Security
Last updated: September 9, 2026
Vivipod is an asynchronous video discussion platform for education. Schools trust us with student recordings, comments and account details, and this page summarizes how we protect them. Institutions that need more detail can request our security documentation below.
Security documentation
| Document | Availability |
|---|---|
| HECVAT 4.1.6 response | On request for institutional reviews |
| Accessibility Conformance Report (ACR / VPATĀ®) | Public |
| Data Privacy Agreement coverage | Public, with signed agreements on request |
| Privacy Policy and Terms of Service | Public |
To request our HECVAT (Higher Education Community Vendor Assessment Toolkit) response, email us from your institutional address with your institution name, role and the questionnaire version you need. We also complete institution-specific security questionnaires and can provide a named security contact for your review. The HECVAT is a self-assessment, not a certification.
Infrastructure security
- Cloud hosting. Vivipod runs on Cloudflare's global platform. We operate no servers of our own, and Cloudflare manages the physical and network layers.
- Encryption. Data is encrypted in transit with TLS and at rest in our databases and media storage, with keys managed by the platform.
- Separated environments. Staging and production are separate deployments with separate data.
- Secrets management. Credentials and signing keys are held in the platform's secret store, never in source code.
- Media access. Recordings are served through signed access links rather than public storage URLs.
Product security
- Sign-in. People sign in with a one-time code sent to their email address, or with Google. Vivipod does not store passwords. Sign-in is rate limited. Sessions expire after seven days without activity and thirty days after sign-in, are revoked server-side on log out, and anyone can end every session on their account from Settings.
- Access control. Spaces have owners, administrators and members. Roles determine who can manage a Space, see private content and publish posts.
- Sharing controls. Content is private to a Space by default. Public sharing is an explicit choice made by the Space's administrators.
- Change management. Changes are reviewed and tested before release, and dependencies are kept current.
- Vulnerability reporting. Email support@vivipod.com to report a suspected vulnerability. Describe the affected feature and how to reproduce it, without including student records or credentials.
Data and privacy
Data we collect
- Account details: name, email address and username.
- Content added through use of the product: recordings, comments, captions and transcripts.
- Space and Topic membership and roles.
- Billing references for paid plans. Payment details are entered on Stripe's hosted checkout and never reach Vivipod.
Data we do not collect
- Card numbers or bank details.
- Passwords.
- Health information.
How we handle it
- Student data is used only to provide the service. We do not sell personal information or use it for advertising.
- Speech-to-text captions are off by default and turned on per Topic by a Space administrator. Vivipod does not train AI models on your content and operates no model-training pipeline; captions come from a pretrained speech-to-text model running in our own Cloudflare account.
- Deleted recordings are hidden immediately and their files become eligible for permanent removal after a 30-day recovery window. Account and data deletion requests are honoured on request, and institutions can export their media where they are authorized to access it.
- Our Privacy Policy describes data categories, retention and your rights in full.
Subprocessors
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, database and media storage, speech-to-text for captions, email routing |
| Optional Google sign-in | |
| Stripe | Subscription checkout and billing |
| Resend | Transactional email delivery, being consolidated into Cloudflare |
The Privacy Policy carries the full provider list and what each one processes.
Accessibility
We aim to meet WCAG 2.2 Levels A and AA and publish our known gaps. Our accessibility statement and Accessibility Conformance Report describe what is supported, how we test, and known limitations.
Compliance and assurance
- Data privacy agreements. We sign student data privacy agreements with schools and districts, including SDPC/NDPA-aligned agreements. See our DPA coverage map.
- HECVAT. Our HECVAT 4.1.6 response is available to institutions on request and is refreshed as the product changes.
- Certifications. Vivipod does not currently hold SOC 2 or ISO 27001 certification. Cloudflare's, Google's and Stripe's certifications cover their own services, not Vivipod.
Frequently asked questions
Where is our data stored? On Cloudflare's platform, with Vivipod operated from the United States. Talk to us if your institution has regional processing requirements.
Do you support single sign-on? Google sign-in is supported. Institution-managed SAML or directory provisioning is not currently offered.
Do you have a HECVAT? Yes. Request it above and we will send the current response.
Who do I contact? support@vivipod.com reaches the team that handles security and privacy questions.