Skip to main content

Trust & Security

Schools and districts trust KANU with student data. This page describes how we protect it, how the platform is built and monitored, and what documentation we can provide for your security review. For anything not covered here, contact support@kanu.us.

Platform Availability

KANU targets 99.5% monthly uptime for the core platform.

Planned maintenance is scheduled during off-peak hours, typically between 12:00 AM and 4:00 AM U.S. Eastern Time, and communicated in advance where possible.

Privacy & Student Data

What we collect

KANU collects the minimum data necessary to operate the platform:

  • Name and email address
  • Basic usage and activity data (progress, completions, and activity within the platform)
  • For students who create a storefront, a business location
  • Audio submitted for voice-enabled features, and its transcription
  • Payout details, for students who receive payments through the platform
  • Device identifiers and usage data, for push notifications and app functionality

KANU does not collect Social Security numbers, health information, demographic information, or biometric data.

How accounts are created

Accounts are created through an invite hierarchy. A school administrator invites educators; educators invite their students. Students on the self-serve free path create their own accounts directly.

Where data lives

All institutional and student data is stored in the United States on Amazon Web Services infrastructure. Data is not transferred outside the United States.

Data access and portability

Institutions retain ownership of their data. Administrators can export a CSV of their students at any time from kanu.us. Following the end of a contract, institutional data remains accessible within KANU for 30 days unless otherwise specified in the data handling agreement.

No sale of data

KANU does not sell student data. KANU does not use student data to build advertising profiles or share it with advertising networks or data brokers.

FERPA & COPPA

KANU is built to support your district's obligations under FERPA and COPPA.

When a school or district uses KANU, KANU operates under FERPA's 'school official' exception — student data is accessed only to deliver the educational service, under the school's direction and control, and is not used for unrelated purposes.

For students under 13 accessing KANU through their school, KANU relies on the school-consent model recognized by the FTC, in which the school acts on behalf of parents to authorize use of the platform as part of instruction.

KANU will sign a district or state student data privacy agreement on request.

Security Practices

Encryption in transit
All traffic is transmitted over HTTPS/TLS.
Encrypted backups
Backups are encrypted using AES-256, at rest and in transit.
Access control
Role-based access control separates student, educator, administrator, and internal functions.
Administrator MFA
Multi-factor authentication (TOTP) is required for all administrative accounts accessing production systems.
Audit logging
Access logs capture login, logout, actions performed, and source IP, and are retained for a minimum of 90 days.
High availability
The platform is deployed across multiple AWS availability zones with load balancing and automated failover.
Backups
Automated backups run hourly, daily, and weekly with tiered retention.
Payment data
KANU does not store cardholder data. All payment information is tokenized and handled by Braintree.
Incident response
KANU maintains a documented incident response plan. Affected institutions are notified without unreasonable delay, and no later than 72 hours after confirmation of a breach.
Secure development
Code changes are peer-reviewed, tested in a staging environment, and subject to static analysis before release.
Infrastructure attestations
KANU's infrastructure providers, AWS and MongoDB Atlas, maintain SOC 2 Type 2 attestations.

Subprocessors

KANU uses the following subprocessors to deliver the platform. This list is reviewed periodically and updated as our vendor relationships change.

Amazon Web Services (AWS)

Purpose
Cloud hosting and infrastructure
Data involved
All platform data

MongoDB Atlas

Purpose
Primary database and backups
Data involved
Platform data, including account and activity data

SendGrid

Purpose
Transactional email (invitations, notifications)
Data involved
Name, email address

Braintree (a PayPal service)

Purpose
Payment processing
Data involved
Tokenized payment data; KANU does not store cardholder data

Amazon SES (AWS)

Purpose
Transactional email (invitations, notifications)
Data involved
Name, email address

Trolley

Purpose
Student payout processing
Data involved
Name, email address, and payout details for students who receive payouts

TaxCloud

Purpose
Sales tax calculation
Data involved
Order and location data

Google Maps Platform

Purpose
Address lookup and mapping
Data involved
Location and address data

Amazon Transcribe (AWS)

Purpose
Speech-to-text for audio features
Data involved
Student-submitted audio and its transcription

Sentry

Purpose
Application error and performance monitoring
Data involved
Error and diagnostic data, which may include account identifiers

Intercom

Purpose
In-product support messaging
Data involved
Name, email address, and support conversation content

Firebase (Google)

Purpose
Push notifications and usage analytics
Data involved
Device push tokens and usage identifiers

Accessibility

KANU has been evaluated against WCAG 2.1 Level AA. An Accessibility Conformance Report (VPAT) is available on request. Our most recent report is dated January 2025 and a refresh is currently underway.

Accessibility issues can be reported through the help form available in the KANU web dashboard and mobile app.

Documentation for Your Review

The following are available on request — contact support@kanu.us:

  • HECVAT (Higher Education Community Vendor Assessment Toolkit) response
  • System and data flow architecture diagram

The following are available on our Document Library:

  • Accessibility Conformance Report (VPAT)
  • Privacy Policy

Was this page helpful?