Access Control
Server-side session cookies, role checks, and Convex ownership checks protect dashboard and session data.
Operational safeguards for student data, payments, tutor workflows, and AI-assisted learning.
Server-side session cookies, role checks, and Convex ownership checks protect dashboard and session data.
Live payment flows fail closed when provider credentials are missing and verify transactions before subscription activation.
AI generation is protected by a fixed-window limiter with Cloudflare KV support for production.
Payment references, session attempts, timestamps, and analytics updates are persisted for operational review.
Privacy, retention, export, and deletion expectations are documented for students, parents, and schools.
Security issues can be reported to support for triage, containment, remediation, and post-incident review.