Trust & Security
Schools and districts trust KANU with student data. This page describes how we protect it, how the platform is built and monitored, and what documentation we can provide for your security review. For anything not covered here, contact support@kanu.us.
Platform Availability
KANU targets 99.5% monthly uptime for the core platform.
Planned maintenance is scheduled during off-peak hours, typically between 12:00 AM and 4:00 AM U.S. Eastern Time, and communicated in advance where possible.
Privacy & Student Data
What we collect
KANU collects the minimum data necessary to operate the platform:
- Name and email address
- Basic usage and activity data (progress, completions, and activity within the platform)
- For students who create a storefront, a business location
- Audio submitted for voice-enabled features, and its transcription
- Payout details, for students who receive payments through the platform
- Device identifiers and usage data, for push notifications and app functionality
KANU does not collect Social Security numbers, health information, demographic information, or biometric data.
How accounts are created
Accounts are created through an invite hierarchy. A school administrator invites educators; educators invite their students. Students on the self-serve free path create their own accounts directly.
Where data lives
All institutional and student data is stored in the United States on Amazon Web Services infrastructure. Data is not transferred outside the United States.
Data access and portability
Institutions retain ownership of their data. Administrators can export a CSV of their students at any time from kanu.us. Following the end of a contract, institutional data remains accessible within KANU for 30 days unless otherwise specified in the data handling agreement.
No sale of data
KANU does not sell student data. KANU does not use student data to build advertising profiles or share it with advertising networks or data brokers.
FERPA & COPPA
KANU is built to support your district's obligations under FERPA and COPPA.
When a school or district uses KANU, KANU operates under FERPA's 'school official' exception — student data is accessed only to deliver the educational service, under the school's direction and control, and is not used for unrelated purposes.
For students under 13 accessing KANU through their school, KANU relies on the school-consent model recognized by the FTC, in which the school acts on behalf of parents to authorize use of the platform as part of instruction.
KANU will sign a district or state student data privacy agreement on request.
Security Practices
- Encryption in transit
- All traffic is transmitted over HTTPS/TLS.
- Encrypted backups
- Backups are encrypted using AES-256, at rest and in transit.
- Access control
- Role-based access control separates student, educator, administrator, and internal functions.
- Administrator MFA
- Multi-factor authentication (TOTP) is required for all administrative accounts accessing production systems.
- Audit logging
- Access logs capture login, logout, actions performed, and source IP, and are retained for a minimum of 90 days.
- High availability
- The platform is deployed across multiple AWS availability zones with load balancing and automated failover.
- Backups
- Automated backups run hourly, daily, and weekly with tiered retention.
- Payment data
- KANU does not store cardholder data. All payment information is tokenized and handled by Braintree.
- Incident response
- KANU maintains a documented incident response plan. Affected institutions are notified without unreasonable delay, and no later than 72 hours after confirmation of a breach.
- Secure development
- Code changes are peer-reviewed, tested in a staging environment, and subject to static analysis before release.
- Infrastructure attestations
- KANU's infrastructure providers, AWS and MongoDB Atlas, maintain SOC 2 Type 2 attestations.
Subprocessors
KANU uses the following subprocessors to deliver the platform. This list is reviewed periodically and updated as our vendor relationships change.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | All platform data |
| MongoDB Atlas | Primary database and backups | Platform data, including account and activity data |
| SendGrid | Transactional email (invitations, notifications) | Name, email address |
| Braintree (a PayPal service) | Payment processing | Tokenized payment data; KANU does not store cardholder data |
| Amazon SES (AWS) | Transactional email (invitations, notifications) | Name, email address |
| Trolley | Student payout processing | Name, email address, and payout details for students who receive payouts |
| TaxCloud | Sales tax calculation | Order and location data |
| Google Maps Platform | Address lookup and mapping | Location and address data |
| Amazon Transcribe (AWS) | Speech-to-text for audio features | Student-submitted audio and its transcription |
| Sentry | Application error and performance monitoring | Error and diagnostic data, which may include account identifiers |
| Intercom | In-product support messaging | Name, email address, and support conversation content |
| Firebase (Google) | Push notifications and usage analytics | Device push tokens and usage identifiers |
Amazon Web Services (AWS)
- Purpose
- Cloud hosting and infrastructure
- Data involved
- All platform data
MongoDB Atlas
- Purpose
- Primary database and backups
- Data involved
- Platform data, including account and activity data
SendGrid
- Purpose
- Transactional email (invitations, notifications)
- Data involved
- Name, email address
Braintree (a PayPal service)
- Purpose
- Payment processing
- Data involved
- Tokenized payment data; KANU does not store cardholder data
Amazon SES (AWS)
- Purpose
- Transactional email (invitations, notifications)
- Data involved
- Name, email address
Trolley
- Purpose
- Student payout processing
- Data involved
- Name, email address, and payout details for students who receive payouts
TaxCloud
- Purpose
- Sales tax calculation
- Data involved
- Order and location data
Google Maps Platform
- Purpose
- Address lookup and mapping
- Data involved
- Location and address data
Amazon Transcribe (AWS)
- Purpose
- Speech-to-text for audio features
- Data involved
- Student-submitted audio and its transcription
Sentry
- Purpose
- Application error and performance monitoring
- Data involved
- Error and diagnostic data, which may include account identifiers
Intercom
- Purpose
- In-product support messaging
- Data involved
- Name, email address, and support conversation content
Firebase (Google)
- Purpose
- Push notifications and usage analytics
- Data involved
- Device push tokens and usage identifiers
Accessibility
KANU has been evaluated against WCAG 2.1 Level AA. An Accessibility Conformance Report (VPAT) is available on request. Our most recent report is dated January 2025 and a refresh is currently underway.
Accessibility issues can be reported through the help form available in the KANU web dashboard and mobile app.
Documentation for Your Review
The following are available on request — contact support@kanu.us:
- HECVAT (Higher Education Community Vendor Assessment Toolkit) response
- System and data flow architecture diagram
The following are available on our Document Library:
- Accessibility Conformance Report (VPAT)
- Privacy Policy