Trust Center - Duolingo
Duolingo English Test
FAQ
How does DET protect user data stored in the cloud?
DET employs a multi-layered security approach to protect user data within our DET cloud infrastructure. This includes the use of advanced encryption algorithms for data at rest and in transit, strict access controls based on the principle of least privilege, and continuous monitoring for suspicious activity. All access to cloud resources is logged and regularly reviewed. Security policies and procedures are aligned with international standards and local regulations, ensuring that data is protected against unauthorized access, disclosure, alteration, and destruction.
Where is user data stored and processed?
User data is stored and processed in secure, geographically distributed cloud environments that are selected based on compliance with applicable data protection laws, including those in China. DET ensures that data residency requirements are met by utilizing local data centers where required, and by implementing robust data segregation and access controls. Data processing activities are documented and subject to regular audits to verify compliance with both domestic and international regulatory requirements.
What measures are in place to prevent unauthorized access to user information?
DET enforces strict identity and access management protocols, including multi-factor authentication (MFA), role-based access control (RBAC), and regular access reviews. All user and administrator actions are logged and monitored for anomalies. Access to sensitive data is restricted to authorized personnel only, and all permissions are reviewed and updated on a regular basis. Security awareness training is provided to all staff, and technical controls are supplemented by administrative safeguards to ensure comprehensive protection.
Is user data encrypted in the DET cloud infrastructure?
Yes, DET uses industry-standard encryption protocols such as AES-256 for data at rest and TLS 1.2+ for data in transit within our DET cloud infrastructure. Encryption keys are managed securely using dedicated key management services, with strict controls over key access and rotation. Regular encryption audits and penetration tests are conducted to validate the effectiveness of our cryptographic controls. This ensures that user data remains confidential and protected from unauthorized access at all times.
What steps are taken to ensure the continual security of DET cloud infrastructure?
DET’s cloud infrastructure is protected by a combination of technical, administrative, and physical controls. Regular vulnerability assessments and penetration testing are performed to identify and remediate potential weaknesses. Security patches and updates are applied promptly, and intrusion detection and prevention systems are deployed to monitor for threats. Infrastructure components are segmented and access is tightly controlled. DET also maintains a business continuity and disaster recovery plan to ensure service availability and data integrity.
How does DET respond to potential data security incidents?
DET has a formal incident response plan that includes continuous monitoring, rapid detection, and escalation procedures for potential data security incidents. A dedicated incident response team is trained to investigate, contain, and remediate incidents in accordance with regulatory requirements. All incidents are documented, and root cause analyses are conducted to prevent recurrence. DET also notifies affected users and relevant authorities as required by law, and regularly tests and updates its incident response procedures.
I found a security bug. Do you have an established bug bounty program?
DET is dedicated to maintaining a robust security posture and actively encourages responsible disclosure of potential vulnerabilities. We operate a private bug bounty program in partnership with HackerOne, a leading vulnerability coordination and bug bounty platform. This program enables vetted security researchers and trusted partners to report security issues in a structured, confidential, and legally safe manner.
How do you monitor for security breaches or other industry-wide security events?
DET employs a comprehensive security monitoring strategy to detect, investigate, and respond to potential security breaches and industry-wide security events. Our approach combines advanced technical solutions, continuous threat intelligence, and well-defined operational processes to ensure rapid identification and mitigation of risks.
Within our DET cloud infrastructure, we deploy automated security information and event management (SIEM) systems that aggregate and analyse logs from critical systems, applications, and network devices in real time. These systems are configured to detect anomalous activities, unauthorized access attempts, and indicators of compromise. Alerts generated by our monitoring tools are promptly reviewed by our dedicated security operations team, who follow documented incident response procedures to assess and address potential threats.
DET also subscribes to multiple external threat intelligence feeds and participates in industry information sharing networks to stay informed about emerging vulnerabilities, attack techniques, and large-scale security incidents affecting the broader technology ecosystem. Our security team regularly reviews advisories from global and regional authorities, including those relevant to China, and proactively applies security patches and mitigations as needed.