Security Policy
Last updated: November 11, 2025
We take the security of your information seriously. This policy explains how Comedy Safe Driver safeguards your data across our website, course platform, and supporting systems.
1) Data in Transit
- All pages and APIs are served over HTTPS (TLS). Browsers should show the secure padlock in the address bar.
- Sensitive actions (account, checkout, and certificate delivery) require secure connections; requests sent over HTTP are redirected to HTTPS.
2) Data at Rest
- Account and course data is stored in access-controlled databases.
- We minimize what we store and retain only what’s needed to operate your course, meet legal obligations, or provide support.
- Backups are encrypted and stored in restricted locations with limited access.
3) Payments
- Card payments are processed by a trusted third-party payment processor.
- We do not store full card numbers or CVV codes on our servers.
4) Access Controls
- Only authorized personnel can access student records, and only for job-related tasks.
- Least-privilege permissions, unique accounts, and login auditing are enforced for staff tools.
5) Application Security
- We follow secure-by-default coding practices (input validation, output encoding, parameterized queries).
- Dependencies and servers receive regular security updates.
- Key features (registration, login, certificate workflows) are monitored for abuse and unusual activity.
6) Infrastructure & Monitoring
- Servers are hosted in data centers with physical security, network segregation, and firewalling.
- Logs and alerts help us detect anomalies and investigate issues.
7) Data Retention & Deletion
- Student records are kept only as long as needed for course completion, support, and compliance.
- You can request deletion of your account where legally permissible; see our Privacy Policy for details.
8) Your Responsibilities
- Use a strong, unique password and keep it confidential.
- Always access our site via the secure URL (https://) and log out on shared devices.
9) Incident Response
- If we identify a security incident that affects your data, we will investigate promptly and notify you as required by law.
10) Questions
If you have questions about this policy or our security practices, please reach out via our Contact page.