Identity and access
Verified authentication protects account functions. Sensitive API operations re-check the user server-side, and administrative routes require an authorised admin identity.
XYSHIMAAI STUDY PLATFORMThis page describes the current security approach and its limits. It is not a claim of SOC 2, ISO 27001 or another independent certification.
Verified authentication protects account functions. Sensitive API operations re-check the user server-side, and administrative routes require an authorised admin identity.
AI and service-role credentials remain server-side. Browser code receives only publishable configuration. Sensitive database tables use row-level security and restricted grants.
Connections use HTTPS/TLS. Infrastructure providers manage encryption at rest and platform-level protections. Account data is separated by user identity and server authorization.
Rate limits, input limits, authentication checks and controlled file types reduce automated abuse and unsafe payloads.
XYSHIMA identifies the specialist providers needed for hosting, authentication, AI and payments and reviews their role in the service.
Suspected incidents are assessed, contained, documented and remediated. Where required, the supervisory authority is notified within 72 hours of awareness and affected people are informed when risk is high.
No online service is perfectly secure. Use a unique password, protect your email account, sign out on shared devices and report unexpected access. Do not upload secrets, unnecessary personal information or special-category data to study materials or tutor conversations.
Send suspected vulnerabilities to support@xyshima.com. Avoid privacy violations, service disruption, social engineering, denial-of-service testing and destructive actions. XYSHIMA does not currently operate a paid bug-bounty programme.