Server-verified access
Production flows resolve authenticated identity, academy membership, and role on the server. Browser-provided tenant or role fields are not trusted.
Trust center
This page separates controls verified in the current product from the policy, provider, and operating work still required before real minor-data production.
Verified now
Production flows resolve authenticated identity, academy membership, and role on the server. Browser-provided tenant or role fields are not trusted.
Tenant-scoped repositories, database constraints, and forced row-level security protect academy records. Anonymous and cross-tenant denial are tested.
Consequential schedule changes, parent-facing content, sensitive feedback, and persistent learning records require explicit authorized approval.
Sandbox, pending, failed, unknown, and externally executed states remain distinct. A sandbox capture is never presented as a real send.
Request logs use a strict metadata allowlist and exclude message content, identity, tenant values, tokens, secrets, network address, and minor data.
Provider credentials remain server-only. Production database connections require certificate-verified TLS and the public origin must use HTTPS.
Not claimed
Report a concern
Do not include student names, records, credentials, exploit details that expose personal data, or other sensitive content in the public form. A dedicated coordinated-disclosure mailbox and response policy remain a launch requirement.
Start a security inquiry