Koydo Breach Protocol
Effective Date: June 1, 2026 Last Updated: June 1, 2026 This protocol describes how Koydo handles confirmed or suspected security incidents affecting personal data, education records, child-directed learning records, or institution-managed accounts.
Plain-language summary
This section covers koydo breach protocol.
Detection and Triage
Koydo reviews suspected incidents for scope, affected systems, data categories, user impact, child-safety impact, and institutional obligations. Incidents involving children, school records, parent accounts, payments, authentication, or AI learning logs receive elevated review.
Plain-language summary
Koydo reviews suspected incidents for scope, affected systems, data categories, user impact, childsafety impact, and institutional obligations.
Containment
When an incident is confirmed or reasonably suspected, Koydo prioritizes containment, credential rotation, access review, affected-service isolation, logging preservation, and restoration of trusted service behavior.
Plain-language summary
When an incident is confirmed or reasonably suspected, Koydo prioritizes containment, credential rotation, access review, affectedservice isolation, logging preservation, and restoration of trusted service behavior.
Notice Timing
For school-managed education records, Koydo notifies the school in writing without undue delay and in any case within 72 hours of confirming a Personal Data Breach affecting those records, consistent with the FERPA Notice and Data Processing Agreement. For other affected users, Koydo provides notices required by applicable law and contract, using practical channels such as email, account notices, school administrator notices, or parent/guardian communications.
Plain-language summary
This section covers notice timing.
Notice Content
When available and appropriate, breach notices describe the affected data categories, approximate number of affected users or records, likely consequences, containment measures, recommended user actions, and contact information for follow-up.
Plain-language summary
This section covers notice content.
Learning and AI Data
If an incident touches adaptive-learning records, AI tutor logs, assessment history, parent summaries, or school reporting data, Koydo evaluates the incident for privacy, child-safety, education-record, and model-governance implications before closing the review.
Plain-language summary
This section explains the categories of information involved and keeps the description focused on what users need to understand.
Contact
Security or breach questions can be sent to security@koydo.app or legal@koydo.app.
Plain-language summary
Use the listed contact path for privacy, legal, accessibility, or account-rights requests.