2,347 children learning safely right now

Security that works
as hard as we do.

BrightMinds is trusted by 50,000+ families across 47 countries. We earn that trust through SOC 2 Type II certification, COPPA & GDPR-K compliance, AES-256 encryption, and a zero-breach track record — not promises.

0
Data breaches — ever
99.97%
Uptime achieved in 2024
6
Compliance certifications
AES-256
Encryption standard used
🛡️ SOC 2 Type II certified 👶 COPPA verified compliant 🇪🇺 GDPR-K fully compliant 🇮🇳 DPDP Act 2023 compliant 🔐 AES-256 encryption at rest 🌍 Multi-region AWS hosting 99.97% uptime achieved in 2024 🔍 Annual CREST pen-test ❌ Zero data breaches — ever 🚫 Zero advertising to children 🛡️ SOC 2 Type II certified 👶 COPPA verified compliant 🇪🇺 GDPR-K fully compliant 🇮🇳 DPDP Act 2023 compliant 🔐 AES-256 encryption at rest 🌍 Multi-region AWS hosting 99.97% uptime achieved in 2024 🔍 Annual CREST pen-test ❌ Zero data breaches — ever 🚫 Zero advertising to children
🏅 Third-party verified

Certifications you can verify.

Every certification listed here is independently audited or legally assessed — not self-declared. Click any badge to read the full detail.

🛡️
SOC 2 Type II
Certified
Last audit: January 2025
Our SOC 2 Type II report covers Security, Availability, and Confidentiality trust service categories. Audited annually by an independent AICPA-accredited firm. Report available under NDA for enterprise customers.
🏗️ How we protect you

Four pillars of uncompromising security.

Select any pillar to see the specific controls we've implemented and why they matter.

ALWAYS ON
🔐

Encryption at every layer

Your data is encrypted in transit and at rest — no exceptions, no overrides.

What we've implemented
  • TLS 1.3 for all data in transit (no TLS 1.0/1.1)
  • AES-256 encryption for all data at rest (AWS KMS)
  • Database-level field encryption for PII
  • End-to-end encrypted parent–child communication
  • Encrypted backups with a separate KMS key
  • HSTS enforced site-wide with 1-year preload
📊 By the numbers

Infrastructure at a glance.

⏱️
99.97%
Uptime 2024
🌍
3
Hosting regions
🔄
Daily
Backup frequency
🔍
Annual
Pen-test frequency
< 15 min
P1 response SLA
🗑️
30 days
Data deleted after
🔄 Your data, your control

What we collect. What we never do.

Radical transparency about what data we hold, why we hold it, and exactly when it disappears.

✅ What we collect (and why)
📧
Account email (parent)
Used only for login, security alerts, and weekly progress reports. Never shared with third parties.
👤
Child name & age
Used to personalise curriculum level and generate progress reports. Stored encrypted. Never publicly visible.
📊
Learning activity data
Lesson completions, quiz scores, session duration. Used only to generate your progress report and improve the AI model.
📱
Device type & browser
Collected for performance optimisation and bug diagnosis only. Not linked to personal identity.
🚫 What we never collect or do
  • Full name (only first name required)
  • Home address or location
  • Date of birth (age range only)
  • Photos or biometric data
  • Social media profiles
  • Behavioural tracking for advertising
  • Third-party advertising pixels
  • Selling or renting data to anyone
⏱️ Data retention schedule
PeriodData coveredWhat happens
While activeAll account and learning dataStored securely, accessible in dashboard
30 days after cancellationFull account dataAvailable for export — download anytime
30 days post-cancellationAll personal dataPermanently and irreversibly deleted
7 years (legal minimum)Aggregated billing records onlyNo personal data — invoices only
📋 Full compliance matrix

Every standard. Every control.

A precise comparison of how each key data protection requirement is met across all five frameworks.

Data protection control👶 COPPA🇪🇺 GDPR-K🇺🇸 FERPA🛡️ SOC 2🇮🇳 DPDP
Data encryption at rest
Parental consent for under-13 data
Right to erasure (delete account)
No advertising to children
Data portability (export)
Annual independent audit
Incident notification < 72 hours
No data selling or renting
🔍 Bug bounty & responsible disclosure

Found a vulnerability? Tell us first.

We thank every good-faith researcher. We acknowledge within 24 hours, investigate within 7 days, and follow coordinated 90-day disclosure. We never pursue legal action against responsible disclosure.

Our commitment to researchers

  • Written acknowledgement within 24 hours
  • Status update within 7 days
  • 90-day coordinated disclosure window
  • No legal action for good-faith research
  • Public credit on our Hall of Fame (if desired)
In scope
brightminds.com · app.brightminds.com · api.brightminds.com · iOS app · Android app
Out of scope
Denial-of-service attacks · Physical attacks · Social engineering · Third-party services we don't control
Prefer email?
security@brightminds.com
PGP key available on Keybase: @brightminds_security
❓ Security questions

Transparent answers.

No. As of the date of this page's last update (March 2025), BrightMinds has never experienced a security incident involving user data. Our annual pen tests and continuous vulnerability scanning are designed to keep this record intact.
Yes — from Account Settings → Privacy → Delete Account. All personal data is permanently deleted within 30 days. You can also email privacy@brightminds.com to request deletion without closing the account (for individual data points).
Data is stored in AWS regions. Indian users' data is stored in ap-south-1 (Mumbai). UK/EU users in eu-west-1 (Ireland). US users in us-east-1 (Virginia). You can request your data's region from privacy@brightminds.com.
Yes — but only to improve your child's learning experience. The AI analyses lesson performance to personalise content. It never uses your child's data to train models that are shared externally, sold, or used for advertising.
It stays accessible for 30 days — you can export everything as a PDF or CSV. After 30 days, all personal data is permanently and irreversibly deleted. Anonymised learning analytics may be retained for product improvement.
Teachers connected to your child's school account can see learning progress (scores, mastery, time-on-task) but never see personal contact information, billing details, or any data you've entered in the parent profile.
Email security@brightminds.com with details of the potential vulnerability. We acknowledge within 24 hours, investigate within 7 days, and follow coordinated disclosure (90-day window before public disclosure). We do not pursue legal action against good-faith researchers.
🔒
Security team
security@brightminds.com
Vulnerability reports · Pen-test enquiries
🛡️
Data Protection Officer
dpo@brightminds.com
GDPR rights · DPA requests · DSAR
📋
Privacy team
privacy@brightminds.com
Data deletion · Access requests · Complaints
🏫
Enterprise / schools
schools@brightminds.com
SOC 2 reports · DPA signing · FERPA
🛡️🔐🌍

Security you can
count on.

50,000+ families trust us with their children's learning — and their data. That trust is not taken lightly.