LEG-011 · Legal & trust

Security is a release condition, not a badge.

A high-level explanation of the safeguards that must be evidenced before the real product is released.

Required policy · release-bound evidence requiredVersion: not approved
01

Private by default

Student information stays private. Authorization is enforced by both the API and the database policy layer.

02

Secrets stay on the server

Privileged credentials and provider keys must never enter client bundles or browser-reachable code. A missing or stale evidence item is a stop signal.

03

Safe failure

Private responses should be sanitized and not cached. Published content and audit events remain append-only, and local demo mode uses synthetic state only.

This page is a design placeholder for review. It does not create consent, change data rights or replace the approved contract, policy or legal notice.