Security at Classed
Effective September 10, 2026 · Classed Inc.
The short version: your school’s data lives in the United States on Google Cloud, encrypted in transit and at rest, and is reached only through your school’s own sign-in. We don’t sell it, we don’t advertise with it, and we never use it to train AI models. If you find a security problem, tell us at security@classedcampus.com — we treat researchers as partners, and this page says exactly what you can expect from us.
1.How we protect your school’s data
- Hosting. The platform runs on Google Cloud in the United States. Databases are backed up automatically every day, and the infrastructure is defined as code so every change is reviewed and reversible.
- Sign-in. Everyone signs in through their school’s own identity provider (single sign-on). Classed stores no passwords, and multi-factor authentication is enforced by the school’s identity provider under the school’s policy. Services talk to each other with short-lived signed tokens.
- Encryption. All traffic uses TLS 1.2 or newer. Data at rest, including backups, is encrypted by default on Google Cloud.
- Isolation and least privilege. Every request is scoped to the caller’s institution and role, so one school’s data is never reachable from another’s. Classed personnel access personal data only to operate or support the platform, under confidentiality obligations, and administrative actions are logged.
- Safe releases. Changes move through development and staging environments before production, and services are deployed as immutable container images that can be rolled back to a previous release.
- AI, carefully. AI features run on Google’s Vertex AI inside Classed’s own cloud project, in the United States. Your data is never used to train models, direct messages are never screened by AI, and no adverse action is taken against a person based solely on an AI output. See the Privacy Policy for the details.
- If something goes wrong. We notify an affected school without undue delay, and within 72 hours of confirming a breach that affects its data, so it can inform its community as the law requires.
2.Our security program
Classed maintains a written security program organized around the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). The program was adopted in September 2026, is owned by our CTO, and is reviewed at least annually. It consists of twenty documents:
- Information Security Policy
- Access Control and Identity Standard
- Change Management and Release Policy
- Patch and Vulnerability Management Policy
- Secure Development Lifecycle Standard
- Incident Response Plan
- Business Continuity Plan
- Disaster Recovery Plan
- Data Classification, Retention, and Disposal Policy
- Third-Party and Subprocessor Management Policy
- Personnel Security (onboarding, offboarding, screening)
- Security Awareness and Training Program
- Logging, Monitoring, and Audit Standard
- Encryption and Key Management Standard
- Endpoint and Systems Management Standard
- AI Governance Policy
- Accessibility Policy and Roadmap
- Vulnerability Disclosure Policy
- Privacy Program and Data Subject Request Procedure
- Risk Management and Internal Audit Procedure
Where we are, honestly. Classed has not yet completed a third-party audit such as SOC 2. Our hosting provider, Google Cloud, holds SOC 1, 2, and 3 and ISO 27001 certifications covering the physical and infrastructure layers, and a SOC 2 readiness assessment is on our roadmap. Where a control in our program is planned rather than in place today, the documents say so.
3.For institutions
We don’t publish the full policy set here, because the operational detail in it belongs with the people responsible for your school’s security review rather than on the open web. Institutions and their assessors can request any of the following, and we provide them under the school’s agreement with us:
- A completed HECVAT 4.1.6 (Higher Education Community Vendor Assessment Toolkit), full edition.
- The security policy set listed above, with the record templates that show each policy in operation.
- Architecture and data-flow documentation: the system overview, the sign-in and token flow, the roster-sync flow, and a per-category data inventory stating where each kind of data is stored and who can read it.
- The subprocessor register with each provider’s attestations and data-processing terms. The current subprocessors are also listed in the Privacy Policy.
- Our data-processing and FERPA disclosure packet, prepared to support the school’s data-processing agreement.
Institutions may also run their own vulnerability scans or penetration tests against our staging environment (preferred, with test accounts provided) or, at a mutually agreed time and scope, against production. Ask at security@classedcampus.com and we will propose a window within 5 business days.
4.Reporting a vulnerability
Classed welcomes reports of security vulnerabilities from researchers, customers, and users. This section is our vulnerability disclosure policy; a machine-readable pointer to it is published at /.well-known/security.txt and on every Classed web host.
In scope: everything under classedcampus.com (the web dashboards, the identity service, and the APIs), the Classed iOS and Android apps, and Classed source repositories.
Out of scope: denial-of-service testing, spam or social engineering of Classed or institution staff, physical attacks, findings that only affect third-party services (please report those to the vendor), and issues in a school’s own systems.
How to report. Email security@classedcampus.com with a description, steps to reproduce (requests, screenshots, or a proof of concept), the affected URL or app version, and the impact you believe it has. Please don’t open public issues or post details elsewhere before we have fixed the issue. We don’t currently offer a bug bounty, but we credit reporters who want it.
What we commit to:
| Step | Commitment |
|---|---|
| Acknowledge your report | Within 2 business days |
| Triage and confirm severity | Within 10 business days, with an estimated fix timeline (critical: 7 days, high: 30 days, medium: 90 days) |
| Status updates | At least every 30 days until resolved |
| Tell you when it is fixed | When the fix is deployed |
| Coordinated disclosure | We ask for up to 90 days from your report before public disclosure, and will agree to earlier disclosure once the issue is fixed |
5.Safe harbor
If you make a good-faith effort to follow this policy — avoid privacy violations, data destruction, and service disruption; access only the minimum data needed to demonstrate the issue and don’t retain it; and stop and report immediately if you encounter personal data — Classed will not pursue legal action against you and will not refer your research to law enforcement. Testing must use accounts you own or that Classed provides, never other people’s data.
Reports are handled under our Incident Response Plan and our Patch and Vulnerability Management Policy. If a report shows that a school’s data was exposed, that school is notified as described above.
6.Contact
Security reports and institution security reviews: security@classedcampus.com
Everything else: support@classedcampus.com