Security Overview
A plain-language overview of platform safeguards, responsibilities, and reporting.
Effective July 1, 2026Security approach
Maynard Protocol Systems uses role-based institutional access, tenant-scoped data operations, private file storage, TLS-protected connections, server-held credentials, password-managed authentication, and audit records for sensitive evaluation and administrative actions.
Data and files
Production records are stored in Supabase. Evaluation audio, optional evaluation video, and supporting accreditation files use private storage and authenticated download paths. Targeted video review is limited to timestamp-adjacent frames requested by authorized faculty. Public website assets are separated from private institutional content.
AI safeguards
AI recommendations remain subject to instructor review. The system records overrides and supporting reasons, separates possible critical criteria from confirmed decisions, and does not expose server API keys to the browser.
Operational safeguards
Stripe webhook signatures are verified. Signup provisioning is idempotent. Failed payments, lifecycle events, and account setup status are tracked. Render health checks and production notifications should be enabled by the operator.
Shared responsibility
Institutions are responsible for user authorization, device security, appropriate content, workforce training, local retention rules, and promptly removing access. Users should not share credentials or upload unnecessary sensitive information.
No unsupported compliance claim
This overview does not certify HIPAA, FERPA, SOC 2, accreditation, or other regulatory compliance. Contractual assurances, security questionnaires, data-processing terms, and required compliance representations must be reviewed for each customer and use case.
Report a concern
Report suspected unauthorized access, exposed credentials, or security concerns through the Support page. Do not include passwords, API keys, payment card numbers, or unnecessary student information.