NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

← All profiles

Khanacademy

khanacademy.com

1
Vendors
1
App matches
7 auth features

Detected Vendor Stack

Atlassian
Atlassian
Collaboration
khanacademy.atlassian.net
vendor customer list

Our Apps for Your Stack

Enterprise Onboarding

SSO / Identity Provider

No SSO vendor detected for this company. SAML 2.0 and OIDC configuration is available via the enterprise onboarding flow for any compliant IdP.
Authentication features(7 available)
TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup Codes+3 more
TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup CodesJWT API TokensCustom Password Policy· betaOrg-level MFA Enforcement· beta

Job Posting Intelligence

22
Total jobs
0
AI security roles
1
Adjacent roles
0
Skill-washed
1 AI tool in JDs

Trust Scanner

0

Public Surface

0

AI Language

0

Legal Clarity

0

Security Trust

100

Consistency

100

Remediation Opportunity

Trust Scanner · ATG Scorecard

Khanacademy · public trust surface

Public trust surface scored 16 with 36 positive detectors out of 74 across 15 pages. Higher remediation scores mean more visible work remains.

16

weak

Public Surface

Whether trust, legal, security, AI, methodology, and contact surfaces are discoverable and coherent.

0

0% signal

AI Language

Whether AI claims are specific, bounded, and tied to engineering evidence rather than generic positioning.

0

0% signal

Legal Clarity

Whether privacy, terms, contract, data-processing, and customer-facing boundaries are clear enough to review.

0

0% signal

Security Trust

Whether public trust artifacts explain controls, evidence, limitations, and escalation paths without oversharing.

0

0% signal

Consistency

Whether public claims, caveats, service language, and trust artifacts agree across the site.

100

100% signal

Remediation Opportunity

Whether the public surface makes the next improvement work obvious, scoped, and evidence-backed.

100

100% signal

Public-signal caveat

Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.

public_claim_with_caveatsurface review

Top finding

high

Missing Incident Communication

Document how customers are notified and where public incident updates live.

24 more findings
high

Missing Privacy Policy

Clarify what personal data you collect, process, retain, and disclose.

high

Missing Data Breach Notice

Explain how breach notification works and who is notified.

high

Missing Data Processing Addendum

Make the DPA request path easy to find for customers and partners.

high

Missing Subprocessors List

Publish a current subprocessor or vendor list with update cadence.

high

Missing Model Provider Disclosure

State which model or provider services are used and where customer data may flow.

high

Missing Model Card or System Card

Publish a model or system card if the site makes substantial AI claims.

high

Missing AI Evaluation or Safety Report

Provide a public evaluation or safety summary when AI claims are central.

high

Missing Transparency Report

Publish a public transparency report when the product makes AI capability claims.

high

Missing Model Limitations

Describe where the model or AI system fails, degrades, or needs human review.

high

Trust center missing privacy policy

Link the privacy policy directly from the trust center and footer.

high

Missing Contact Paths

Surface public trust and support contact paths in a discoverable place.

high

Missing Footer Cross-links

Add footer links that make trust artifacts easy to reach.

medium

Missing Cookie Policy

Publish cookie and tracking language with a clear consent path.

medium

Missing Data Retention Policy

State how long data is kept and what triggers deletion or archival.

medium

Missing Data Sharing Notice

Clarify which parties receive data and why.

medium

Missing Cross-Border Transfers

Explain transfer mechanisms, safeguards, and processor relationships.

medium

Missing Data Residency Policy

State where data is stored and whether region selection is supported.

medium

Missing Acceptable Use Policy

Clarify prohibited and abusive use patterns in public-facing terms.

medium

Missing Human Review Policy

Explain what is reviewed by humans and what remains automated.

medium

Missing Evals and Red Teaming

Describe testing and evaluation practices that back AI claims.

medium

Missing Prohibited Uses

State the use cases you will not support and where enforcement lives.

medium

Missing Output Moderation Policy

Explain how outputs are filtered, blocked, or escalated.

medium

Missing Unsupported Maturity Phrasing

Ground broad maturity language in observable public evidence.

low

Missing Encryption at Rest

State where encryption is used and what it protects.

Dimension maturity
public surface·Public SurfaceWhether trust, legal, security, AI, and methodology pages are visible and navigable.
ai language·AI LanguageWhether AI claims are specific, bounded, and paired with review or data-use language.
legal clarity·Legal ClarityWhether privacy, terms, DPA, subprocessors, and acceptable-use surfaces are visible.
security trust·Security TrustWhether security, vulnerability, incident-response, and contact paths are documented.
consistency·ConsistencyWhether claims, caveats, and trust artifacts are coherent across pages.
remediation opportunity·Remediation OpportunityWhether the public surface makes the next improvement work obvious.

Scanned 2026-06-23 · rules vtrust-scanner-rules.v1 · 15 artifacts probed