Skip to content

How CocoAI protected its students' data with a VDP program

CocoAI
"We went from assuming everything was fine to knowing for certain that our platform is secure. That shift gave us the peace of mind we needed to focus on growing."

After its first year on the market, CocoAI — the EdTech startup founded in 2025 that is transforming the way families manage their digital wellbeing — decided to put its platform through a rigorous advanced security assessment. With a consolidated Minimum Viable Product (MVP) and a growing user base, the company took a decisive step: moving from a purely passive security approach toward a proactive offensive strategy, guaranteeing absolute student privacy and shielding its financial viability against the abuse of AI resources.


The challenge

From its inception, CocoAI started from a responsible security foundation aligned with the industry's quality standards. The platform already had traditional mitigation mechanisms in place, such as two-factor authentication (2FA), systematic backup policies and the careful selection of infrastructure providers that guaranteed data sovereignty and strict regulatory compliance. However, the real challenge lay in the false sense of security created by these passive measures. Despite an apparently robust architecture, the platform had critical challenges that went unnoticed due to the absence of analysis from an offensive-security perspective.

The lack of an active intrusion simulation left blind spots exposed in the API's internal logic — an area where conventional 2FA was insufficient. In the education sector, where institutions demand an absolute and unshakeable privacy standard, it became clear that good operational desktop practices were no longer enough. A high-level technical validation was needed, capable of turning intuitive trust into verifiable structural robustness shielded against unauthorized access in communications.


The solution

To mitigate these risks for good, CocoAI adopted a strategic solution: launching a Vulnerability Disclosure Program (VDP). This operational framework enabled an active, continuous and open search for security flaws, subjecting the business logic to a deep examination that passive and perimeter scanning tools are unable to cover. Through this proactive collaboration with security researchers, critical vulnerabilities of various kinds were identified — directly affecting both user privacy and the platform's financial stability.


Impact

The intervention allowed CocoAI to make a critical transition toward a technically validated infrastructure. Although the end-user experience (teachers and students) remained smooth and uninterrupted, the internal impact on the organization was radical: the company went from operating under a presumption of security to owning a hardened ecosystem, where every vulnerability detected translated immediately into a definitive architectural improvement.

The benefits consolidate across two key dimensions:

  • Strategic peace of mind and operational confidence: the startup's leadership stresses that the program's main value was not only technical but emotional and strategic. They highlighted experiencing "an increase in peace of mind as issues were detected and fixed", giving them the clarity needed to focus their efforts on scaling the business, certain they were operating on solid ground.
  • Structural defense through code: unlike superficial fixes or temporary patches, the findings drove a re-engineering of the platform's structure. This mitigated the risk of AI-token exploitation and trained the development team under a "protection by design" philosophy, ensuring future software is born secure before being deployed.

Put your security to the test today

Tell us what you need and we'll prepare a tailored demo. No commitment and no jargon.