Security

What we do with your material, in plain words.

Schools are handing us pupil records and exam material. This page says where it goes, who can reach it, and — just as importantly — what we have not done yet.

Where your material lives

Accounts, classrooms, question banks and progress records are stored in the platform database. Uploaded documents and generated media are held in object storage. Both are reachable only by the account or the school workspace they belong to.

A school workspace is a boundary: teachers in one school cannot see another school’s classrooms, question banks or pupil records.

Getting in

Sign-in is email and password with a server-side session cookie. Sessions are validated on the server for every protected page rather than trusted from the browser.

Roles decide what you can reach — a pupil, a teacher, a school admin and a platform admin see different things, and the check runs on the server, not in the interface.

What goes to a model provider

Generating a classroom sends your requirement and any material you attached to the model provider configured for your workspace — OpenAI, Google, Anthropic and others are supported, and a self-hosted model is supported too.

That means the content of what you upload does leave the platform when you generate. If that is unacceptable for your material, run a local model or ask us about a private deployment on the Enterprise plan.

We do not sell your material, publish it, or use it to train models.

Payments

Mobile money and card payments are handled by our payment provider. Card numbers do not touch our servers — we store the transaction reference and its status, not the instrument.

Operational practice

Traffic is served over HTTPS. Application errors are captured in an error-monitoring service so we can fix faults quickly; this can include technical context about a request.

Access to production systems is limited to the engineers who operate them.

What we have not done

  • We hold no third-party security certification (no ISO 27001, no SOC 2). We are a small Zambian company and we will not imply otherwise.
  • We have not commissioned an external penetration test yet.
  • Single sign-on and audit logging are available on the Enterprise plan and are not part of the standard plans.
REPORT AN ISSUEOPEN

Found a vulnerability? Tell us before you tell anyone else and we will work with you on it. We do not run a paid bounty, but we will credit you.

[email protected]

Lusaka · +260 978 825 597