Help center🔒 Trust & Security

For everyone

Bank-grade security: our 20-point standard

How ClassLingos protects teachers, parents and students — encryption, ownership checks, private vault, bot protection and a live compliance panel.

Encryption at rest and in transit

  • All traffic uses TLS 1.3 on Cloudflare's global edge.
  • High-risk personal data — parent phone numbers and WeChat IDs, two-factor secrets and identity-document extracts — is additionally encrypted field-by-field with AES-256-GCM. Even a database export cannot reveal it.
  • Passwords are stored only as bcrypt hashes (cost 12). Older hashes are upgraded silently the next time you sign in — no reset needed.

You can only ever see your own data

Every API request passes through a central security gate that checks your role (parent, teacher, admin) and then row-level ownership: a teacher only sees their own roster, a parent only their own children. Staff overrides are written to a tamper-evident security audit log the CEO reviews.

Sessions, bots and rate limits

  • Session cookies are HttpOnly, Secure, SameSite=Lax and use the __Host- prefix, so they cannot be read by scripts or sent cross-site.
  • Cloudflare Turnstile protects every public form (sign-up, sign-in, contact, waitlist) without CAPTCHAs.
  • Sign-in attempts are rate-limited (10 per 5 minutes) and every write is validated with strict schemas.

Live compliance panel

The CEO dashboard shows a real-time 9-point checklist (RLS, field encryption, bcrypt coverage, cookies, rate limiting, validation, Turnstile, AI fence, audit log) plus encryption coverage per column — so “secure” is measured, not assumed.

Full details in the Privacy Policy (sections 11–13) and Terms of Service (13–14). Questions: security@classlingos.com.