Security & trust
Built so you can trust it with your idea, your money, and your kids.
Trust isn't a badge — it's an architecture. Here's how the platform is built to keep your data, your spending, and the most vulnerable users safe.
The trust boundary
Exam scoring, XP, certificates, and entitlements are decided server-side. The browser never grades itself, sets a plan, or holds a model key.
Authentication
Sessions use HTTP-only, Secure cookies — no tokens in browser storage. Sensitive actions require step-up re-authentication.
Child safety
Kids accounts require verified parental consent, collect only progress, have no public profile or sharing, and receive no marketing email — enforced server-side.
Agent safety
Do It shows its plan and pauses for confirmation before anything that sends, posts, pays, or deletes. Fetched content is treated as data, never instructions.
Payments
Card data never touches our servers — Stripe Checkout and Portal only. The signed, idempotent webhook is the single source of truth for entitlements.
Your data
Default-deny database rules, App Check on every entry point, encryption at rest, and a clear path to export or delete your data on request.
Found a vulnerability? Email security@neopotters.com — we read every report. Enterprise customers receive a DPA and configurable data retention.