Security

Last updated: June 2026

Compliance posture

TheClassHive is FERPA aligned and COPPA compliant. SOC 2 Type II certification is on our roadmap. We are also designed with awareness of state-level student privacy laws, including New York Education Law 2-D and California's SOPIPA.

Data handling

Data is encrypted with TLS 1.3 in transit and AES-256 at rest. Access control is enforced at the database layer using row-level security, not just at the application layer. All data is stored within the United States.

Subprocessors

We rely on a small set of named, SOC 2 certified subprocessors: Supabase (database and backend infrastructure), Vercel (hosting), and Anthropic (AI features). We will provide advance notice before adding or changing any subprocessor.

Data Processing Agreement

A Data Processing Agreement covering FERPA, COPPA, and applicable state laws is available on request at legal@theclasshive.com.

Incident response

In the event of a data breach, affected customers are notified within 72 hours, followed by a written summary within 7 days.

Privacy Officer & vulnerability disclosure

Privacy questions: privacy@theclasshive.com. Security vulnerabilities or disclosures: security@theclasshive.com.