LEG-011 · Legal & trust
Security is a release condition, not a badge.
A high-level explanation of the safeguards that must be evidenced before the real product is released.
Required policy · release-bound evidence requiredVersion: not approved
01
Private by default
Student information stays private. Authorization is enforced by both the API and the database policy layer.
02
Secrets stay on the server
Privileged credentials and provider keys must never enter client bundles or browser-reachable code. A missing or stale evidence item is a stop signal.
03
Safe failure
Private responses should be sanitized and not cached. Published content and audit events remain append-only, and local demo mode uses synthetic state only.
This page is a design placeholder for review. It does not create consent, change data rights or replace the approved contract, policy or legal notice.