Our approach
String was built with serious security controls from day one, because school and student data deserves them. This page lists the practices that actually exist — not aspirations, and not badges. Where we don't hold something yet, we say so plainly rather than staying silent about it.
Encryption
All data is encrypted in transit using TLS, and at rest using AES-256 encryption.
Access control and audit logs
We apply role-based access control, with comprehensive audit logging for all system activity.
Authentication and single sign-on
String supports enterprise single sign-on through the SAML 2.0 and OAuth 2.0 protocols.
Infrastructure and availability
String is hosted on cloud infrastructure from major providers (AWS and Google Cloud Platform). We target high availability, but we do not promise standard accounts a numeric, financially-backed uptime figure — this matches exactly what the Terms of use state.
Backups and recovery
We run automated daily backups, stored with geographic redundancy, with a disaster-recovery plan in place.
Vulnerability testing
We run continuous vulnerability scanning, alongside periodic penetration testing by third-party specialists.
AI and your data
No third-party AI provider trains its models on your data. The OpenAI API we use operates under an enterprise agreement that explicitly excludes your data from training, and any internal use to improve our own algorithms happens on de-identified data only.
Certifications today
Reporting a security issue
If you find a security vulnerability or suspicious behavior, contact us through the channels below — we treat every security report seriously and promptly.
- Hello@string.education
- +962 78 597 0011
- 301 Congress Ave, Floor 22, Austin, Texas, United States