Skip to main content
Launch trust center

Security, source safety, and provider truth without fake launch claims.

PrepAI is designed around deterministic practice, role-separated portals, answer-masked retrieval, review-gated content, and provider-state honesty. Source evidence is named below; live provider-owned states remain UNKNOWN until their dashboards prove them.

Live-state boundary

GitHub source and local tests prove source behavior. Provider dashboards prove live runtime, database, auth, billing, webhook, and environment state. This page does not convert UNKNOWN into verified.

  • Live Supabase applied schema, RLS, grants, and Auth provider settings: UNKNOWN
  • Stripe live credentials, price objects, checkout, webhooks, and tier flips: UNKNOWN
  • Legal/source clearance beyond source locators and review-gated contracts: UNKNOWN
  • Live helpdesk/email provider, SLA, and external support delivery: UNKNOWN

Trust boundaries

Each boundary names what is source-tested today and what still needs provider or legal authority before it becomes a live claim.

Supabase Auth boundary

Source-enforced

PrepAI uses Supabase Auth as the only account source. The backend rejects malformed, expired, unsigned, and wrong-signature JWTs.

Proof: backend/app/middleware/supabase_auth.py and backend/tests/unit/test_auth_security_contract.py

Role split

Source-tested

Student, teacher, school-admin, parent, and content-admin controls are separated by route and source contract. Founder admin entitlement is allowlisted in code.

Proof: frontend/tests/navigation-role-contract.test.mjs and backend/tests/unit/test_admin_allowlist.py

Answer masking

Source-tested

Practice and DPP payloads omit answer keys, explanations, rubrics, and solutions until the learner commits an answer.

Proof: backend/tests/unit/test_answer_key_masking_contract.py

RLS matrix

Source-only; live UNKNOWN

Supabase migration source classifies public curriculum, student telemetry, teacher/classroom data, admin content review, and provider state.

Proof: docs/product/supabase-migration-subset-rls-matrix-v1.md

Official source handling

Review-gated

NCERT and CBSE sources guide locators, metadata, and review queues. PrepAI does not redistribute unofficial copied textbook passages.

Proof: docs/product/official-source-ingestion-contract-v1.md

Payment boundary

Fail-closed

Stripe is the source-selected launch rail, but live provider state remains UNKNOWN. Paid checkout stays disabled until provider evidence verifies it.

Proof: docs/product/provider-readiness-truth-board-v1.md

Stop-gate doctrine

Launch safety is a product feature, not a footer claim.

These gates stop work before source safety, payment, database, or privacy risk leaks into the student, teacher, parent, or admin experience.

No custom password system or local login backend.

No answer, explanation, rubric, or answer-key material in pre-commit practice payloads.

No student access to teacher, school-admin, or content-review controls.

No teacher access to another organization or content-approval controls.

No live payment, webhook, refund, price, provider, or environment mutation without owner evidence.

No copied NCERT textbook passages or unofficial textbook redistribution.

Need to report a safe evidence packet?

Use support categories that forbid secrets, copied source text, answer keys, and payment identifiers.

Open support readiness