Controls
Every security and privacy control, with its real status. A control is marked in place only once we hold evidence for it. Until then it shows as not yet verified. Controls tagged critical map to ST4S hash (#) controls: missing the minimum answer on any one of them makes the whole assessment non-compliant.
Infrastructure security
- Encryption in transitVerified 15 September 2026 →In place
All traffic between users, the app, the API, the database and third-party providers uses TLS 1.2 or higher. Plain HTTP is redirected.
CriticalST4S S1, S3, S5
- Not yet verified
Encryption at rest
The database, file storage and backups are encrypted at rest with AES-256 by Supabase on AWS.
CriticalST4S S2
- Tenant isolation with row-level securityVerified 15 September 2026 →In progress
Tables holding personal data are protected by Postgres row-level security scoped to the signed-in user and their school. Privileged keys never reach the browser.
CriticalST4S S4, A13, PR14
- Database functions and views locked to the serverVerified 15 September 2026 →In place
Functions and views that bypass row-level security can be used only by the server role, never by anonymous or signed-in browser sessions. New tables, views and functions are private to the server by default. Verified by probing the public API after the fixes on 15 September 2026.
CriticalST4S S4, S8, A13
- Not yet verified
Database not publicly reachable
Application servers reach the database through an SSL-required connection pooler. There is no anonymous or default admin access.
CriticalST4S S8, S9
- Web application firewall and DDoS protectionVerified 15 September 2026 →In place
Vercel Firewall sits in front of the app, the API and the website: DDoS mitigation at the edge, managed web application firewall rulesets (generic, remote code execution, cross-site scripting, SQL injection), per-IP rate limits on the API, and bot challenges on the public website.
CriticalST4S S7, S11
- Not yet verified
Separate production and development environments
Development uses a separate project seeded with synthetic data. Production data is not copied to development machines.
CriticalST4S S8, S13
- Not yet verified
TLS 1.3 with modern ciphers only
Hosts negotiate TLS 1.3 with AEAD (GCM or ChaCha20) ciphers; older protocols refused.
CriticalST4S S1, S3 (Tier 1 option D)
- Not yet verified
Host intrusion detection
Serverless hosting has no persistent hosts for Kuraplan to instrument; platform-level detection by Vercel and AWS is relied on and documented.
CriticalST4S S7 (Tier 1 requires IDS, WAF and anti-malware)
- Not yet verified
Key management process
Written process for generating, storing, rotating and revoking API keys, JWT secrets and provider credentials, with a rotation record.
ST4S S6
- Certificates from a trusted CA, auto-renewedVerified 15 September 2026 →In place
TLS certificates are issued by Let's Encrypt and renewed automatically by Vercel.
CriticalST4S S5
- Not yet verified
Notice before infrastructure or data moves country
Customers are told in advance, with a stated lead time, before hosting, data or people with access to unencrypted data relocate to another country.
CriticalST4S H5
Access control
- Not yet verified
Unique accounts for every user
Each teacher signs in with their own email and password or Google account. Shared school logins are not supported.
CriticalST4S A1, A12
- Not yet verified
Password hashing
Passwords are salted and hashed with bcrypt by Supabase Auth. Kuraplan never sees or stores plaintext passwords.
CriticalST4S A2
- Multi-factor authentication for all teacher and parent accountsVerified 16 September 2026 →In progress
Two-step sign-in with an authenticator app, available to every account from Settings, with a school-wide switch that requires it for all of a school's teachers. Built and reviewed on 16 September 2026; not yet released.
CriticalST4S A4 (Tier 1 = mandated for all non-student accounts)
- Passwordless sign-in with one-time codesVerified 15 September 2026 →In place
Kuraplan has no passwords. Teachers sign in with Google or a 6-digit code emailed to them: single use, expires after one hour, rate-limited. Codes are never stored in plain text.
CriticalST4S A2 (answered as option C with explanation: no passwords), A11 (not applicable)
- Not yet verified
MFA on all administrative consoles
Multi-factor authentication is required on GitHub, Supabase, Vercel, Stripe, Google Workspace, AI provider consoles and the domain registrar.
CriticalST4S A5
- Secure sign-in links and codesVerified 15 September 2026 →In place
There are no passwords to reset. Sign-in codes and magic links are random, single-use, expire after one hour and are delivered by email only.
CriticalST4S A11
- Deny by defaultVerified 15 September 2026 →In place
New users and roles have no access to any other user's data until explicitly granted by row-level security policy.
CriticalST4S A13
- Not yet verified
Documented roles and access review
A written access register covering product roles (teacher, school admin, Kuraplan admin) and every console, reviewed quarterly.
CriticalST4S A6, A7
- Not yet verified
No access to customer devices or networks
Kuraplan never requires remote access to school devices, networks or other systems, and never asks schools to share credentials.
ST4S A8, A9, A16A
Organisational security
- Not yet verified
Named security lead and privacy officer
The founder is the named security lead and privacy officer with written responsibilities, including liaison with the NZ Privacy Commissioner and the OAIC.
CriticalST4S GO1, GO2
- Not yet verified
Information security policy
A signed and dated policy covering management commitment, roles, access control, hardening, key management and device rules.
CriticalST4S Q7, S6, S10, S12
- Not yet verified
Background checks
Criminal history check for anyone with access to user data.
CriticalST4S HR1
- Not yet verified
Security awareness training
Annual completion of a recognised security, privacy and online-safety course, with a dated record.
CriticalST4S HR2
- Not yet verified
Device security
Work devices use full-disk encryption, a passcode, automatic screen lock within 15 minutes, remote wipe and automatic OS updates.
CriticalST4S S12, A10
- Not yet verified
Cyber insurance
Data breach cover of at least AUD 1M, including AI-related incidents.
ST4S P7
- Not yet verified
Same-day access removal
Documented process removing access for anyone who no longer needs it on the same day, and immediately on suspected malicious activity.
CriticalST4S HR3
- Not yet verified
Child-safety misconduct process
A process to identify, respond to and disclose any known child-safety misconduct or offences involving staff or contractors.
CriticalST4S SC3
- Not yet verified
No direct contact between Kuraplan staff and students
The service provides no way for Kuraplan personnel to message, tutor or otherwise interact with students.
ST4S HR4
- Not yet verified
Written agreements with integrated third parties
Agreements covering purpose, scope, scale, controls and data ownership for every native integration, starting with Google sign-in.
CriticalST4S INT7
Product security
- Dependency and vulnerability monitoringVerified 15 September 2026 →In progress
Dependencies are pinned with lockfiles and monitored for known vulnerabilities. Serverless hosting means there is no operating system for Kuraplan to patch.
CriticalST4S T1, T2
- Not yet verified
Security patch timelines
Internet-facing vulnerabilities patched within two weeks, or 48 hours where an exploit is known.
CriticalST4S T3, T4, T5
- Not yet verified
Independent penetration test
External penetration test annually and after major changes, with findings triaged by risk.
CriticalST4S T1
- Secure development lifecycleVerified 15 September 2026 →In progress
Every change goes branch, pull request, automated checks, preview deployment, review, then production. Threat modelling covers the AI pipeline.
CriticalST4S Q3, Q5, Q8
- Not yet verified
Payments handled by Stripe
Card details are entered into Stripe's PCI-DSS compliant checkout. Kuraplan systems never receive or store card numbers.
CriticalST4S CC2
- Upload validationVerified 16 September 2026 →In place
Uploads are limited to images and documents, validated by type and size, stored under randomised names and never executed. Images are re-encoded on upload. Documents are stored privately and served only through short-lived links for their owner.
ST4S PF13, PF51, PF52
- Not yet verified
Accessibility
Core flows audited against WCAG 2.1 AA with an exported report.
ST4S P14
Logging and incident response
- Public status page and uptime monitoringVerified 16 September 2026 →In place
status.kuraplan.com shows live health of the app, API, website and this site, with 90 days of history and email subscription for schools. Fed automatically by uptime checks every three minutes from four regions.
ST4S T6, Q2
- Not yet verified
Application and authentication logging
Authentication events, privileged actions and system errors are logged by Supabase, Vercel and Sentry with synchronised timestamps.
ST4S L1, PF39
- Error and anomaly alertingVerified 16 September 2026 →In place
Production errors reach the founder through Sentry; outages are detected by external uptime checks every three minutes from four regions and pushed to the founder's phone.
ST4S L2
- Incident response plan and registerVerified 16 September 2026 →In progress
A written plan for security, privacy, online-safety and AI incidents, with a register recording dates, actions and who was notified, and a public status page for customer communication.
CriticalST4S T6, AI_I2
- Not yet verified
Breach notification commitment
Affected schools are notified as soon as possible and within 72 hours of confirming a breach, with what was affected and what was disclosed. Regulators are notified as required by the NZ Privacy Act and the Australian Privacy Act.
CriticalST4S T7, T8, T8A
- Not yet verified
Centralised logging
Vercel and Supabase logs drained into one searchable store with at least 12 months' retention.
ST4S L4
- Not yet verified
Audit logs available to schools on request
Relevant logs are supplied to a school customer on request.
ST4S L3
- Not yet verified
Incident response plan tested annually
The plan is exercised at least once a year and after any major incident, with a dated record.
CriticalST4S T6A
Data and privacy
- Daily backupsVerified 16 September 2026 →In progress
Point-in-time recovery covers the last seven days continuously. A weekly encrypted backup is written to a second provider in a different region, and every backup run restores itself into a fresh database and checks row counts.
CriticalST4S D1, D3
- In progress
Backups retained for 90 days
Weekly backups are kept for 90 days and then deleted, so deleted data does not persist in backups beyond that.
ST4S D1
- Account deletion on requestVerified 16 September 2026 →In place
Teachers can delete their own account from Settings: everything they made is removed straight away, their sign-in is deleted, any personal subscription is cancelled, and a confirmation email is sent. Live for beta members first; requests by email are handled within 30 days.
CriticalST4S D2, PR13
- Not yet verified
Self-service data export
A download of all account data and created resources in reusable formats.
ST4S D6
- Not yet verified
Dormant account process
Accounts inactive for 24 months are warned by email, then deleted.
ST4S D5
- Not yet verified
Student activity data retention and deletion
Student names and answers from activities are deleted on the teacher's or school's request and automatically after a fixed period; teachers can delete a class's responses themselves.
ST4S D2, PF25, PF26
- Student names kept out of internal alerts and third partiesVerified 15 September 2026 →In progress
Operational alerts and subprocessors receive no student names. One activity alert currently includes the student's typed name; being removed.
CriticalST4S PR10, PR14, AI_G1A
- Not yet verified
No sale or advertising use of user data
User data is never sold or used to train AI models. Advertising conversion events with hashed identifiers still fire for kuraplan.com sign-ups; removing them for school users.
ST4S PR18, PR19, PR20
- Not yet verified
Marketing email is opt-in
Product news is sent only to users who opt in. Transactional email is separate. Unsubscribe is honoured immediately.
ST4S PR11
- No government identifiersVerified 15 September 2026 →In place
Kuraplan does not collect or store national student numbers, teacher registration numbers or similar identifiers.
CriticalST4S PR12
- Not yet verified
Privacy policy published, reviewed and versioned
Free to read, shown before use, reviewed at least annually, with version and date recorded.
CriticalST4S PR1, PR1B, PR1C
- Not yet verified
Privacy policy covers every required element
Kinds of information, how collected and held, purposes, recipients, consequences of not providing, access and correction, complaints, contact details, overseas disclosure and countries.
CriticalST4S PR2
- Not yet verified
Users must accept updated policies before continuing
When the privacy policy or terms change, users review and explicitly accept the new version before continuing to use the service.
CriticalST4S PR16
- In progress
Published subprocessor list
Every subprocessor with name, contact, data types and purpose, lawful basis, and countries of processing.
CriticalST4S PR17
- Not yet verified
Child-friendly acceptable use notice for students
Where students complete an activity, the acceptable-use text on the join screen is written for children.
ST4S SC1A
AI safety and privacy
- Not yet verified
No training on user data
Prompts and outputs are not used to train or fine-tune any model. Model providers are used under business terms with zero data retention where available.
CriticalST4S AI_PA1, AI_PA2, AI_T8
- In progress
Student AI use limited to the activity helper
Students have no accounts. Inside a teacher-shared activity they can use a helper chat (guidance only, never answers) and hints, rate-limited and length-limited, with the student's name kept out of the model call. Real-time detection of harmful inputs with alerting to the school, and a crisis-response protocol, are not yet built.
CriticalST4S AI_A1, AI_SF5
- Personal information kept out of promptsVerified 16 September 2026 →In progress
Kuraplan Shield swaps names, emails, phone numbers, student IDs, dates of birth and addresses for placeholders before any request reaches a model, and puts them back in the reply. Live for accounts that turn it on; default-on rollout to follow.
CriticalST4S AI_G1A, AI_PF8, AI_SF6
- Not yet verified
AI output disclosure
Generated content is labelled as AI-generated with a notice that it may be inaccurate or biased, in the product and on exported resources.
CriticalST4S AI_PF1, AI_PF1A
- Not yet verified
Report and feedback on outputs
Thumbs up or down and a report button on every AI output, with reported content reviewed within two business days.
CriticalST4S AI_PF4, AI_PF5, AI_PF6
- Not yet verified
Personalisation is opt-in
Any memory of a teacher's preferences used to tailor prompts is off by default and controlled in settings.
CriticalST4S AI_PR1, AI_PR2, AI_PR4
- Not yet verified
Output moderation
Provider-side safety filters plus Kuraplan's own checks on generated content, with a removal path for anything inappropriate.
CriticalST4S AI_SF4, SC6, PF22
- Not yet verified
Model inventory and change notice
A published list of the models and providers in use, with notice to users before the hosting country of any model changes.
CriticalST4S AI_G5, AI_G6, AI_H1, AI_H2, AI_T7
- Not yet verified
AI security, privacy and safety testing
Quarterly jailbreak and prompt-injection tests, PII-leak tests in CI, and a bias and content-integrity eval set, with reports kept.
CriticalST4S AI_T2, AI_T3, AI_T4
- Not yet verified
AI not used for any excluded purpose
No processing of personal information, profiling, biometrics, student monitoring, administrative decisions, note-taking, health data, or content pulled from connected repositories. Each item answered individually.
CriticalST4S AI_G1
- Not yet verified
Schools can disable AI features for their users
A school administrator can switch AI features off for all of the school's users, or request it.
ST4S AI_G1B
- Not yet verified
Responsible AI framework and ethics policy
A published framework covering governance, design and development, testing and deployment, communication, and accountability.
CriticalST4S AI_T1
- Not yet verified
OWASP AI security guidance applied
OWASP Machine Learning Security Top 10 and the OWASP AI Security and Privacy Guide reviewed, with each item mapped to what Kuraplan does or why it does not apply.
CriticalST4S AI_T5, AI_T6
- Not yet verified
AI training records and test data
No models are trained or fine-tuned by Kuraplan; testing uses synthetic or de-identified data only.
CriticalST4S AI_T9, AI_T10
- Not yet verified
AI training for everyone who builds or supports AI features
Ethical AI, user-centred design, compliance, privacy, cybersecurity and online safety, with dated completion records.
CriticalST4S AI_HR1
- Not yet verified
Named AI safety role, separate from product ownership
A designated person, not the product owner, responsible for AI risk assessment, safety guidelines, monitoring, data governance and complaints.
CriticalST4S AI_GO1
- Not yet verified
AI privacy statement and consent controls
A clear statement of what personal information AI features use, why, for how long, who it is shared with, and how to withdraw; plus settings to stop prompts being shared with third parties.
CriticalST4S AI_PR3, AI_PR4, AI_PR6
- Not yet verified
User guidance on using AI well and safely
Help material on how the AI works, using it effectively and responsibly, spotting bias, privacy and consent, legal obligations, and how to report problems.
CriticalST4S AI_PF9
- Not yet verified
Session limits and crisis safeguards for interactive AI
School administrators can set chat limits for their users, and a documented crisis-response protocol (signposting, safe mode, escalation to the school) covers the student helper chat and teacher chat.
ST4S AI_SF7, AI_SF8