User content is supported
Course content, discussions, submissions, links, files, grades, and quizzes create real safety and misuse risks.
Confirmed from codeProposed safety, privacy, content, and security rules—with missing reporting and enforcement operations shown honestly.
Missing implementationBusiness/legal decision requiredThe product accepts educational content and files, but it does not yet provide the reporting, safeguarding, moderation, suspension, or appeal systems needed to operate these rules.
Confirmed from codeMissing implementationCourse content, discussions, submissions, links, files, grades, and quizzes create real safety and misuse risks.
Confirmed from codeReporting, safeguarding escalation, suspension, case management, and appeals are not implemented.
Missing implementationContacts, enforcement owners, age groups, jurisdictions, and procedures require human and legal decisions.
Business/legal decision requiredEach factual or decision-bearing statement shows whether it is proven today, inferred and awaiting confirmation, missing from the product, or reserved for a human decision.
The product lets administrators, teachers, teaching assistants, and students create or access course content, communications, assignments, submissions, grades, quiz material, and uploaded files.
If approved and validly accepted, this policy would apply to [PRODUCT NAME], operated by [COMPANY LEGAL NAME], and its authorized customers and users.
Relevant workflows accept text, sanitized Markdown, HTTP(S) links, and files up to 10 MB. Downloads are served as attachments through authorization-guarded routes.
Production file-safety policy and operational controls are incomplete. Exact gaps and proposed remediation remain documented in the internal security review.
Users must have authority to share content and must not upload malware, secrets, unlawfully obtained material, or content that violates another person’s rights. Institutions must configure membership carefully because course files are available to every active member of that course.
No abuse-report or safeguarding workflow is implemented. There is no case queue, account-suspension tool, moderation appeal, or emergency escalation path.
Reports require [ABUSE/SAFEGUARDING CONTACT] and security reports require [SECURITY CONTACT] after those channels are staffed and tested.
[LEGAL REVIEW REQUIRED] Define investigation, evidence preservation, notice, content restriction, role removal, suspension, termination, appeal, emergency disclosure, and institution or guardian escalation. Enforcement must be proportionate and documented.
Unauthorized production testing is prohibited. Authorized research requires written scope, targets, timing, data handling, safety, and disclosure terms.
No vulnerability-disclosure policy or staffed security-contact page exists.
Confirm [PRODUCT NAME], [COMPANY LEGAL NAME], [JURISDICTIONS], [AGE GROUPS], [REPORTING CONTACTS], [ENFORCEMENT OWNER], and [APPEAL PROCESS], then obtain qualified legal, safeguarding, and institutional review before acceptance.