Security
How we protect coursework.
Plain-language security for students and institutions. This is not a penetration-test certificate.
Tenant isolation
Assignments, documents, reports, and shares are scoped to the signed-in account on the server — not only in the UI.
Encrypted fields
Sensitive draft content is field-encrypted at rest when encryption keys are configured. Losing those keys loses readability — we treat them as critical secrets.
Uploads
Files are validated by signature and size limits. Executable disguises are rejected. Optional malware scanning can be enabled in production.
Sessions & CSRF
Cookie sessions with CSRF protection on state-changing requests. Production should run with secure cookies over HTTPS.
What we do not claim
We do not claim guaranteed grades, human grading, or perfect detection accuracy. AI feedback is diagnostic only.
Questions: hello@academiccheck.ai