Skip to main content
Blended Teaching

Security and Trust

Last updated: 30 September 2026

How we protect your data

Schools and universities trust us with Student work, grades and course data. This page explains how we protect that data, who can reach it, and what we do when something goes wrong. If you are reviewing Blended Teaching for your institution, the last sections list the documents we can send you.

Where your data is hosted

Our backend runs on Amazon Web Services (AWS) and our database runs on Supabase, both in the AWS us-east-1 region (Northern Virginia, United States).

All institution data, including sign-in details, is stored in the United States. Backups also stay in the United States.

Our web apps are hosted on Vercel in the United States.

We run no servers of our own. AWS, Supabase and Vercel each hold independent SOC 2 Type II reports for their services.

Encryption

In transit: every connection to our apps and API uses TLS 1.2 or higher, and browsers are told to use HTTPS only (HSTS). Our connections to our database and to other providers are also encrypted.

At rest: our database, file storage and backups are encrypted with AES-256.

Card payments are handled by Stripe. Card numbers never reach our systems.

Access control

Multi-factor authentication (MFA) is required for all staff access to our infrastructure consoles.

Staff access is based on role and limited to what each person needs.

Passwords are stored only as salted hashes.

Sign-in through your LMS

We connect to Canvas, Blackboard, Brightspace (D2L) and Moodle using the LTI 1.3 standard.

Students and Educators who open Blended Teaching from their course sign in through your institution's own single sign-on, with whatever MFA your institution requires. We never see their institution password.

Since 30 September 2026, sign-in to Blended Teaching is handled by Supabase Auth, hosted in the United States (AWS us-east-1).

Independent testing and monitoring

An independent security firm, Vaadata, carried out a human-led penetration test of our apps in June 2026. Every finding was fixed, and a retest on 31 July 2026 confirmed that none remained open. A summary of the report is available on request.

We commission an independent penetration test at least once a year.

GitHub Dependabot alerts us to known vulnerabilities in the software we depend on, and GitHub secret scanning checks our code for leaked credentials. We aim to fix critical issues within 72 hours, high issues within 14 days, and medium and low issues within 90 days.

AWS WAF filters traffic to our API, and Amazon GuardDuty watches our AWS account for threats.

Backups and recovery

Our database has point-in-time recovery. We can restore it to any moment in the last 7 days.

We last tested a full restore of our production database on 14 July 2026.

Our target is to restore service within 4 hours of a major failure.

If something goes wrong

We follow a written incident response plan. Our Security Officer leads the response.

If we confirm a breach that affects your institution's data, we will tell you without undue delay, and no later than 72 hours after confirming it. We will explain what happened, what data was involved, and what we are doing about it.

AI and Student data

We never use customer data to train or fine-tune AI models.

Our AI model providers (OpenAI and Anthropic) do not use our data for training and do not store it for reuse. Any retention on their side is limited to short-term abuse monitoring.

Student names and emails held in our records are replaced with opaque references before model calls. What a Student writes or scans (answers, handwriting images) is sent as written for grading.

Our instructional features for Students contain no generative AI. The only AI a Student may meet is the assistant in our support chat (Intercom's Fin).

Read more at https://www.blended-teaching.com/ai.

The companies we work with

We use a small number of providers to run Blended Teaching. Each one is bound by a data processing agreement or equivalent terms. Our current list is at https://www.blended-teaching.com/subprocessors.

Compliance and documents for reviewers

We follow the NIST Cybersecurity Framework (CSF) 2.0.

Our SOC 2 program starts in October 2026. We do not yet hold a SOC 2 report.

We act as a school official under FERPA and sign data protection agreements with institutions.

On request we can send a completed HECVAT, our VPAT (accessibility conformance report) and a summary of our latest penetration test. Email help@blended-teaching.com.

Report a security issue

If you think you have found a security problem in Blended Teaching, email help@blended-teaching.com with "Security" in the subject line. Please include enough detail for us to reproduce it. We will acknowledge your report and keep you informed of our progress.

Please test only against your own account, do not access or change other people's data, and do not disrupt the service. Give us a reasonable time to fix the problem before you tell anyone else. If you follow these rules in good faith, we will not take legal action against you.

For privacy questions or deletion requests, email privacy@blended-teaching.com. For anything else, email help@blended-teaching.com.