background-image
Start your security review
View & download sensitive information
Ask for information
ControlK

At Breakout Learning Inc., we approach security and compliance as part of how we build and operate — not as an add-on. We follow established frameworks, maintain independent audits, and publish our policies so that partners, institutions, and learners know exactly how their data is protected. Use this Trust Center to learn about our security posture and request access to our security documentation.

SOC 2 Type 2 Logo
SOC 2 Type 2
FERPA Logo
FERPA
WCAG 2.2 AA Logo
WCAG 2.2 AA
VPAT Logo
VPAT
CSA STAR Level 1 Logo
CSA STAR Level 1
CSA STAR for AI Logo
CSA STAR for AI
CSA STAR AI Level 1 Logo
CSA STAR AI Level 1
TX-RAMP Logo
TX-RAMP
PIPEDA Logo
PIPEDA
GDPR Logo
GDPR
Standard Contractual Clause (SCC) Logo
Standard Contractual Clause (SCC)
EU-US DPF Logo
EU-US DPF
UK Extension to EU-US DPF Logo
UK Extension to EU-US DPF
Swiss-US DPF Logo
Swiss-US DPF
nFADP Logo
nFADP
DPDPA Logo
DPDPA
CCPA Logo
CCPA
PIPL Logo
PIPL
Sensiba LLP-company-logoSensiba LLP
AssuranceLab-company-logoAssuranceLab
Allyant-company-logoAllyant
ThinkSys Inc-company-logoThinkSys Inc

Documents

REPORTSData Flow Diagram (DFD)
SOC 2 Type 2 Report - 2025
SOC 2 Type 2 Report - 2024
Data Flow Diagram (DFD)
View more

Subprocessors

Knowledge Base (FAQ)
  • What accessibility standards do you support?
  • How can customers report concerns or inquiries?
  • Do you have accessibility support?
  • Do you comply with U.S. state privacy laws (e.g., CCPA/CPRA)?
  • Do you comply with security and privacy standards?
View more
Trust Center Updates

Breakout Learning — Compliance Updates

Copy link
Compliance

SOC 2 Type 2: 2025 Reporting Cycle

Breakout Learning Inc. has completed a new SOC 2 Type 2 independent assessment for the 2025 reporting cycle, covering a defined annual observation period within 2025. This report follows prior SOC 2 Type 2 reports and confirms the continued operating effectiveness of our controls in accordance with the AICPA Trust Services Criteria.

The report provides current, independent assurance that Breakout Learning’s security controls remain consistently designed and operating effectively to protect customer data and support secure operations.

APPs and POPIA: International Data Protection Compliance

Breakout Learning Inc. aligns its data protection practices with key international privacy laws governing the collection, use, and transfer of personal information. Our compliance posture includes adherence to:

  • Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth)
  • Protection of Personal Information Act, 2013 (POPIA) of South Africa

This alignment ensures that personal information originating from Australia and South Africa is handled in accordance with recognized legal and regulatory requirements, including lawful processing, data minimization, security safeguards, and individual rights protections.

Data Privacy Framework (DPF): EU, UK, and Swiss Data Transfer Compliance

Breakout Learning Inc. has self-certified its compliance with the Data Privacy Framework (DPF) programs administered by the U.S. Department of Commerce. Our active listing confirms participation in:

  • EU–U.S. Data Privacy Framework (EU–U.S. DPF)
  • UK Extension to the EU–U.S. DPF
  • Swiss–U.S. Data Privacy Framework (Swiss–U.S. DPF)

This ensures that transfers of personal data from the EU, UK, and Switzerland to Breakout Learning in the United States are safeguarded under recognized adequacy mechanisms.

You can verify our status on the official Data Privacy Framework List.

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo