Constrain every database request
Application queries run in an authenticated transaction with the caller identity bound for policy evaluation.
- ✓Tenant and school row isolation
- ✓Student-own-work policies
- ✓Reviewer-own-feedback policies
The platform is designed so page appearance is never the security control. PostgreSQL row-level policies and restricted database roles enforce access.
Application queries run in an authenticated transaction with the caller identity bound for policy evaluation.
Student-facing assessment views omit answer columns; authorized staff retrieve guidance through restricted functions.
Runtime, login verification, and migration connections are separated. Production passwords and providers remain deployment blockers until configured.
This describes the current application architecture, not a third-party security certification. A production privacy policy, hosting configuration, retention schedule, incident process, and legal review are still required before launch.
No generic sales theatre. We’ll focus on curriculum, teaching workflow, privacy, and your pilot goals.