Security & Compliance Overview
For Schools
1. Security Overview
HipDeck is built on modern cloud infrastructure with security as a foundational principle. The platform leverages managed services and industry best practices to ensure data confidentiality, integrity, and availability.
Encryption in Transit: All communications between clients, APIs, and services are secured using TLS (HTTPS).
Encryption at Rest: Data stored in PlanetScale and cloud storage systems is encrypted using provider-managed disk-level encryption.
Authentication: Auth0 is used for secure identity management, including token-based authentication and session handling.
Access Control: Role-based access controls restrict user access to authorized resources within each workspace.
Infrastructure Security: Applications are hosted on AWS (us-west-2) and DigitalOcean App Platform with network isolation and managed security controls.
Reliability: PlanetScale provides automated backups, replication, and high availability.
2. Data Handling & Privacy
HipDeck collects only the minimum data required to operate the platform and deliver its services.
Data Collected: Includes user account information, playlists, uploaded media, and configuration settings.
Purpose Limitation: Data is used solely to provide digital signage functionality and related services.
No Data Selling: HipDeck does not sell or share customer data with third parties for advertising.
Customer Ownership: Customers retain full ownership and control over their data.
Data Deletion: Users may delete content and accounts, and associated data is removed accordingly.
3. Data Residency
HipDeck ensures that customer data remains within the United States.
Application infrastructure operates in AWS (us-west-2, Oregon) and DigitalOcean U.S. regions.
Database services (PlanetScale) are configured within U.S.-based regions.
HipDeck does not transfer or process customer data outside the United States.
4. Subprocessors
HipDeck relies on trusted third-party providers to deliver core functionality. Each provider is used strictly to support the platform.
AWS: Core infrastructure services and compute resources (U.S. region).
DigitalOcean: Application hosting, deployment, and CDN/media storage.
PlanetScale: Managed MySQL database with encryption, scaling, and backups.
Auth0: Secure authentication and identity management.
Upstash (Redis): Real-time messaging layer storing ephemeral, non-identifying metadata only.
Stripe: Payment processing; all sensitive payment data is handled directly by Stripe.
Sanity CMS: Content management for marketing pages; does not store sensitive user or application data.
5. FERPA Alignment
HipDeck is designed to support educational institutions and aligns with FERPA requirements.
Acts as a “school official” processing data on behalf of institutions.
Data is used strictly for operational and educational purposes.
Institutions maintain ownership and control of all data.
No data is used for advertising, profiling, or unrelated purposes.
6. Incident Response
HipDeck maintains procedures to detect, respond to, and remediate security incidents.
Continuous monitoring and logging of system activity.
Rapid investigation and containment of potential issues.
Customer notification when appropriate based on severity.
Post-incident reviews to improve processes and prevent recurrence.
Last Updated: April 02, 2026
Contact: [email protected]
