Security & Trust

How we protect Customer Content, Learner Data, and the running platform — and what we're still working on.

TLS 1.2+ in transit AES-256 at rest Bcrypt password hashing Audit logging No AI training on customer data SOC 2 Type II in progress Penetration test (annual)

Infrastructure

Encryption

Access control

Sub-processors

Full list with purpose and data flow lives in the Privacy Policy. Current sub-processors:

VendorPurposeData shared
AnthropicClaude LLM (lessons, roleplay, AI assistant)Conversation content (no retention for training)
Google Cloud PlatformHosting, storage, databaseAll Customer Content + Learner Data
StripePayment processingBilling info (no card numbers on our servers)
TwilioSMS messaging (when SMS features used)Phone numbers, SMS content
ElevenLabsVoice synthesis + conversational voiceAudio during active sessions only
Qdrant Cloud (or self-hosted)Vector searchDocument embeddings

Customers on annual contracts can subscribe to sub-processor change notifications — email security@learnready.ai.

AI safety

Compliance and audit

Backups and disaster recovery

Incident response

If we detect or confirm a security incident affecting customer data:

Vulnerability disclosure

If you've found a vulnerability, please tell us before disclosing publicly. Email security@learnready.ai with:

We'll acknowledge receipt within 1 business day, investigate, and coordinate disclosure. We don't currently run a paid bug bounty but are happy to credit researchers publicly.

Compliance roadmap

Security questions for procurement? Most enterprise customers have a standard security questionnaire (CAIQ, SIG, etc.). Email security@learnready.ai and we'll turn it around — typical response time is 3-5 business days.

Get in touch

Security disclosures & questions: security@learnready.ai
General contact: /contact · support@learnready.ai