How we secure student data.
Defense in depth, in plain English.
Encryption
Data is encrypted at rest with AES-256 and in transit using TLS 1.3.
Access control
Coursim employee access to production data is restricted to a need-to-know basis, logged, and reviewed quarterly. All production access requires hardware MFA (YubiKey). No Coursim employee can read a student's free-text response without an audit trail.
Infrastructure
We run on AWS (us-east-1, us-west-2, eu-west-1) with full redundancy. Our infrastructure is provisioned via Terraform; every change is code-reviewed. We achieve 99.95% uptime on a rolling 12-month basis.
Incident response
We maintain a 24/7 on-call rotation for security incidents. Any suspected breach of student data triggers an immediate incident, notification to affected customers within 24 hours, and full post-mortem within 7 days.
Employee security
Every Coursim employee completes annual security training, passes a background check, and signs a data handling agreement. We use device management on all company-issued hardware.
Certifications
We maintain SOC 2 Type II, with our most recent audit completed February 2026 by A-LIGN. The full report is available to customers under NDA. We also participate in the Student Privacy Pledge and are iKeepSafe COPPA-certified.
Want the full security packet?
20 minutes with our security lead. They'll walk you through the SOC 2 report, our DPA, pen-test results, and the incident runbook – in plain English, on camera.