Security at Classed

Effective September 10, 2026 · Classed Inc.

The short version: your school’s data lives in the United States on Google Cloud, encrypted in transit and at rest, and is reached only through your school’s own sign-in. We don’t sell it, we don’t advertise with it, and we never use it to train AI models. If you find a security problem, tell us at security@classedcampus.com — we treat researchers as partners, and this page says exactly what you can expect from us.

1.How we protect your school’s data

  • Hosting. The platform runs on Google Cloud in the United States. Databases are backed up automatically every day, and the infrastructure is defined as code so every change is reviewed and reversible.
  • Sign-in. Everyone signs in through their school’s own identity provider (single sign-on). Classed stores no passwords, and multi-factor authentication is enforced by the school’s identity provider under the school’s policy. Services talk to each other with short-lived signed tokens.
  • Encryption. All traffic uses TLS 1.2 or newer. Data at rest, including backups, is encrypted by default on Google Cloud.
  • Isolation and least privilege. Every request is scoped to the caller’s institution and role, so one school’s data is never reachable from another’s. Classed personnel access personal data only to operate or support the platform, under confidentiality obligations, and administrative actions are logged.
  • Safe releases. Changes move through development and staging environments before production, and services are deployed as immutable container images that can be rolled back to a previous release.
  • AI, carefully. AI features run on Google’s Vertex AI inside Classed’s own cloud project, in the United States. Your data is never used to train models, direct messages are never screened by AI, and no adverse action is taken against a person based solely on an AI output. See the Privacy Policy for the details.
  • If something goes wrong. We notify an affected school without undue delay, and within 72 hours of confirming a breach that affects its data, so it can inform its community as the law requires.

2.Our security program

Classed maintains a written security program organized around the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). The program was adopted in September 2026, is owned by our CTO, and is reviewed at least annually. It consists of twenty documents:

  1. Information Security Policy
  2. Access Control and Identity Standard
  3. Change Management and Release Policy
  4. Patch and Vulnerability Management Policy
  5. Secure Development Lifecycle Standard
  6. Incident Response Plan
  7. Business Continuity Plan
  8. Disaster Recovery Plan
  9. Data Classification, Retention, and Disposal Policy
  10. Third-Party and Subprocessor Management Policy
  11. Personnel Security (onboarding, offboarding, screening)
  12. Security Awareness and Training Program
  13. Logging, Monitoring, and Audit Standard
  14. Encryption and Key Management Standard
  15. Endpoint and Systems Management Standard
  16. AI Governance Policy
  17. Accessibility Policy and Roadmap
  18. Vulnerability Disclosure Policy
  19. Privacy Program and Data Subject Request Procedure
  20. Risk Management and Internal Audit Procedure

Where we are, honestly. Classed has not yet completed a third-party audit such as SOC 2. Our hosting provider, Google Cloud, holds SOC 1, 2, and 3 and ISO 27001 certifications covering the physical and infrastructure layers, and a SOC 2 readiness assessment is on our roadmap. Where a control in our program is planned rather than in place today, the documents say so.

3.For institutions

We don’t publish the full policy set here, because the operational detail in it belongs with the people responsible for your school’s security review rather than on the open web. Institutions and their assessors can request any of the following, and we provide them under the school’s agreement with us:

  • A completed HECVAT 4.1.6 (Higher Education Community Vendor Assessment Toolkit), full edition.
  • The security policy set listed above, with the record templates that show each policy in operation.
  • Architecture and data-flow documentation: the system overview, the sign-in and token flow, the roster-sync flow, and a per-category data inventory stating where each kind of data is stored and who can read it.
  • The subprocessor register with each provider’s attestations and data-processing terms. The current subprocessors are also listed in the Privacy Policy.
  • Our data-processing and FERPA disclosure packet, prepared to support the school’s data-processing agreement.

Institutions may also run their own vulnerability scans or penetration tests against our staging environment (preferred, with test accounts provided) or, at a mutually agreed time and scope, against production. Ask at security@classedcampus.com and we will propose a window within 5 business days.

4.Reporting a vulnerability

Classed welcomes reports of security vulnerabilities from researchers, customers, and users. This section is our vulnerability disclosure policy; a machine-readable pointer to it is published at /.well-known/security.txt and on every Classed web host.

In scope: everything under classedcampus.com (the web dashboards, the identity service, and the APIs), the Classed iOS and Android apps, and Classed source repositories.

Out of scope: denial-of-service testing, spam or social engineering of Classed or institution staff, physical attacks, findings that only affect third-party services (please report those to the vendor), and issues in a school’s own systems.

How to report. Email security@classedcampus.com with a description, steps to reproduce (requests, screenshots, or a proof of concept), the affected URL or app version, and the impact you believe it has. Please don’t open public issues or post details elsewhere before we have fixed the issue. We don’t currently offer a bug bounty, but we credit reporters who want it.

What we commit to:

StepCommitment
Acknowledge your reportWithin 2 business days
Triage and confirm severityWithin 10 business days, with an estimated fix timeline (critical: 7 days, high: 30 days, medium: 90 days)
Status updatesAt least every 30 days until resolved
Tell you when it is fixedWhen the fix is deployed
Coordinated disclosureWe ask for up to 90 days from your report before public disclosure, and will agree to earlier disclosure once the issue is fixed

5.Safe harbor

If you make a good-faith effort to follow this policy — avoid privacy violations, data destruction, and service disruption; access only the minimum data needed to demonstrate the issue and don’t retain it; and stop and report immediately if you encounter personal data — Classed will not pursue legal action against you and will not refer your research to law enforcement. Testing must use accounts you own or that Classed provides, never other people’s data.

Reports are handled under our Incident Response Plan and our Patch and Vulnerability Management Policy. If a report shows that a school’s data was exposed, that school is notified as described above.

6.Contact

Security reports and institution security reviews: security@classedcampus.com

Everything else: support@classedcampus.com