Skip to content
All policies

Security

How we protect accounts, lesson content and institution data, and how to report a vulnerability.

Last updated March 1, 2026 · Santi Open University Ltd.

Our approach

Santi Tutor holds schoolwork, progress records and, for institutions, data about minors. We treat that as sensitive by default and design for least privilege, short retention and clear audit trails.

Infrastructure

  • Hosted with major cloud providers in regions chosen for proximity to learners.
  • Network isolation between public services, application services and data stores.
  • Infrastructure defined as code, with peer-reviewed changes and no manual production edits.
  • Automated daily backups with tested restore procedures.

Encryption

  • TLS 1.2 or higher for all traffic, with HSTS enabled.
  • AES-256 encryption at rest for databases, object storage and backups.
  • Passwords stored using a memory-hard hashing algorithm, never in plain text or reversibly encrypted.
  • Secrets held in a managed secret store with rotation, never in source control.

Access control

  • Role-based access with least privilege; production access is granted for a task and expires.
  • Mandatory multi-factor authentication for all staff accounts.
  • Access to lesson content requires an explicit, logged justification.
  • Quarterly access reviews and same-day revocation on offboarding.

Application security

  • Code review required on every change; no direct pushes to production branches.
  • Automated dependency scanning and static analysis in continuous integration.
  • Rate limiting and abuse detection on authentication and lesson endpoints.
  • Independent penetration testing, with material findings remediated on a tracked timeline.

AI-specific controls

  • Contracts with model providers prohibit training on customer content.
  • Prompt-injection and jailbreak filtering on user-supplied content.
  • Mathematical solutions verified symbolically before they are drawn.
  • Lesson content is not used to fine-tune third-party models.

For institutions

  • SSO with Google Workspace and Microsoft Entra ID, with enforced-SSO options.
  • Admin audit log covering roster changes, role changes and data exports.
  • Configurable retention and regional data residency.
  • Signed data-processing agreement and sub-processor list on request.

Incident response

We maintain a written incident-response plan with named owners and defined severity levels. Where a personal-data breach is likely to affect you, we notify affected users and the relevant regulator without undue delay and within any statutory deadline, and we publish a post-incident summary for significant incidents.

Reporting a vulnerability

Email security@santitutor.com with enough detail to reproduce the issue. We acknowledge reports within two business days and will keep you updated until it is resolved.

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, use only their own test accounts, and give us reasonable time to fix an issue before disclosing it. Please do not run automated scanning against production, access other users' data, or attempt denial-of-service testing.

Questions about this document? Write to privacy@santitutor.com. Other policies: Privacy Policy, Terms of Service, Cookie Policy, Data Policy.