XYSHIMA owl logoXYSHIMAAI STUDY PLATFORM
SECURITY OVERVIEW

Layered safeguards for account and learning data.

This page describes the current security approach and its limits. It is not a claim of SOC 2, ISO 27001 or another independent certification.

Current controls

Identity and access

Verified authentication protects account functions. Sensitive API operations re-check the user server-side, and administrative routes require an authorised admin identity.

Secrets and permissions

AI and service-role credentials remain server-side. Browser code receives only publishable configuration. Sensitive database tables use row-level security and restricted grants.

Data protection

Connections use HTTPS/TLS. Infrastructure providers manage encryption at rest and platform-level protections. Account data is separated by user identity and server authorization.

Abuse resistance

Rate limits, input limits, authentication checks and controlled file types reduce automated abuse and unsafe payloads.

Vendors

XYSHIMA identifies the specialist providers needed for hosting, authentication, AI and payments and reviews their role in the service.

Incident response

Suspected incidents are assessed, contained, documented and remediated. Where required, the supervisory authority is notified within 72 hours of awareness and affected people are informed when risk is high.

Limits and user responsibilities

No online service is perfectly secure. Use a unique password, protect your email account, sign out on shared devices and report unexpected access. Do not upload secrets, unnecessary personal information or special-category data to study materials or tutor conversations.

Responsible disclosure

Send suspected vulnerabilities to support@xyshima.com. Avoid privacy violations, service disruption, social engineering, denial-of-service testing and destructive actions. XYSHIMA does not currently operate a paid bug-bounty programme.