Scoped access exists
Server-side roles and principal-scoped reads protect administrator, staff, student, grading, quiz, and file flows.
Confirmed from codeA public-safe summary of what protects LMS data now, what is missing, and which launch decisions cannot be made by code.
Confirmed from codeInferred — requires confirmationMissing implementationBusiness/legal decision requiredThe repository contains meaningful application-level protections, but production infrastructure, lifecycle operations, provider governance, and several security controls remain incomplete or unverified.
Confirmed from codeInferred — requires confirmationMissing implementationServer-side roles and principal-scoped reads protect administrator, staff, student, grading, quiz, and file flows.
Confirmed from codeSecurity operations, production infrastructure, lifecycle tooling, and provider evidence remain incomplete or unverified.
Missing implementationOperator facts, jurisdictions, ages, providers, retention, incidents, and contracts require accountable human review.
Business/legal decision requiredEach factual or decision-bearing statement shows whether it is proven today, inferred and awaiting confirmation, missing from the product, or reserved for a human decision.
This is a readiness summary for [COMPANY LEGAL NAME] and [PRODUCT NAME]. It is not a data-processing agreement or proof of compliance, certification, production approval, or legal advice.
No production target, hosting dashboard, live database, vendor contract, backup system, security-monitoring platform, or active penetration test was reviewed.
The application stores account identity, credentials, course membership, assignments, submission attempts and files, grades, feedback, course content, announcements, discussions, quiz answers/results, and timestamps. The detailed categories and access map are reflected in the Privacy Policy draft.
Passwords are bcrypt-hashed. Login failures are generic. Administrator-set passwords must be changed, and password changes invalidate older sessions.
Server-side role checks, active-enrollment checks, resource re-scoping, and principal-scoped queries protect administrator, course-staff, and student records.
Inputs are validated, submission URLs are limited to HTTP(S), user Markdown blocks raw HTML and unsafe links, submitted attempts use database-backed immutability, storage keys are path-contained, and files download as private attachments with no-sniff headers.
Secrets are expected in ignored environment files, and the repository integrity check found no secrets in tracked files on 19 July 2026.
Launch-readiness gaps remain across authentication hardening, security operations, browser and platform defenses, private production storage, infrastructure resilience, and privacy-rights/account-lifecycle operations. Exact findings and remediation guidance stay in the internal security and compliance audit rather than this public summary.
Auth.js, Next.js, Prisma, PostgreSQL, and the local-disk storage adapter are confirmed runtime components.
The active database host is unknown because it is selected by secret configuration. Production hosting, storage, monitoring, support, backup, and processing regions are not confirmed.
No email, payment, analytics, advertising, AI, or production object-storage provider is integrated.
Select and document each provider’s legal name, purpose, data, regions, access, retention, deletion, subprocessors, security, contract, and transfer terms before use.
The schema has no institution/customer entity, guardian relationship, age gate, parental authorization, child-specific notice, or safeguarding-report workflow.
[LEGAL REVIEW REQUIRED] Confirm the customer model, responsibility for educational records, [MINIMUM AGE], target education levels, direct-signup policy, guardian or school authority, and child-safety obligations before live student use.
Academic attempts are versioned, timestamps are retained, and restrictive database relations preserve certain submission and quiz records.
There is no approved retention schedule, export generator, account-deletion workflow, privacy-request tracker, purge job, legal-hold process, or deletion evidence.
Approve record-by-record retention, academic-record exceptions, active and backup deletion, export scope, request authentication, holds, and appeals before implementation.
Phase 0: confirm product/operator identity, customer model, markets, ages, providers, retention, support, incident, pricing, cancellation, and refund decisions; freeze unsupported public claims.
Phase 1: implement authentication abuse controls, privileged-account protection, security headers/logging, production storage and file safety, backups, incident procedures, rights workflows, and lifecycle controls.
Phase 2: add email, payments, analytics, or AI only after feature-specific data flows, provider contracts, retention, user controls, security, human oversight, and support are approved.
Phase 3: verify the deployed domain, TLS, cookies, headers, private-route indexing, sitemap/robots behavior, mobile rendering, performance, backups, logs, and vendor settings with runtime evidence.
Security, infrastructure, privacy, finance, safeguarding, and education-record owners must verify operational promises. Qualified counsel in each applicable jurisdiction must review the legal drafts before publication or acceptance. No policy page establishes that the platform is legally compliant or safe for live student data.