Skip to content

Security & trust

Built so you can trust it with your idea, your money, and your kids.

Trust isn't a badge — it's an architecture. Here's how the platform is built to keep your data, your spending, and the most vulnerable users safe.

The trust boundary

Exam scoring, XP, certificates, and entitlements are decided server-side. The browser never grades itself, sets a plan, or holds a model key.

Authentication

Sessions use HTTP-only, Secure cookies — no tokens in browser storage. Sensitive actions require step-up re-authentication.

Child safety

Kids accounts require verified parental consent, collect only progress, have no public profile or sharing, and receive no marketing email — enforced server-side.

Agent safety

Do It shows its plan and pauses for confirmation before anything that sends, posts, pays, or deletes. Fetched content is treated as data, never instructions.

Payments

Card data never touches our servers — Stripe Checkout and Portal only. The signed, idempotent webhook is the single source of truth for entitlements.

Your data

Default-deny database rules, App Check on every entry point, encryption at rest, and a clear path to export or delete your data on request.

Found a vulnerability? Email security@neopotters.com — we read every report. Enterprise customers receive a DPA and configurable data retention.