Security and data protection

Coursebricks protects your learners' personal, payment and health data. Everything is encrypted at rest and in transit, hosted in the region you choose, and handled in line with GDPR, PCI-DSS, HIPAA, CCPA and the Australian Privacy Principles.

Compliance

Compliant with GDPR, PCI-DSS, HIPAA, CCPA and APP.

Coursebricks meets the data protection and payment security standards that training providers in Europe, the US and Australia are asked about.

  • GDPR

    EU and UK General Data Protection Regulation

  • PCI-DSS

    Payment Card Industry Data Security Standard

  • HIPAA

    US Health Insurance Portability and Accountability Act

  • CCPA

    California Consumer Privacy Act

  • APP

    Australian Privacy Principles

Server and infrastructure security

Coursebricks controls who and what can reach your data. Your account runs in the region you choose, every connection is encrypted with TLS 1.3, and account data is only reachable by signed-in users or by API keys you create.

Authenticated access only
Account data is only reachable by signed-in team members, trainers and learners, or by API keys you create and can set to expire.
Your chosen region
Your account's data stays in the region you choose: Frankfurt, N. Virginia, Sydney or Singapore.
DDoS protection
Automatic DDoS mitigation at the network edge keeps Coursebricks available during traffic floods.
Audited cloud hosting
Coursebricks is hosted on Vercel, a SOC 2 Type 2 attested and ISO 27001 certified cloud platform.

Physical security

Coursebricks stores customer data only in secure, access-controlled cloud data centres in your chosen region. Every provider that stores or processes your data is named, contracted and bound to protect it.

See the sub-processors list
Four hosting regions
Your data is hosted in Frankfurt, N. Virginia, Sydney or Singapore, in the region you choose.
Named sub-processors
Every provider that stores or processes your data is listed on the Coursebricks sub-processors page, with its location and security measures.
Contractual safeguards
Each sub-processor is bound by Standard Contractual Clauses for the personal data it handles.

Data encryption

Coursebricks encrypts all data at rest and in transit. Data stored in Coursebricks databases and media stores is encrypted, and every connection uses HTTPS by default.

Encrypted at rest
All data in Coursebricks databases and media stores, including uploaded documents, is stored encrypted.
TLS 1.3 in transit
All data in transit, including login codes and card details, is protected with TLS 1.3 (HTTPS) by default.
AES-256 and SHA-256
Connections use AES-256 bit encryption and SHA-256 signed certificates.

Role-based access control

Coursebricks role-based access control decides what each team member can see and do. Start with the Admin and Manager roles, then create custom roles with permissions set action by action.

Learn about role-based access control
Per-action permissions
Switch create, edit, delete, approve, confirm and send actions on or off for each role, such as approving orders and expenses.
Admin-only settings
Only Admins can share table views or change website settings.
Expiring API keys
API keys can be given an expiry date, with warning emails before they expire.

Passwordless sign-in

Coursebricks uses passwordless sign-in with one-time email codes for your team, your trainers and your learners. Nobody has a Coursebricks password to reuse, forget or leak.

One-time codes
Each sign-in sends a fresh code to the person's email address.
Same model everywhere
Staff, the trainer portal and the learner portal all sign in the same way.

Card payments and PCI-DSS

Coursebricks is PCI-DSS compliant, and card payments are processed by Stripe. Card details go straight from the learner to Stripe and never touch Coursebricks servers.

Your own Stripe account
Payments are taken through the Stripe account you connect, so money goes directly to you.
No stored card numbers
Coursebricks never stores card numbers. Saved cards for payment plans are held by Stripe.

Testing

Coursebricks maintains an automated test suite for its core business logic, so the parts that handle your bookings, payments and sign-in are checked by code, not by hand.

Business logic tests
Automated tests check registrations, waitlists, payment plans, discounts, invoices and workflows.
Sign-in and access tests
One-time code sign-in, portal sessions and access checks are covered by automated tests.

Data handling

Coursebricks processes your data only to provide the service, under a data processing agreement. You stay in control of your data, including when it is deleted.

Read the data processing agreement
Deletion on request
User data is kept until you or the user request deletion, and is removed from backups within 7 days after deletion.
Return or delete at the end
When the service ends, Coursebricks deletes or returns all personal data, at your choice.
Confidential staff access
Everyone authorised to process your data is bound by confidentiality agreements.
Breach notification
Coursebricks informs you of any personal data breach, including suspected breaches.
Export any time
Export contacts, courses and registrations to CSV or Excel whenever you need them.

Data residency

Choose where your data is stored.

Coursebricks hosts each account in one of four regions, so your data stays in the EU, the US, Australia or Singapore.

  • EU
    Frankfurt
    eu-central-1
  • US
    N. Virginia
    us-east-1
  • AU
    Sydney
    ap-southeast-2
  • SG
    Singapore
    ap-southeast-1

Coursebricks Security FAQs

Coursebricks keeps training data secure with encryption at rest and in transit, hosting in four regions, role-based access control, passwordless sign-in and Stripe card payments.

Book a Demo

Is Coursebricks secure?

Yes. Coursebricks encrypts all data at rest and in transit, using TLS 1.3 (HTTPS) with AES-256 encryption and SHA-256 signed certificates. Coursebricks uses role-based access control and passwordless sign-in, lets you choose the region your data is stored in, and is GDPR, PCI-DSS, HIPAA, CCPA and Australian Privacy Principles (APP) compliant.

Where is Coursebricks data hosted?

Coursebricks is hosted on Vercel, and you choose the region where your data is stored: the EU (Frankfurt, eu-central-1), the US (N. Virginia, us-east-1), Australia (Sydney, ap-southeast-2) or Singapore (ap-southeast-1). The Coursebricks sub-processors page lists every provider that processes your data and its location.

Is my data encrypted in Coursebricks?

Yes. All data at rest in Coursebricks databases and media stores is stored encrypted. All data in transit, including login codes and card details, is protected with TLS 1.3 (HTTPS) by default, with AES-256 bit encryption and SHA-256 signed certificates.

Does Coursebricks store credit card details?

No. Card payments in Coursebricks are processed by Stripe, and card details go straight to Stripe without touching Coursebricks servers. Coursebricks is PCI-DSS compliant, and saved cards for payment plans are held by Stripe.

Is Coursebricks GDPR compliant?

Yes. Coursebricks is GDPR compliant and offers a data processing agreement to every customer. EU customers can keep their data in Frankfurt (eu-central-1), and every sub-processor is listed with its location and Standard Contractual Clauses.

Is Coursebricks HIPAA compliant?

Yes. Coursebricks is HIPAA compliant, so providers who handle health information in their training records can use it. Coursebricks also complies with GDPR, PCI-DSS, CCPA and the Australian Privacy Principles.

Does Coursebricks comply with CCPA and the Australian Privacy Principles?

Yes. Coursebricks is compliant with the California Consumer Privacy Act (CCPA) and the Australian Privacy Principles (APP). Australian customers can keep their data in Sydney (ap-southeast-2), and the Coursebricks privacy policy sets out how California residents can request access to or deletion of their data.

Can I delete my data from Coursebricks?

Yes. Coursebricks keeps user data until you or the user request deletion, and deleted data is removed from backups within 7 days. When your subscription ends, Coursebricks deletes or returns all personal data, at your choice.

Spend less time on admin and more time training.

See how Coursebricks fits the way you run courses, or try it free for three months. No credit card needed.