Security & Shared Responsibility
At Cothink, we understand that data security is paramount for educators and students. We have built our platform with a "security-first" architecture to ensure your data remains private and protected.
However, keeping a classroom secure is a partnership.
Reliable Infrastructure
Cothink is hosted on Google Cloud Platform (GCP). By leveraging Google's robust infrastructure, we inherit industry-leading security standards, physical data center protections, and compliance certifications (including ISO 27001 and SOC 2). This ensures that Cothink operates with the same level of reliability and security found in Google's own services.
Data Encryption
We employ strict encryption standards to protect your data at every stage within our ecosystem:
Data in Transit
Whenever you access Cothink, data moving between your device and our servers is encrypted using Transport Layer Security (TLS/SSL) via HTTPS. This prevents unauthorized parties from intercepting your information.
Data at Rest
When your data is stored in our database, it is encrypted using AES-256, the Advanced Encryption Standard with a 256-bit key. This is the industry standard for securing sensitive electronic data.
Shared Responsibility
Security is a collaborative effort. While Cothink secures the infrastructure and application, users play a vital role in maintaining the integrity of their accounts and data:
Account Credentials
Users are responsible for maintaining the confidentiality of their login information. We require teachers to utilize strong, unique passwords and recommend updating them periodically. Cothink will never ask for your password via email.
Downloaded Data
Once data is exported from the Cothink platform (e.g., downloading grade books, student rosters, or reports to a local hard drive), it leaves our encrypted environment. Users assume responsibility for securing this offline data by storing it on password-protected devices and deleting it when it is no longer needed.
Your Data Storage Options
FAST-Action gives you control over how your data is stored:
Session Data (Default)
- Processed securely during your session
- Automatically deleted when session ends
- No permanent record on our servers
Saved Plans (Optional)
- Encrypted with AES-256 at rest
- Accessible only from your account
- Delete anytime from My Plans
Questions About Security?
We take security seriously and are happy to answer any questions about how we protect your data.
Contact Us