Encryption
TLS in transit, encryption at rest, and secure secret management.
The production classroom application should treat security, privacy, access control, data isolation, and operational resilience as foundational architecture—not procurement paperwork added at the end.
TLS in transit, encryption at rest, and secure secret management.
Role-based permissions for students, teachers, administrators, and internal staff.
Server-side school scoping so one school cannot retrieve another school’s resources.
Record sensitive administrative and staff access without placing raw student content in routine logs.
Backups, restoration testing, rate limiting, dependency scanning, and incident-response procedures.
MFA for sensitive internal/admin functions and controlled access to production systems.
These are roadmap commitments, not claims that every document or control is already production-complete.