Encryption at rest + in transit
All databases encrypted at rest with AES-256. TLS 1.3 enforced on every connection; HSTS preloaded. Backups encrypted with separate per-region keys.
Loading…
Security at Koydo
Schools, families, and tutors trust Koydo with student data. Our security posture is published, audited, and updated continuously. Vulnerability reports get acknowledged within 24 hours; SOC 2 Type II completes Q2 2027.
All databases encrypted at rest with AES-256. TLS 1.3 enforced on every connection; HSTS preloaded. Backups encrypted with separate per-region keys.
Row-Level Security on every Supabase table. Staff access reviewed quarterly; SSO required for all staff accounts; MFA mandatory; just-in-time access requests audited.
Type I audit in flight Q3 2026; Type II observation window opens Q4 2026 → report Q2 2027. Current trust-services controls already mapped via Vanta.
Annual external pen-test by an OSCP-credentialed firm; remediation tracked publicly on the trust portal. Last test: Jan 2026; 0 critical, 2 high (both closed).
On-call rotation with 15-minute acknowledgment SLA. Public status page (status.koydo.app) updated within 30 minutes of incident detection. Post-mortem within 5 business days.
COPPA + FERPA + GDPR-K aligned. Verified background-screening badges required before minor-facing tutor bookings. Recording consent captured per-lesson; auto-purge at 90 days. Parent + admin can audit any session.
Report a vulnerability
security@koydo.app
PGP key
Available on the trust portal
Bug bounty
Hosted on HackerOne (private, by invitation)
Response SLA
Acknowledge in 24 hours. Triage in 72 hours.