Security
What we do with your material, in plain words.
Schools are handing us pupil records and exam material. This page says where it goes, who can reach it, and — just as importantly — what we have not done yet.
Where your material lives
Accounts, classrooms, question banks and progress records are stored in the platform database. Uploaded documents and generated media are held in object storage. Both are reachable only by the account or the school workspace they belong to.
A school workspace is a boundary: teachers in one school cannot see another school’s classrooms, question banks or pupil records.
Getting in
Sign-in is email and password with a server-side session cookie. Sessions are validated on the server for every protected page rather than trusted from the browser.
Roles decide what you can reach — a pupil, a teacher, a school admin and a platform admin see different things, and the check runs on the server, not in the interface.
What goes to a model provider
Generating a classroom sends your requirement and any material you attached to the model provider configured for your workspace — OpenAI, Google, Anthropic and others are supported, and a self-hosted model is supported too.
That means the content of what you upload does leave the platform when you generate. If that is unacceptable for your material, run a local model or ask us about a private deployment on the Enterprise plan.
We do not sell your material, publish it, or use it to train models.
Payments
Mobile money and card payments are handled by our payment provider. Card numbers do not touch our servers — we store the transaction reference and its status, not the instrument.
Operational practice
Traffic is served over HTTPS. Application errors are captured in an error-monitoring service so we can fix faults quickly; this can include technical context about a request.
Access to production systems is limited to the engineers who operate them.
What we have not done
- We hold no third-party security certification (no ISO 27001, no SOC 2). We are a small Zambian company and we will not imply otherwise.
- We have not commissioned an external penetration test yet.
- Single sign-on and audit logging are available on the Enterprise plan and are not part of the standard plans.
Found a vulnerability? Tell us before you tell anyone else and we will work with you on it. We do not run a paid bounty, but we will credit you.
[email protected]Lusaka · +260 978 825 597