Security overview
For school IT teams, administrators and parents who want the details. ClassGuard is built by Kryft; security contact [email protected]. Version 2026-10.
Architecture in one paragraph
ClassGuard runs entirely on Cloudflare: an API on Cloudflare Workers (api.classguard.dev), a SQL database (D1), private file storage (R2), small stateful services for each student phone, live class and user (Durable Objects), background queues, and the Cloudflare Realtime video relay. The apps are a Flutter app for Android and the web (app.classguard.dev). There are no servers of our own to patch, and no third-party analytics or advertising code.
Protecting data
- Encryption in transit: every connection uses HTTPS/TLS, including live video (WebRTC with DTLS-SRTP) and real-time connections (secure WebSockets).
- Encryption at rest: Cloudflare encrypts the database and file storage at rest. Printed student login sheets are additionally encrypted with our own AES-GCM key and deleted when they expire.
- Passwords are stored only as salted one-way hashes (Better Auth's scrypt). Exit PINs and teacher PINs are stored as salted PBKDF2-SHA-256 hashes (100,000 rounds).
- Files are private. Homework, materials, reports and profile pictures are never public. They are handed out through links that expire after 10 to 15 minutes, issued only after checking the person may see that file.
- No images, video or audio of children are stored. Focus tracking runs on the phone (Google ML Kit) and sends numbers only. Live class media is relayed and never recorded.
Who can access what
- Every request is checked for the user's role and school. A teacher sees only the classes they teach; a parent only their own children; a school admin only their own school. Our automated isolation test signs in as users of two different schools and confirms neither can read the other's data; it must pass before every release.
- Student routes also require an approved phone: a new phone must be approved by a parent or the school before it can be used.
- Sign-ins: sessions last 24 hours. Optional fingerprint sign-in uses a key kept in the phone's secure hardware; the server checks the key's Android attestation where available.
- Kryft staff have no routine access to school data. Platform administration is limited to approving schools, billing and support, and every administrative action is logged.
Stopping misuse
- Rate limits on sign-in, sign-up, password reset, PIN checks, device pairing, file transfers, messages and other sensitive actions.
- Exit PINs lock after 5 wrong attempts. Password-reset codes expire after 10 minutes and die after 5 wrong guesses.
- Strict web security headers (Content Security Policy, HSTS, no framing) and a limited list of websites allowed to call the API.
- Every input is checked against a strict schema before the server uses it.
- The student phone reports tampering (lock switched off, permissions removed, accessibility disabled, signs of a rooted or modified phone) to parents and teachers.
Monitoring
- Structured server logs with personal details removed.
- Server errors and app crash reports are counted; alerts are emailed to Kryft when errors spike, a scheduled job stops, or the health check fails (checked from outside every 15 minutes).
Change management
- All code is reviewed and tested before release: type checks, linting, more than a thousand automated server and app tests, and the cross-school isolation test.
- Database changes are applied forward-only, by a reviewed one-click step before the code that needs them goes live.
- Secrets are stored only in Cloudflare's encrypted secret store and GitHub's encrypted secrets, never in the code.
Incidents
If a security incident affects personal data, Kryft follows its breach response plan: contain it, assess the risk, tell affected schools within 48 hours and families without undue delay, and notify authorities where the law requires (within 72 hours in the EU/UK).
Focus-tracking assessment
Because focus tracking uses a child's camera, Kryft has carried out a data protection impact assessment. Its conclusions: processing stays on the phone, only numbers are sent, it is off until a parent consents, it runs only during scheduled classes, its detail is deleted after 90 days, and it is never used for automated decisions about a child. Schools can request the full assessment from [email protected].
Reporting a vulnerability
Please email [email protected] with details. We will acknowledge within 3 working days and will not take action against good-faith research that avoids harming users or their data.