One customer, one instance
Every customer runs an isolated stack — application, database, and storage. There is no shared database and no cross-customer access path.
Most of our customers serve minors. The architecture starts from that fact.
Every customer runs an isolated stack — application, database, and storage. There is no shared database and no cross-customer access path.
Instances are hosted in EU data centers (Germany/Finland), with TLS on every connection.
Students are identified by a server-side HMAC signature from your backend — the widget can't be impersonated from the browser.
Databases are backed up on a fixed schedule, and restores are tested before any customer goes live.
We process student data on your instructions, under a signed data processing addendum. On termination, data is exported to you and deleted. Sub-processors are listed publicly.