Security
Layered protection for identity, curriculum, and classroom records.
This page distinguishes VPPO’s application controls from its hosting provider’s independent reports so schools can evaluate the service without inflated claims.
Identity and authorization
Prestwick House remains the adult identity source. VPPO does not store adult passwords. Signed sessions are HTTP-only, secure in production, audience-restricted, and shorter for students on shared school devices. Protected pages, actions, media, results, and teacher material re-check role, organization, entitlement, level, class ownership, and seat status on the server near the data being accessed.
Network and browser protection
Production traffic uses HTTPS with strict transport security. VPPO enforces its canonical host and sends a content security policy, anti-framing, content-type, referrer, browser-permission, and origin isolation headers. Authentication and upload abuse counters persist across deploys and application replicas; their stored keys are protected digests rather than raw IPs, emails, user IDs, or class codes.
Student work and answer protection
Student-rendered question payloads exclude correct-answer flags, accepted answers, private feedback, and answer keys. Grading runs on the server. Curriculum audio is private and served through authorized routes. Support attachments require an authenticated adult, ticket ownership or staff authority, a same-origin request, size and quota checks, an allowed media type, and matching file signatures.
Data and operations
The production PostgreSQL service is reached over Railway’s private network and has no public database TCP endpoint. Privileged tools are role-restricted. Important login, access, classroom, assessment, content, support, messaging, and commerce events enter a retention-bound activity ledger with sensitive detail fields redacted. Security logs do not store student answers or PIN values.
Independent evidence and current status
Railway publishes SOC 2 Type II and SOC 3 reports and related hosting control material through its Trust Center. Those reports cover Railway’s platform; they are not a certification of VPPO. Prestwick House is building VPPO’s own verification record against OWASP ASVS 5.0 and is preparing school-facing student-data and incident-response materials. VPPO does not currently claim its own SOC 2 or ISO 27001 certification.
Student privacy compliance
FERPA does not issue vendor certifications. A school’s use generally requires contractual control over the educational records and limits on use and redisclosure. For children under 13, school authorization under COPPA must genuinely come from the school and cover the collection in the Student Data Notice. A signed school data-protection agreement may add state-specific terms.
Report a security concern
Email contact@vppo.app with the affected URL, approximate time, account email, and a concise description. Do not email passwords, student PINs, answer keys, or student responses. Prestwick House will preserve evidence, assess scope, contain the issue, and coordinate required school or legal notification.
Security overview · Updated August 21, 2026