Skip to main content
LMS
Learning Management System
FeaturesSolutionsPricingResourcesAbout
Legal & trust
FeaturesSolutionsPricingResourcesAboutLegal & trust
Home/Data Protection Readiness
Trust · Repository readiness

Data Protection Readiness

A public-safe summary of what protects LMS data now, what is missing, and which launch decisions cannot be made by code.

1Confirmed from code3Inferred — requires confirmation4Missing implementation5Business/legal decision required
Last updated: 19 July 2026Readiness summary · Not a DPA5Business/legal decision required
On this page9 entries
  • 1. What this page is
  • 2. Data that needs protection
  • 3. Protections implemented in application code
  • 4. Launch-critical controls not implemented or evidenced
  • 5. Providers and locations
  • 6. Student, child, and institution decisions
  • 7. Retention, export, and deletion
  • 8. Production launch gate
  • 9. Human review required
On this page
  • 1. What this page is
  • 2. Data that needs protection
  • 3. Protections implemented in application code
  • 4. Launch-critical controls not implemented or evidenced
  • 5. Providers and locations
  • 6. Student, child, and institution decisions
  • 7. Retention, export, and deletion
  • 8. Production launch gate
  • 9. Human review required
Plain-language overview

Read this first

The repository contains meaningful application-level protections, but production infrastructure, lifecycle operations, provider governance, and several security controls remain incomplete or unverified.

1Confirmed from code3Inferred — requires confirmation4Missing implementation
01

Scoped access exists

Server-side roles and principal-scoped reads protect administrator, staff, student, grading, quiz, and file flows.

1Confirmed from code
02

Production controls are incomplete

Security operations, production infrastructure, lifecycle tooling, and provider evidence remain incomplete or unverified.

4Missing implementation
03

Launch needs owners

Operator facts, jurisdictions, ages, providers, retention, incidents, and contracts require accountable human review.

5Business/legal decision required
Repository evidence

How to read these drafts

Each factual or decision-bearing statement shows whether it is proven today, inferred and awaiting confirmation, missing from the product, or reserved for a human decision.

  • 1Confirmed from code
  • 2Confirmed from configuration
  • 3Inferred — requires confirmation
  • 4Missing implementation
  • 5Business/legal decision required
5Business/legal decision requiredThis draft is not legal advice, a data-processing agreement, a security certification, or proof of compliance. It intentionally omits exploit details while preserving the launch blockers future builders and reviewers must resolve.

1What this page is

5Business/legal decision required

This is a readiness summary for [COMPANY LEGAL NAME] and [PRODUCT NAME]. It is not a data-processing agreement or proof of compliance, certification, production approval, or legal advice.

3Inferred — requires confirmation

No production target, hosting dashboard, live database, vendor contract, backup system, security-monitoring platform, or active penetration test was reviewed.

2Data that needs protection

1Confirmed from code

The application stores account identity, credentials, course membership, assignments, submission attempts and files, grades, feedback, course content, announcements, discussions, quiz answers/results, and timestamps. The detailed categories and access map are reflected in the Privacy Policy draft.

3Protections implemented in application code

1Confirmed from code

Passwords are bcrypt-hashed. Login failures are generic. Administrator-set passwords must be changed, and password changes invalidate older sessions.

1Confirmed from code

Server-side role checks, active-enrollment checks, resource re-scoping, and principal-scoped queries protect administrator, course-staff, and student records.

1Confirmed from code

Inputs are validated, submission URLs are limited to HTTP(S), user Markdown blocks raw HTML and unsafe links, submitted attempts use database-backed immutability, storage keys are path-contained, and files download as private attachments with no-sniff headers.

2Confirmed from configuration

Secrets are expected in ignored environment files, and the repository integrity check found no secrets in tracked files on 19 July 2026.

4Launch-critical controls not implemented or evidenced

4Missing implementation

Launch-readiness gaps remain across authentication hardening, security operations, browser and platform defenses, private production storage, infrastructure resilience, and privacy-rights/account-lifecycle operations. Exact findings and remediation guidance stay in the internal security and compliance audit rather than this public summary.

5Providers and locations

1Confirmed from code

Auth.js, Next.js, Prisma, PostgreSQL, and the local-disk storage adapter are confirmed runtime components.

3Inferred — requires confirmation

The active database host is unknown because it is selected by secret configuration. Production hosting, storage, monitoring, support, backup, and processing regions are not confirmed.

4Missing implementation

No email, payment, analytics, advertising, AI, or production object-storage provider is integrated.

5Business/legal decision required

Select and document each provider’s legal name, purpose, data, regions, access, retention, deletion, subprocessors, security, contract, and transfer terms before use.

6Student, child, and institution decisions

4Missing implementation

The schema has no institution/customer entity, guardian relationship, age gate, parental authorization, child-specific notice, or safeguarding-report workflow.

5Business/legal decision required

[LEGAL REVIEW REQUIRED] Confirm the customer model, responsibility for educational records, [MINIMUM AGE], target education levels, direct-signup policy, guardian or school authority, and child-safety obligations before live student use.

7Retention, export, and deletion

1Confirmed from code

Academic attempts are versioned, timestamps are retained, and restrictive database relations preserve certain submission and quiz records.

4Missing implementation

There is no approved retention schedule, export generator, account-deletion workflow, privacy-request tracker, purge job, legal-hold process, or deletion evidence.

5Business/legal decision required

Approve record-by-record retention, academic-record exceptions, active and backup deletion, export scope, request authentication, holds, and appeals before implementation.

8Production launch gate

5Business/legal decision required

Phase 0: confirm product/operator identity, customer model, markets, ages, providers, retention, support, incident, pricing, cancellation, and refund decisions; freeze unsupported public claims.

4Missing implementation

Phase 1: implement authentication abuse controls, privileged-account protection, security headers/logging, production storage and file safety, backups, incident procedures, rights workflows, and lifecycle controls.

5Business/legal decision required

Phase 2: add email, payments, analytics, or AI only after feature-specific data flows, provider contracts, retention, user controls, security, human oversight, and support are approved.

3Inferred — requires confirmation

Phase 3: verify the deployed domain, TLS, cookies, headers, private-route indexing, sitemap/robots behavior, mobile rendering, performance, backups, logs, and vendor settings with runtime evidence.

9Human review required

5Business/legal decision required

Security, infrastructure, privacy, finance, safeguarding, and education-record owners must verify operational promises. Qualified counsel in each applicable jurisdiction must review the legal drafts before publication or acceptance. No policy page establishes that the platform is legally compliant or safe for live student data.

LMS
Learning Management System

A repository-backed learning management project for courses, assignments, submissions, grading, files, discussions, and quizzes.

Platform

  • Course management
  • Assignments
  • Communication
  • Quizzes

Solutions

  • For teachers
  • For students
  • For institutions
  • Student lifecycle

Resources

  • Help centre
  • FAQ
  • Getting started
  • About us

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie & Storage
  • Acceptable Use
  • Refunds
  • Data Protection Readiness
  • Legal & trust center
© 2026 LMS project. Operator: [COMPANY LEGAL NAME].
Legal & trustPrivacyTermsCookies