Hosting (self-managed, Coolify)Application runtimeEUEU data centre

Data processing agreement (DPA)

A GDPR Article 28 Data Processing Agreement, including the sub-processor list and EU Standard Contractual Clauses, is available for signature on request. Email [email protected]. The data controller and contracting entity is Design Excellent Group SL (NIF B02759603), Calle Blanquerna 53, 07003 Palma de Mallorca, Spain.

Backups & resilience

  • Continuous database backups with point-in-time recovery.
  • Recovery objectives: RPO ≤ 24h, RTO ≤ 8h for a major incident (targets, kept under review as we formalise our SLA).
  • Infrastructure is reproducible from version control and deploys through an automated pipeline.

Incident response

We maintain an incident-response process. In the event of a personal-data breach, we will notify affected controllers/customers without undue delay and, where required, within 72 hours of becoming aware, in line with GDPR Article 33.

Responsible disclosure

If you believe you have found a security vulnerability, please report it to [email protected]. We will acknowledge your report, keep you updated, and we will not pursue or support legal action against good-faith research that respects user privacy and avoids service disruption.

Compliance & accessibility

  • GDPR — EU data residency, DPA available, data-subject rights honoured (see Privacy Policy).
  • Accessibility — WCAG 2.2 Level AA as a product requirement; see our Accessibility Conformance Report (VPAT/ACR).
  • SOC 2 — on our roadmap; a formal programme will be initiated to support enterprise customers. We are happy to complete security questionnaires (e.g. CAIQ-Lite) in the meantime.

Higher education security questionnaire (HECVAT)

Universities assess vendors with the EDUCAUSE HECVAT. We publish the substance of our answers — hosting and data location, tenant isolation, encryption, backups, incident response, SSO and SCIM, audit logging, FERPA and attestations — so a security reviewer can qualify us before the questionnaire is ever sent. Where we do not meet an expectation yet, we say so.

HECVAT Lite is completed and available under NDA. See our full HECVAT answers, or email [email protected] from an institutional address and we will send the document together with the security one-pager. Institutions planning a pilot can start from the university pilot kit.

Documents

  • Accessibility Conformance Report (ACR / VPAT) — published at /accessibility/conformance; WCAG 2.2 AA, EN 301 549 and Section 508, self-assessed, third-party audit in progress.
  • Data Processing Agreement (DPA) — GDPR Article 28, with a FERPA “school official” clause for student records; on request at [email protected].
  • HECVAT Lite — on request under NDA; public summary of the answers at /trust/hecvat.
  • Security one-pager — a one-page summary of the controls on this page; on request.

Compliance documents

Everything below is generated from the product repository and re-issued with each release, so it is never older than the software it describes.

DocumentWhat it is
Accessibility Conformance Report (PDF)ITI VPAT® 2.5 INT — WCAG 2.2 A/AA, EN 301 549 and Section 508. Report version 2.0, 2026-09-03, product version 0.1.0. Also readable at /accessibility/conformance.
Accessibility changelogEvery accessibility-relevant change shipped, with the WCAG success criteria it affects.
System statusLive checks of the application, database/authentication and video delivery; incident history once external monitoring has collected real data.
Retention & erasureLearners and academies can export their data at any time (JSON, audit-logged). A deletion request is fulfilled by an automated erasure that anonymises the identity, removes uploaded files, preferences and accessibility declarations, revokes sessions and e-mails a receipt. Payment and invoice records are kept for 10 years (tax law) and enrollment/certificate records are kept so issued certificates stay verifiable — both with anonymised references. Audit logs are append-only with per-academy retention of 1–7 years (default 2), archived to a private bucket before purge. Details in the Data Classification & Handling Policy.
SOC 2 readinessPolicies are in place and published below; controls (change management through reviewed pull requests and CI, immutable audit log, 2FA-gated admin zone, encrypted secrets vault, vendor DPAs, EU hosting) are operating. A SOC 2 Type I audit is commissioned on contract with the first customer that requires it, followed by Type II after the observation period.

Policies

Contact

Security, privacy and data requests: [email protected]