Security at DailyRiff
Protecting your data is fundamental to everything we build. DailyRiff serves music teachers, students, and families, including children under 13. We take that responsibility seriously.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Hosted on SOC 2 Type II certified cloud infrastructure with automated backups.
Row-level security, per-studio data isolation, and COPPA compliance built in from day one.
24/7 automated threat detection, anomaly monitoring, and real-time alerting.
Periodic security assessments, penetration testing, and vulnerability scanning.
COPPA, FERPA-aligned, CCPA, and GDPR compliant. Built for handling student data responsibly.
Data Encryption
In transit: All connections use TLS 1.3. HTTP Strict Transport Security (HSTS) is enforced.
At rest: All data stored in our databases is encrypted using AES-256 encryption.
Passwords: User passwords are hashed using bcrypt with per-user salts. We never store plaintext passwords.
Payment data: Credit card information is handled exclusively by our PCI DSS compliant payment processor. We never store card numbers on our servers.
Infrastructure Security
- Hosted on SOC 2 Type II certified cloud infrastructure
- Automated daily backups with point-in-time recovery
- DDoS protection and rate limiting on all endpoints
- 99.9% uptime SLA
- Infrastructure-as-code for reproducible, auditable deployments
Access Controls
- Multi-factor authentication (MFA) available for all accounts
- Role-based access control (RBAC) with five distinct personas
- Row-level security ensures studios can only access their own data
- Principle of least privilege for all internal access
- Superadmin impersonation sessions are time-limited (8 hours) and fully audited
Security Monitoring
- 24/7 automated monitoring and threat detection
- Real-time alerting for suspicious activity
- Comprehensive audit logging for all data access
- Regular log review and anomaly detection
Compliance & Certifications
- COPPA: Full compliance for handling data of children under 13, including verifiable parental consent and 15-day grace deletion
- FERPA: Aligned with FERPA requirements for student educational records
- CCPA: California Consumer Privacy Act compliance for California residents
- GDPR: General Data Protection Regulation compliance for EU users
Incident Response
In the event of a security incident, our response plan includes:
- Immediate containment and assessment of the incident scope
- Notification to affected users within 72 hours as required by law
- Thorough investigation and root cause analysis
- Implementation of preventive measures to avoid recurrence
- Post-incident report and process improvements
Your Responsibilities
- Use a strong, unique password for your DailyRiff account
- Enable multi-factor authentication when available
- Do not share your account credentials with others
- Log out of shared or public devices after use
- Report any suspicious activity to our security team immediately
Security Questions?
If you have questions about our security practices or want to report a vulnerability, please contact us:
DailyRiff Security Team
Email: security@dailyriff.co
For urgent security issues: security-emergency@dailyriff.co