Security & Compliance

Enterprise-grade security built for regulated industries.

Encryption

TLS 1.2+ for all data in transit. AES-256-GCM field-level encryption at rest for student submissions, drafts, LISA tutoring interactions, and grading audit logs.

Authentication & Authorization

Role-based access control across Provider, Learner, and EnterpriseAdmin roles. TOTP-based multi-factor authentication with backup codes. Session tokens are hashed before storage, with account lockout after repeated failed logins. We don't currently offer SSO/SAML.

Data Privacy

Student data is never sold and never used to train AI models. Data subject access, export, and deletion are available on request. GDPR- and CCPA-aligned data practices; see our Privacy Policy for the specific rights and mechanisms available to you.

Compliance & Security Policies

FERPA compliant. COPPA compliant. SOC 2-aligned and HIPAA-aligned security policies in place; formal SOC 2 and HIPAA certification are not yet complete.

Audit Trails

Every grading decision and administrative action is logged. Grading audit logs are hash-linked and field-encrypted, and exportable for institutional compliance review.

Infrastructure

Hosted on Replit's autoscale infrastructure with a Neon serverless PostgreSQL database. Automatic backups. We have not yet completed a formal third-party penetration test or published an uptime SLA.

Reporting a Security Issue

Found a vulnerability? Email privacy@helokn.com — reports are reviewed and addressed directly by the team building the product.

Breach Notification

If a confirmed security incident affects your institution's data, we will notify your account's designated contact within 72 hours of confirming the incident, consistent with GDPR Article 33's notification window. Enterprise admins can review incident status for their institution from their compliance dashboard.

Data Destruction on Contract Termination

When an institution's contract with Helokn ends, all associated student data is scheduled for destruction within 30 days — consistent with the data-return-and-destruction requirements found in most state student-privacy laws (e.g. Ohio's 90-day standard, Colorado's contract-mandated destruction terms).