Encryption at rest and in transit
- All traffic uses TLS 1.3 on Cloudflare's global edge.
- High-risk personal data — parent phone numbers and WeChat IDs, two-factor secrets and identity-document extracts — is additionally encrypted field-by-field with AES-256-GCM. Even a database export cannot reveal it.
- Passwords are stored only as bcrypt hashes (cost 12). Older hashes are upgraded silently the next time you sign in — no reset needed.
You can only ever see your own data
Every API request passes through a central security gate that checks your role (parent, teacher, admin) and then row-level ownership: a teacher only sees their own roster, a parent only their own children. Staff overrides are written to a tamper-evident security audit log the CEO reviews.
Sessions, bots and rate limits
- Session cookies are HttpOnly, Secure, SameSite=Lax and use the __Host- prefix, so they cannot be read by scripts or sent cross-site.
- Cloudflare Turnstile protects every public form (sign-up, sign-in, contact, waitlist) without CAPTCHAs.
- Sign-in attempts are rate-limited (10 per 5 minutes) and every write is validated with strict schemas.
Live compliance panel
The CEO dashboard shows a real-time 9-point checklist (RLS, field encryption, bcrypt coverage, cookies, rate limiting, validation, Turnstile, AI fence, audit log) plus encryption coverage per column — so “secure” is measured, not assumed.
Full details in the Privacy Policy (sections 11–13) and Terms of Service (13–14). Questions: security@classlingos.com.