Security Practices
Technical details about how we protect your data
Built with enterprise-grade security for educational institutions
Cyber Jack Academy is built by cyber security and fraud prevention experts with over 25 years of experience protecting businesses and individuals from cyber threats. We apply the same enterprise-grade security standards used to protect financial institutions to safeguard your educational data.
Data in Transit
- TLS 1.3 encryption for all connections
- HTTPS enforced on all endpoints
- HSTS (HTTP Strict Transport Security) enabled
- Modern cipher suites only
Data at Rest
- AES-256 encryption for stored data
- MongoDB Atlas encrypted storage
- Encrypted backups with separate keys
- Key rotation policies in place
Password Security
- bcrypt hashing with unique salt per password
- Passwords never stored in plain text
- Password strength requirements enforced (8+ chars, mixed case, numbers, symbols)
- Secure password reset via email verification
Authentication Methods
- Email/password authentication
- Google Single Sign-On (SSO)
- Two-Factor Authentication (2FA/TOTP)
- Backup codes for account recovery
Session Management
- JWT tokens with expiration
- Automatic session timeout
- Device tracking and management
- Secure logout on all devices
Role-Based Access Control (RBAC)
| Role | Access Level | Capabilities |
|---|---|---|
| Parent/Guardian | Account Owner | Manage family, view all progress, billing |
| Child Profile | Limited | Access learning content, own progress only |
| Teacher | Class-scoped | View assigned students, class reports |
| School Admin | School-scoped | Manage school users, view all school data |
Child Profile Protection
- 6-digit PIN required for profile access
- PIN rate limiting (lockout after failed attempts)
- Children cannot access other family members' data
- Parents maintain full visibility and control
Cloud Infrastructure
- MongoDB Atlas (SOC 2 Type II certified)
- Kubernetes container orchestration
- Automated failover and redundancy
- US-based data centers
Network Security
- DDoS protection enabled
- Web Application Firewall (WAF)
- API rate limiting per endpoint
- CORS restricted to authorized domains
API Rate Limits
To prevent abuse and ensure fair access:
Proactive Security
- Regular dependency updates and patching
- Automated vulnerability scanning
- Security-focused code reviews
- OWASP Top 10 awareness and prevention
Monitoring & Detection
- 24/7 security event monitoring
- Comprehensive audit logging
- Anomaly detection for suspicious activity
- Failed login attempt tracking
In the event of a security incident, we follow a structured response process:
Detect
Identify and confirm the incident
Contain
Isolate affected systems
Notify
Alert affected parties within 72 hours
Recover
Restore and improve
Notification Timeline
- Within 72 hours: Initial notification to affected organizations
- Within 7 days: Detailed incident report with scope and impact
- Within 30 days: Root cause analysis and remediation summary
We value the security research community and welcome responsible disclosure of vulnerabilities.
How to Report a Vulnerability
- 1Email your findings to support@cyberjackacademy.com with "Security Vulnerability" in the subject line
- 2Include detailed steps to reproduce the issue
- 3Allow us reasonable time (90 days) to address the issue before public disclosure
- 4Do not access or modify data belonging to other users
What We Promise
- Acknowledge receipt within 48 hours
- Provide regular updates on remediation progress
- Not pursue legal action for good-faith security research
- Credit researchers (if desired) after fixes are deployed
Security Contact
For security questions, concerns, or to report a vulnerability
support@cyberjackacademy.com