Security that works
as hard as we do.
BrightMinds is trusted by 50,000+ families across 47 countries. We earn that trust through SOC 2 Type II certification, COPPA & GDPR-K compliance, AES-256 encryption, and a zero-breach track record — not promises.
Certifications you can verify.
Every certification listed here is independently audited or legally assessed — not self-declared. Click any badge to read the full detail.
Four pillars of uncompromising security.
Select any pillar to see the specific controls we've implemented and why they matter.
Encryption at every layer
Your data is encrypted in transit and at rest — no exceptions, no overrides.
- ✓ TLS 1.3 for all data in transit (no TLS 1.0/1.1)
- ✓ AES-256 encryption for all data at rest (AWS KMS)
- ✓ Database-level field encryption for PII
- ✓ End-to-end encrypted parent–child communication
- ✓ Encrypted backups with a separate KMS key
- ✓ HSTS enforced site-wide with 1-year preload
Infrastructure at a glance.
What we collect. What we never do.
Radical transparency about what data we hold, why we hold it, and exactly when it disappears.
- ✗Full name (only first name required)
- ✗Home address or location
- ✗Date of birth (age range only)
- ✗Photos or biometric data
- ✗Social media profiles
- ✗Behavioural tracking for advertising
- ✗Third-party advertising pixels
- ✗Selling or renting data to anyone
| Period | Data covered | What happens |
|---|---|---|
| While active | All account and learning data | Stored securely, accessible in dashboard |
| 30 days after cancellation | Full account data | Available for export — download anytime |
| 30 days post-cancellation | All personal data | Permanently and irreversibly deleted |
| 7 years (legal minimum) | Aggregated billing records only | No personal data — invoices only |
Every standard. Every control.
A precise comparison of how each key data protection requirement is met across all five frameworks.
| Data protection control | 👶 COPPA | 🇪🇺 GDPR-K | 🇺🇸 FERPA | 🛡️ SOC 2 | 🇮🇳 DPDP |
|---|---|---|---|---|---|
| Data encryption at rest | ✓ | ✓ | ✓ | ✓ | ✓ |
| Parental consent for under-13 data | ✓ | ✓ | ✓ | – | ✓ |
| Right to erasure (delete account) | ✓ | ✓ | ✓ | – | ✓ |
| No advertising to children | ✓ | ✓ | ✓ | – | ✓ |
| Data portability (export) | – | ✓ | – | – | ✓ |
| Annual independent audit | – | ✓ | – | ✓ | – |
| Incident notification < 72 hours | – | ✓ | – | ✓ | ✓ |
| No data selling or renting | ✓ | ✓ | ✓ | – | ✓ |
Found a vulnerability? Tell us first.
We thank every good-faith researcher. We acknowledge within 24 hours, investigate within 7 days, and follow coordinated 90-day disclosure. We never pursue legal action against responsible disclosure.
Our commitment to researchers
- ✓Written acknowledgement within 24 hours
- ✓Status update within 7 days
- ✓90-day coordinated disclosure window
- ✓No legal action for good-faith research
- ✓Public credit on our Hall of Fame (if desired)