Security
What we do to keep student accounts and their work safe, and how to tell us if we have missed something.
Last updated 22 August 2026.
Accounts
- Passwords are hashed, never stored in a readable form, and never sent to us in an email.
- You can sign in with Google instead, so there is no extra password to lose.
- Email addresses are verified before an account becomes usable.
- Sessions are held in cookies that JavaScript cannot read and that are only sent to us.
Your material
- Uploads live in private object storage. The browser never talks to that storage directly — every file is fetched through the app, which checks it is yours first.
- File paths are generated by the server. A request cannot ask for a file by naming a path.
- Uploads are checked by file signature, not just by their name, and are size-capped.
- Anything you try on the homepage before signing up is scoped to that trial and deleted within 24 hours.
The application
- Everything is served over HTTPS, with HSTS.
- A Content Security Policy with per-request nonces limits what can run in the page.
- Requests that change data are origin-checked to prevent cross-site request forgery.
- Rate limits sit in front of sign-in, class codes, AI calls and the anonymous homepage tool.
- Administrative access is granted by server configuration only. There is no role that can be granted from inside the app.
Payments
Card details go straight to Stripe or Mollie and never reach our servers. Payment webhooks are signature-verified and processed once, so a replayed message cannot double-charge or double-credit an account.
Reporting a vulnerability
If you have found a security problem, please tell us before you tell anyone else, and give us a reasonable window to fix it. Report it through our contact page and include enough detail to reproduce it.
We will not pursue you for good-faith research that respects other people's data: do not access or alter an account that is not yours, do not run denial-of-service tests, and stop as soon as you have proved the point.
TO CONFIRM before launch: a dedicated security contact address, your disclosure window and whether you offer a bounty, plus a /.well-known/security.txt pointing at it.