SECURITY

Protect the classroom, preserve the relationship.

RSA combines limited collection, isolated classrooms, secure teacher access, and reviewed incident procedures. Security is an ongoing practice, not a one-time claim.Effective August 29, 2026 · RSA classroom pilot

Current safeguards

  • HTTPS protects information in transit.
  • Teacher access uses an approved email, a short-lived six-digit code, and an HTTP-only secure session cookie.
  • Login attempts are limited and codes expire after 10 minutes.
  • Classroom records and materials are scoped to the teacher’s classroom.
  • Teacher material changes and student follow-up acknowledgements require teacher authentication.
  • AI requests explicitly disable Responses API application-state storage.
  • Private coaching transcripts are not written to RSA’s classroom database.

Safety and integrity controls

Every student AI route uses the same safety screening before generation. High-risk language pauses coaching and directs the student toward a trusted adult or emergency support without automatically exposing the private conversation. Study requests that seek direct answers are redirected, and generated study replies receive a second academic-integrity review before reaching the learner.

Incident response

  1. Contain the issue and preserve only the operational evidence needed to investigate.
  2. Protect affected classrooms and rotate credentials when appropriate.
  3. Determine which records and people may be affected.
  4. Notify the appropriate pilot teacher, school contact, service provider, and authorities as required.
  5. Correct the cause, verify the fix, document the decision, and improve the relevant test.

Reporting a concern

Pilot teachers should use their existing RSA onboarding contact. Students and families should begin with the pilot teacher or school contact. Do not include unnecessary student details in the first report.