Data safety
Safety is a system, not a slogan.
Here is how EduAlly protects accounts, learning activity, files, and higher-risk workflows—and where users share responsibility.
Last updated August 22, 2026
Our approach
EduAlly uses layers of safeguards because no single control can protect every part of a learning platform. Protections cover sign-in, role-based access, network requests, files, sessions, security monitoring, and higher-risk assessment workflows.
No internet service can guarantee perfect security. We continue to review safeguards as the platform, threat landscape, and research program change.
Account protection
- Email verification helps confirm account ownership.
- Passwords, email one-time codes, magic links, and passkeys are supported sign-in methods.
- Passkeys can provide a phishing-resistant option, and extra verification is required for protected exam actions.
- Active sessions are limited, and users can review or switch device sessions.
- Repeated failed sign-in attempts are rate-limited and logged; suspicious activity can trigger an alert.
Your choices matter too: use a unique password, prefer a passkey when available, protect one-time codes, and sign out on shared devices.
Access and privacy controls
Access to course, submission, and administrative information is tied to user roles and course relationships. Privacy settings let users control parts of profile visibility and communication. Protected routes require an authenticated account. Email verification helps confirm ownership before normal app use.
EduAlly also keeps audit records for important security and administrative activity, including specialized access to secure-exam evidence. These records help investigate misuse and enforce accountability.
Application and network safeguards
EduAlly is configured for secure web delivery and applies browser protections that limit where scripts, connections, images, and forms may load or submit. Additional headers reduce framing, content-type confusion, and unnecessary browser access to camera, microphone, and location.
Request-rate limits help reduce automated attacks against sign-in and API routes. The app also restricts unsupported request methods and isolates secure-exam pages with stricter controls.
Data and file handling
Structured platform records are stored in a managed database, while uploaded files are handled through managed object storage. File operations use scoped, time-limited links where the workflow calls for them. EduAlly records ownership and course relationships so access decisions can be enforced.
Information sent to an AI feature may be processed by an AI provider to generate a response or embedding. Only put information into a prompt or file when it is appropriate for the course and permitted by your institution.
Monitoring and response
Security logs, application error monitoring, and operational checks help the team detect failed logins, suspicious events, broken safeguards, and service problems. Account deletion and session-revocation workflows are available, with notifications for important account events.
If you notice unexpected account activity, change your credentials, revoke unfamiliar sessions when available, and contact EduAlly support or your institutional contact promptly. Do not send passwords, passkeys, or one-time codes to anyone.
What safety does not mean
Security controls reduce risk; they do not make EduAlly an appropriate place for every kind of information. Avoid entering government identifiers, financial details, medical records, or unrelated confidential information. Follow instructor and institutional guidance for student records and protected data.
Data safety and research transparency work together. Read the Research & Data Guide for how information may support study, and the Privacy Policy for collection, sharing, retention, and choices.