Enterprise-grade security built for regulated industries.
TLS 1.2+ for all data in transit. AES-256-GCM field-level encryption at rest for student submissions, drafts, LISA tutoring interactions, and grading audit logs.
Role-based access control across Provider, Learner, and EnterpriseAdmin roles. TOTP-based multi-factor authentication with backup codes. Session tokens are hashed before storage, with account lockout after repeated failed logins. We don't currently offer SSO/SAML.
Student data is never sold and never used to train AI models. Data subject access, export, and deletion are available on request. GDPR- and CCPA-aligned data practices; see our Privacy Policy for the specific rights and mechanisms available to you.
FERPA compliant. COPPA compliant. SOC 2-aligned and HIPAA-aligned security policies in place; formal SOC 2 and HIPAA certification are not yet complete.
Every grading decision and administrative action is logged. Grading audit logs are hash-linked and field-encrypted, and exportable for institutional compliance review.
Hosted on Replit's autoscale infrastructure with a Neon serverless PostgreSQL database. Automatic backups. We have not yet completed a formal third-party penetration test or published an uptime SLA.
Found a vulnerability? Email privacy@helokn.com — reports are reviewed and addressed directly by the team building the product.
If a confirmed security incident affects your institution's data, we will notify your account's designated contact within 72 hours of confirming the incident, consistent with GDPR Article 33's notification window. Enterprise admins can review incident status for their institution from their compliance dashboard.
When an institution's contract with Helokn ends, all associated student data is scheduled for destruction within 30 days — consistent with the data-return-and-destruction requirements found in most state student-privacy laws (e.g. Ohio's 90-day standard, Colorado's contract-mandated destruction terms).