Security and data protection
Coursebricks protects your learners' personal, payment and health data. Everything is encrypted at rest and in transit, hosted in the region you choose, and handled in line with GDPR, PCI-DSS, HIPAA, CCPA and the Australian Privacy Principles.
Compliance
Compliant with GDPR, PCI-DSS, HIPAA, CCPA and APP.
Coursebricks meets the data protection and payment security standards that training providers in Europe, the US and Australia are asked about.
- GDPR
EU and UK General Data Protection Regulation
- PCI-DSS
Payment Card Industry Data Security Standard
- HIPAA
US Health Insurance Portability and Accountability Act
- CCPA
California Consumer Privacy Act
- APP
Australian Privacy Principles
Server and infrastructure security
Coursebricks controls who and what can reach your data. Your account runs in the region you choose, every connection is encrypted with TLS 1.3, and account data is only reachable by signed-in users or by API keys you create.
- Authenticated access only
- Account data is only reachable by signed-in team members, trainers and learners, or by API keys you create and can set to expire.
- Your chosen region
- Your account's data stays in the region you choose: Frankfurt, N. Virginia, Sydney or Singapore.
- DDoS protection
- Automatic DDoS mitigation at the network edge keeps Coursebricks available during traffic floods.
- Audited cloud hosting
- Coursebricks is hosted on Vercel, a SOC 2 Type 2 attested and ISO 27001 certified cloud platform.
Physical security
Coursebricks stores customer data only in secure, access-controlled cloud data centres in your chosen region. Every provider that stores or processes your data is named, contracted and bound to protect it.
See the sub-processors list- Four hosting regions
- Your data is hosted in Frankfurt, N. Virginia, Sydney or Singapore, in the region you choose.
- Named sub-processors
- Every provider that stores or processes your data is listed on the Coursebricks sub-processors page, with its location and security measures.
- Contractual safeguards
- Each sub-processor is bound by Standard Contractual Clauses for the personal data it handles.
Data encryption
Coursebricks encrypts all data at rest and in transit. Data stored in Coursebricks databases and media stores is encrypted, and every connection uses HTTPS by default.
- Encrypted at rest
- All data in Coursebricks databases and media stores, including uploaded documents, is stored encrypted.
- TLS 1.3 in transit
- All data in transit, including login codes and card details, is protected with TLS 1.3 (HTTPS) by default.
- AES-256 and SHA-256
- Connections use AES-256 bit encryption and SHA-256 signed certificates.
Role-based access control
Coursebricks role-based access control decides what each team member can see and do. Start with the Admin and Manager roles, then create custom roles with permissions set action by action.
Learn about role-based access control- Per-action permissions
- Switch create, edit, delete, approve, confirm and send actions on or off for each role, such as approving orders and expenses.
- Admin-only settings
- Only Admins can share table views or change website settings.
- Expiring API keys
- API keys can be given an expiry date, with warning emails before they expire.
Passwordless sign-in
Coursebricks uses passwordless sign-in with one-time email codes for your team, your trainers and your learners. Nobody has a Coursebricks password to reuse, forget or leak.
- One-time codes
- Each sign-in sends a fresh code to the person's email address.
- Same model everywhere
- Staff, the trainer portal and the learner portal all sign in the same way.
Card payments and PCI-DSS
Coursebricks is PCI-DSS compliant, and card payments are processed by Stripe. Card details go straight from the learner to Stripe and never touch Coursebricks servers.
- Your own Stripe account
- Payments are taken through the Stripe account you connect, so money goes directly to you.
- No stored card numbers
- Coursebricks never stores card numbers. Saved cards for payment plans are held by Stripe.
Testing
Coursebricks maintains an automated test suite for its core business logic, so the parts that handle your bookings, payments and sign-in are checked by code, not by hand.
- Business logic tests
- Automated tests check registrations, waitlists, payment plans, discounts, invoices and workflows.
- Sign-in and access tests
- One-time code sign-in, portal sessions and access checks are covered by automated tests.
Data handling
Coursebricks processes your data only to provide the service, under a data processing agreement. You stay in control of your data, including when it is deleted.
Read the data processing agreement- Deletion on request
- User data is kept until you or the user request deletion, and is removed from backups within 7 days after deletion.
- Return or delete at the end
- When the service ends, Coursebricks deletes or returns all personal data, at your choice.
- Confidential staff access
- Everyone authorised to process your data is bound by confidentiality agreements.
- Breach notification
- Coursebricks informs you of any personal data breach, including suspected breaches.
- Export any time
- Export contacts, courses and registrations to CSV or Excel whenever you need them.
Data residency
Choose where your data is stored.
Coursebricks hosts each account in one of four regions, so your data stays in the EU, the US, Australia or Singapore.
- EUFrankfurteu-central-1
- USN. Virginiaus-east-1
- AUSydneyap-southeast-2
- SGSingaporeap-southeast-1
Privacy policy
Privacy policy and legal documents.
Read exactly how Coursebricks collects, uses, retains and protects personal data, and which providers process it.
Coursebricks Security FAQs
Coursebricks keeps training data secure with encryption at rest and in transit, hosting in four regions, role-based access control, passwordless sign-in and Stripe card payments.
Is Coursebricks secure?
Yes. Coursebricks encrypts all data at rest and in transit, using TLS 1.3 (HTTPS) with AES-256 encryption and SHA-256 signed certificates. Coursebricks uses role-based access control and passwordless sign-in, lets you choose the region your data is stored in, and is GDPR, PCI-DSS, HIPAA, CCPA and Australian Privacy Principles (APP) compliant.
Where is Coursebricks data hosted?
Coursebricks is hosted on Vercel, and you choose the region where your data is stored: the EU (Frankfurt, eu-central-1), the US (N. Virginia, us-east-1), Australia (Sydney, ap-southeast-2) or Singapore (ap-southeast-1). The Coursebricks sub-processors page lists every provider that processes your data and its location.
Is my data encrypted in Coursebricks?
Yes. All data at rest in Coursebricks databases and media stores is stored encrypted. All data in transit, including login codes and card details, is protected with TLS 1.3 (HTTPS) by default, with AES-256 bit encryption and SHA-256 signed certificates.
Does Coursebricks store credit card details?
No. Card payments in Coursebricks are processed by Stripe, and card details go straight to Stripe without touching Coursebricks servers. Coursebricks is PCI-DSS compliant, and saved cards for payment plans are held by Stripe.
Is Coursebricks GDPR compliant?
Yes. Coursebricks is GDPR compliant and offers a data processing agreement to every customer. EU customers can keep their data in Frankfurt (eu-central-1), and every sub-processor is listed with its location and Standard Contractual Clauses.
Is Coursebricks HIPAA compliant?
Yes. Coursebricks is HIPAA compliant, so providers who handle health information in their training records can use it. Coursebricks also complies with GDPR, PCI-DSS, CCPA and the Australian Privacy Principles.
Does Coursebricks comply with CCPA and the Australian Privacy Principles?
Yes. Coursebricks is compliant with the California Consumer Privacy Act (CCPA) and the Australian Privacy Principles (APP). Australian customers can keep their data in Sydney (ap-southeast-2), and the Coursebricks privacy policy sets out how California residents can request access to or deletion of their data.
Can I delete my data from Coursebricks?
Yes. Coursebricks keeps user data until you or the user request deletion, and deleted data is removed from backups within 7 days. When your subscription ends, Coursebricks deletes or returns all personal data, at your choice.
Spend less time on admin and more time training.
See how Coursebricks fits the way you run courses, or try it free for three months. No credit card needed.