Security & Trust Center
This page describes the core technical and operational controls Studyula uses to protect institution, learner and teacher data.
Last updated: 4 September 2026
Studyula uses a layered model across identity, authorization, tenant isolation, monitoring, backups, privacy requests and audit records rather than relying on a single security claim.
1. Identity and access
Role-based authorization separates learner, teacher, counselor and institution-admin access. Institution users can act only within authorized institutions and related academic data. Secure sessions, CSRF protection, rate limiting and account-security controls are applied.
2. Tenant isolation
Multi-tenant controls are designed to prevent classes, learners, teachers, courses, rooms and other resources from being incorrectly linked across institutions. Tenant validation is enforced server-side for critical institution features.
3. Data security and privacy
Studyula uses encrypted network communication, password hashing, role/permission controls, privacy-request workflows, data export/deletion, legal-consent records and data-minimization practices. Private learner AI conversations and personal notes are not automatically exposed in institution or guardian reports.
4. Operational resilience
Production uses health/readiness checks, operational observations, client-error telemetry, daily automated backups and controlled release validation. Type checking, tests, production builds and live smoke tests are part of the deployment approach.
5. Auditability
Authenticated mutating API operations are persistently recorded with actor, institution, action, resource, timestamp and request ID. Authorized institution administrators can review records in their institution Audit Log.
6. Certification status
Studyula does not currently claim SOC 2 or ISO 27001 certification. Security controls are part of product development; independent audits and certifications can be pursued as enterprise scale and market requirements grow.