Skip to content

Trust center

Security claims should be testable.

This page separates controls verified in the current product from the policy, provider, and operating work still required before real minor-data production.

Technical controls verified locally · Production approval pending

Verified now

Boundaries enforced in code and tests.

01

Server-verified access

Production flows resolve authenticated identity, academy membership, and role on the server. Browser-provided tenant or role fields are not trusted.

02

Tenant isolation

Tenant-scoped repositories, database constraints, and forced row-level security protect academy records. Anonymous and cross-tenant denial are tested.

03

Human approval gates

Consequential schedule changes, parent-facing content, sensitive feedback, and persistent learning records require explicit authorized approval.

04

Provider truth

Sandbox, pending, failed, unknown, and externally executed states remain distinct. A sandbox capture is never presented as a real send.

05

Minimized observability

Request logs use a strict metadata allowlist and exclude message content, identity, tenant values, tokens, secrets, network address, and minor data.

06

Secret and transport boundaries

Provider credentials remain server-only. Production database connections require certificate-verified TLS and the public origin must use HTTPS.

Not claimed

No certification theater.

We do not currently claim

  • SOC 2, ISO 27001, FERPA certification, COPPA safe-harbor status, or universal regulatory compliance.
  • That real student data is approved for every customer, jurisdiction, provider, or AI feature.
  • That a local test, sandbox provider result, or technical preflight is customer or business validation.

Before real minor-data production

  1. Complete and approve the written information-security program and risk assessment.
  2. Approve the production subprocessor register and provider contract evidence.
  3. Assign incident, privacy, security, legal, and communication owners and backups.
  4. Exercise the incident scenarios and jurisdiction-specific notice matrix.
  5. Approve exact retention, deletion, backup-tombstone, and privacy-request workflows.
  6. Connect production monitoring and verify deployed browser-to-database behavior.

Report a concern

Use a minimized, adult contact path.

Do not include student names, records, credentials, exploit details that expose personal data, or other sensitive content in the public form. A dedicated coordinated-disclosure mailbox and response policy remain a launch requirement.

Start a security inquiry