Introduction
At DrivEd, we take data security seriously. We understand the importance of protecting your personal information and keeping your data safe while using our Platform. This Data Security Policy outlines the measures we take to ensure your data is secure.
Data Protection
We use industry-standard security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
- Regular Backups. We conduct daily database backups. Our backup strategy enables us to quickly restore data in the event of data loss or corruption.
- Customer data regulation. We never transfer any school or user data outside of the secure environment for testing or any other purposes.
- Password salting and hashing. We use the bcrypt (salted) hash function to encrypt all passwords for our accounts in the database, and they are filtered from our logs. Additionally, login information is securely transmitted over HTTPS to protect your privacy. Your account password cannot be accessed by anyone from the DrivEd team. If you forget your password, you will need to reset it.
- HTTPS everywhere. To protect the privacy of your users, we enforce HTTPS for all requests, encrypting all traffic between your school and the user's browser. This makes it impossible for anyone to intercept and access the data. Moreover, all schools powered by us receive a free SSL certificate for life. We support TLS 1.2 and 1.3 on our site and its subdomains, to ensure a high level of security.
- XSS vulnerability avoidance. To prevent any XSS vulnerabilities, we appropriately handle all user inputs.
Data Сenter Security
Our hosting is provided by Amazon Web Services (AWS), a leading company in the industry, that offers a scalable cloud computing platform with comprehensive end-to-end security and privacy features. AWS supports 143 security standards and compliance certifications, and all 117 AWS services that store customer data offer the ability to encrypt that data.
To ensure the highest level of security, access to the data centers is strictly monitored and controlled using various features, including security guards, fencing, security feeds, intrusion detection technology, and other security measures.
Access Control
Access to customer data is strictly controlled and limited to authorized employees who require it to provide our Platform service. All access is logged and monitored to ensure that only authorized employees are accessing your data.
Data Sharing
We do not share your data with third parties unless required by law or with your explicit consent. We do not sell or rent your data to third parties.
User Responsibility
We encourage our users to take responsibility for their own data security. We recommend using strong passwords, regularly changing passwords, and not sharing login information with others. We also recommend using up-to-date antivirus software and keeping devices and software up to date with the latest security patches.
Breach Notification
In the unlikely event of a data breach, we will notify affected customers as soon as possible, provide information about the breach, and take steps to mitigate any potential harm.
At DrivEd, we are committed to protecting your data and ensuring your privacy. We strive to meet or exceed industry standards for data security and will continue to make improvements to our security measures as needed. If you have any questions about our Data Security Policy or find a security issue, please don't hesitate to contact us at [email protected]. We will make sure your request is processed as soon as possible.