Draft for review. Statuses and facts are being verified before publication.
KuraplanTrust Center

Controls

Every security and privacy control, with its real status. A control is marked in place only once we hold evidence for it. Until then it shows as not yet verified. Controls tagged critical map to ST4S hash (#) controls: missing the minimum answer on any one of them makes the whole assessment non-compliant.

12 in place57 not yet verified11 in progress0 planned60 critical: failing any of these fails the assessmentUpdated 16 September 2026Mapped to ST4S Supplier Guide 2026.1 (21 June 2026)

Infrastructure security

  • Encryption in transitVerified 15 September 2026

    All traffic between users, the app, the API, the database and third-party providers uses TLS 1.2 or higher. Plain HTTP is redirected.

    CriticalST4S S1, S3, S5

    In place
  • Encryption at rest

    The database, file storage and backups are encrypted at rest with AES-256 by Supabase on AWS.

    CriticalST4S S2

    Not yet verified
  • Tenant isolation with row-level securityVerified 15 September 2026

    Tables holding personal data are protected by Postgres row-level security scoped to the signed-in user and their school. Privileged keys never reach the browser.

    CriticalST4S S4, A13, PR14

    In progress
  • Database functions and views locked to the serverVerified 15 September 2026

    Functions and views that bypass row-level security can be used only by the server role, never by anonymous or signed-in browser sessions. New tables, views and functions are private to the server by default. Verified by probing the public API after the fixes on 15 September 2026.

    CriticalST4S S4, S8, A13

    In place
  • Database not publicly reachable

    Application servers reach the database through an SSL-required connection pooler. There is no anonymous or default admin access.

    CriticalST4S S8, S9

    Not yet verified
  • Web application firewall and DDoS protectionVerified 15 September 2026

    Vercel Firewall sits in front of the app, the API and the website: DDoS mitigation at the edge, managed web application firewall rulesets (generic, remote code execution, cross-site scripting, SQL injection), per-IP rate limits on the API, and bot challenges on the public website.

    CriticalST4S S7, S11

    In place
  • Separate production and development environments

    Development uses a separate project seeded with synthetic data. Production data is not copied to development machines.

    CriticalST4S S8, S13

    Not yet verified
  • TLS 1.3 with modern ciphers only

    Hosts negotiate TLS 1.3 with AEAD (GCM or ChaCha20) ciphers; older protocols refused.

    CriticalST4S S1, S3 (Tier 1 option D)

    Not yet verified
  • Host intrusion detection

    Serverless hosting has no persistent hosts for Kuraplan to instrument; platform-level detection by Vercel and AWS is relied on and documented.

    CriticalST4S S7 (Tier 1 requires IDS, WAF and anti-malware)

    Not yet verified
  • Key management process

    Written process for generating, storing, rotating and revoking API keys, JWT secrets and provider credentials, with a rotation record.

    ST4S S6

    Not yet verified
  • Certificates from a trusted CA, auto-renewedVerified 15 September 2026

    TLS certificates are issued by Let's Encrypt and renewed automatically by Vercel.

    CriticalST4S S5

    In place
  • Notice before infrastructure or data moves country

    Customers are told in advance, with a stated lead time, before hosting, data or people with access to unencrypted data relocate to another country.

    CriticalST4S H5

    Not yet verified

Access control

  • Unique accounts for every user

    Each teacher signs in with their own email and password or Google account. Shared school logins are not supported.

    CriticalST4S A1, A12

    Not yet verified
  • Password hashing

    Passwords are salted and hashed with bcrypt by Supabase Auth. Kuraplan never sees or stores plaintext passwords.

    CriticalST4S A2

    Not yet verified
  • Multi-factor authentication for all teacher and parent accountsVerified 16 September 2026

    Two-step sign-in with an authenticator app, available to every account from Settings, with a school-wide switch that requires it for all of a school's teachers. Built and reviewed on 16 September 2026; not yet released.

    CriticalST4S A4 (Tier 1 = mandated for all non-student accounts)

    In progress
  • Passwordless sign-in with one-time codesVerified 15 September 2026

    Kuraplan has no passwords. Teachers sign in with Google or a 6-digit code emailed to them: single use, expires after one hour, rate-limited. Codes are never stored in plain text.

    CriticalST4S A2 (answered as option C with explanation: no passwords), A11 (not applicable)

    In place
  • MFA on all administrative consoles

    Multi-factor authentication is required on GitHub, Supabase, Vercel, Stripe, Google Workspace, AI provider consoles and the domain registrar.

    CriticalST4S A5

    Not yet verified
  • Secure sign-in links and codesVerified 15 September 2026

    There are no passwords to reset. Sign-in codes and magic links are random, single-use, expire after one hour and are delivered by email only.

    CriticalST4S A11

    In place
  • Deny by defaultVerified 15 September 2026

    New users and roles have no access to any other user's data until explicitly granted by row-level security policy.

    CriticalST4S A13

    In place
  • Documented roles and access review

    A written access register covering product roles (teacher, school admin, Kuraplan admin) and every console, reviewed quarterly.

    CriticalST4S A6, A7

    Not yet verified
  • No access to customer devices or networks

    Kuraplan never requires remote access to school devices, networks or other systems, and never asks schools to share credentials.

    ST4S A8, A9, A16A

    Not yet verified

Organisational security

  • Named security lead and privacy officer

    The founder is the named security lead and privacy officer with written responsibilities, including liaison with the NZ Privacy Commissioner and the OAIC.

    CriticalST4S GO1, GO2

    Not yet verified
  • Information security policy

    A signed and dated policy covering management commitment, roles, access control, hardening, key management and device rules.

    CriticalST4S Q7, S6, S10, S12

    Not yet verified
  • Background checks

    Criminal history check for anyone with access to user data.

    CriticalST4S HR1

    Not yet verified
  • Security awareness training

    Annual completion of a recognised security, privacy and online-safety course, with a dated record.

    CriticalST4S HR2

    Not yet verified
  • Device security

    Work devices use full-disk encryption, a passcode, automatic screen lock within 15 minutes, remote wipe and automatic OS updates.

    CriticalST4S S12, A10

    Not yet verified
  • Cyber insurance

    Data breach cover of at least AUD 1M, including AI-related incidents.

    ST4S P7

    Not yet verified
  • Same-day access removal

    Documented process removing access for anyone who no longer needs it on the same day, and immediately on suspected malicious activity.

    CriticalST4S HR3

    Not yet verified
  • Child-safety misconduct process

    A process to identify, respond to and disclose any known child-safety misconduct or offences involving staff or contractors.

    CriticalST4S SC3

    Not yet verified
  • No direct contact between Kuraplan staff and students

    The service provides no way for Kuraplan personnel to message, tutor or otherwise interact with students.

    ST4S HR4

    Not yet verified
  • Written agreements with integrated third parties

    Agreements covering purpose, scope, scale, controls and data ownership for every native integration, starting with Google sign-in.

    CriticalST4S INT7

    Not yet verified

Product security

  • Dependency and vulnerability monitoringVerified 15 September 2026

    Dependencies are pinned with lockfiles and monitored for known vulnerabilities. Serverless hosting means there is no operating system for Kuraplan to patch.

    CriticalST4S T1, T2

    In progress
  • Security patch timelines

    Internet-facing vulnerabilities patched within two weeks, or 48 hours where an exploit is known.

    CriticalST4S T3, T4, T5

    Not yet verified
  • Independent penetration test

    External penetration test annually and after major changes, with findings triaged by risk.

    CriticalST4S T1

    Not yet verified
  • Secure development lifecycleVerified 15 September 2026

    Every change goes branch, pull request, automated checks, preview deployment, review, then production. Threat modelling covers the AI pipeline.

    CriticalST4S Q3, Q5, Q8

    In progress
  • Payments handled by Stripe

    Card details are entered into Stripe's PCI-DSS compliant checkout. Kuraplan systems never receive or store card numbers.

    CriticalST4S CC2

    Not yet verified
  • Upload validationVerified 16 September 2026

    Uploads are limited to images and documents, validated by type and size, stored under randomised names and never executed. Images are re-encoded on upload. Documents are stored privately and served only through short-lived links for their owner.

    ST4S PF13, PF51, PF52

    In place
  • Accessibility

    Core flows audited against WCAG 2.1 AA with an exported report.

    ST4S P14

    Not yet verified

Logging and incident response

  • Public status page and uptime monitoringVerified 16 September 2026

    status.kuraplan.com shows live health of the app, API, website and this site, with 90 days of history and email subscription for schools. Fed automatically by uptime checks every three minutes from four regions.

    ST4S T6, Q2

    In place
  • Application and authentication logging

    Authentication events, privileged actions and system errors are logged by Supabase, Vercel and Sentry with synchronised timestamps.

    ST4S L1, PF39

    Not yet verified
  • Error and anomaly alertingVerified 16 September 2026

    Production errors reach the founder through Sentry; outages are detected by external uptime checks every three minutes from four regions and pushed to the founder's phone.

    ST4S L2

    In place
  • Incident response plan and registerVerified 16 September 2026

    A written plan for security, privacy, online-safety and AI incidents, with a register recording dates, actions and who was notified, and a public status page for customer communication.

    CriticalST4S T6, AI_I2

    In progress
  • Breach notification commitment

    Affected schools are notified as soon as possible and within 72 hours of confirming a breach, with what was affected and what was disclosed. Regulators are notified as required by the NZ Privacy Act and the Australian Privacy Act.

    CriticalST4S T7, T8, T8A

    Not yet verified
  • Centralised logging

    Vercel and Supabase logs drained into one searchable store with at least 12 months' retention.

    ST4S L4

    Not yet verified
  • Audit logs available to schools on request

    Relevant logs are supplied to a school customer on request.

    ST4S L3

    Not yet verified
  • Incident response plan tested annually

    The plan is exercised at least once a year and after any major incident, with a dated record.

    CriticalST4S T6A

    Not yet verified

Data and privacy

  • Daily backupsVerified 16 September 2026

    Point-in-time recovery covers the last seven days continuously. A weekly encrypted backup is written to a second provider in a different region, and every backup run restores itself into a fresh database and checks row counts.

    CriticalST4S D1, D3

    In progress
  • Backups retained for 90 days

    Weekly backups are kept for 90 days and then deleted, so deleted data does not persist in backups beyond that.

    ST4S D1

    In progress
  • Account deletion on requestVerified 16 September 2026

    Teachers can delete their own account from Settings: everything they made is removed straight away, their sign-in is deleted, any personal subscription is cancelled, and a confirmation email is sent. Live for beta members first; requests by email are handled within 30 days.

    CriticalST4S D2, PR13

    In place
  • Self-service data export

    A download of all account data and created resources in reusable formats.

    ST4S D6

    Not yet verified
  • Dormant account process

    Accounts inactive for 24 months are warned by email, then deleted.

    ST4S D5

    Not yet verified
  • Student activity data retention and deletion

    Student names and answers from activities are deleted on the teacher's or school's request and automatically after a fixed period; teachers can delete a class's responses themselves.

    ST4S D2, PF25, PF26

    Not yet verified
  • Student names kept out of internal alerts and third partiesVerified 15 September 2026

    Operational alerts and subprocessors receive no student names. One activity alert currently includes the student's typed name; being removed.

    CriticalST4S PR10, PR14, AI_G1A

    In progress
  • No sale or advertising use of user data

    User data is never sold or used to train AI models. Advertising conversion events with hashed identifiers still fire for kuraplan.com sign-ups; removing them for school users.

    ST4S PR18, PR19, PR20

    Not yet verified
  • Marketing email is opt-in

    Product news is sent only to users who opt in. Transactional email is separate. Unsubscribe is honoured immediately.

    ST4S PR11

    Not yet verified
  • No government identifiersVerified 15 September 2026

    Kuraplan does not collect or store national student numbers, teacher registration numbers or similar identifiers.

    CriticalST4S PR12

    In place
  • Privacy policy published, reviewed and versioned

    Free to read, shown before use, reviewed at least annually, with version and date recorded.

    CriticalST4S PR1, PR1B, PR1C

    Not yet verified
  • Privacy policy covers every required element

    Kinds of information, how collected and held, purposes, recipients, consequences of not providing, access and correction, complaints, contact details, overseas disclosure and countries.

    CriticalST4S PR2

    Not yet verified
  • Users must accept updated policies before continuing

    When the privacy policy or terms change, users review and explicitly accept the new version before continuing to use the service.

    CriticalST4S PR16

    Not yet verified
  • Published subprocessor list

    Every subprocessor with name, contact, data types and purpose, lawful basis, and countries of processing.

    CriticalST4S PR17

    In progress
  • Child-friendly acceptable use notice for students

    Where students complete an activity, the acceptable-use text on the join screen is written for children.

    ST4S SC1A

    Not yet verified

AI safety and privacy

  • No training on user data

    Prompts and outputs are not used to train or fine-tune any model. Model providers are used under business terms with zero data retention where available.

    CriticalST4S AI_PA1, AI_PA2, AI_T8

    Not yet verified
  • Student AI use limited to the activity helper

    Students have no accounts. Inside a teacher-shared activity they can use a helper chat (guidance only, never answers) and hints, rate-limited and length-limited, with the student's name kept out of the model call. Real-time detection of harmful inputs with alerting to the school, and a crisis-response protocol, are not yet built.

    CriticalST4S AI_A1, AI_SF5

    In progress
  • Personal information kept out of promptsVerified 16 September 2026

    Kuraplan Shield swaps names, emails, phone numbers, student IDs, dates of birth and addresses for placeholders before any request reaches a model, and puts them back in the reply. Live for accounts that turn it on; default-on rollout to follow.

    CriticalST4S AI_G1A, AI_PF8, AI_SF6

    In progress
  • AI output disclosure

    Generated content is labelled as AI-generated with a notice that it may be inaccurate or biased, in the product and on exported resources.

    CriticalST4S AI_PF1, AI_PF1A

    Not yet verified
  • Report and feedback on outputs

    Thumbs up or down and a report button on every AI output, with reported content reviewed within two business days.

    CriticalST4S AI_PF4, AI_PF5, AI_PF6

    Not yet verified
  • Personalisation is opt-in

    Any memory of a teacher's preferences used to tailor prompts is off by default and controlled in settings.

    CriticalST4S AI_PR1, AI_PR2, AI_PR4

    Not yet verified
  • Output moderation

    Provider-side safety filters plus Kuraplan's own checks on generated content, with a removal path for anything inappropriate.

    CriticalST4S AI_SF4, SC6, PF22

    Not yet verified
  • Model inventory and change notice

    A published list of the models and providers in use, with notice to users before the hosting country of any model changes.

    CriticalST4S AI_G5, AI_G6, AI_H1, AI_H2, AI_T7

    Not yet verified
  • AI security, privacy and safety testing

    Quarterly jailbreak and prompt-injection tests, PII-leak tests in CI, and a bias and content-integrity eval set, with reports kept.

    CriticalST4S AI_T2, AI_T3, AI_T4

    Not yet verified
  • AI not used for any excluded purpose

    No processing of personal information, profiling, biometrics, student monitoring, administrative decisions, note-taking, health data, or content pulled from connected repositories. Each item answered individually.

    CriticalST4S AI_G1

    Not yet verified
  • Schools can disable AI features for their users

    A school administrator can switch AI features off for all of the school's users, or request it.

    ST4S AI_G1B

    Not yet verified
  • Responsible AI framework and ethics policy

    A published framework covering governance, design and development, testing and deployment, communication, and accountability.

    CriticalST4S AI_T1

    Not yet verified
  • OWASP AI security guidance applied

    OWASP Machine Learning Security Top 10 and the OWASP AI Security and Privacy Guide reviewed, with each item mapped to what Kuraplan does or why it does not apply.

    CriticalST4S AI_T5, AI_T6

    Not yet verified
  • AI training records and test data

    No models are trained or fine-tuned by Kuraplan; testing uses synthetic or de-identified data only.

    CriticalST4S AI_T9, AI_T10

    Not yet verified
  • AI training for everyone who builds or supports AI features

    Ethical AI, user-centred design, compliance, privacy, cybersecurity and online safety, with dated completion records.

    CriticalST4S AI_HR1

    Not yet verified
  • Named AI safety role, separate from product ownership

    A designated person, not the product owner, responsible for AI risk assessment, safety guidelines, monitoring, data governance and complaints.

    CriticalST4S AI_GO1

    Not yet verified
  • AI privacy statement and consent controls

    A clear statement of what personal information AI features use, why, for how long, who it is shared with, and how to withdraw; plus settings to stop prompts being shared with third parties.

    CriticalST4S AI_PR3, AI_PR4, AI_PR6

    Not yet verified
  • User guidance on using AI well and safely

    Help material on how the AI works, using it effectively and responsibly, spotting bias, privacy and consent, legal obligations, and how to report problems.

    CriticalST4S AI_PF9

    Not yet verified
  • Session limits and crisis safeguards for interactive AI

    School administrators can set chat limits for their users, and a documented crisis-response protocol (signposting, safe mode, escalation to the school) covers the student helper chat and teacher chat.

    ST4S AI_SF7, AI_SF8

    Not yet verified