Skip to content

Trust

Trust and security

A practical overview of how Lectern handles academy, parent, and student data. This page is for vendor review and customer diligence. Signed customer agreements control where they say something different.

Last updated: July 6, 2026

Lectern is early-stage. We are documenting the current operating posture plainly, without claiming certifications we do not have.

Security posture

Lectern is designed around least-privilege access, tenant-aware product boundaries, private uploads, and conservative production operations.

  • Tenant-aware application access patterns, with second-tenant data co-location blocked until tenant-scoped data isolation is complete.
  • Role-based access for academy admins, staff, TAs, students, and portal users.
  • Private storage for sensitive intake and platform uploads.
  • Server-side validation for intake file records and signed upload paths.
  • Cloudflare Turnstile on the public intake abuse surface when configured.
  • Service-role secrets kept server-side and outside browser bundles.
  • Production database migrations are hand-authored and applied deliberately.
  • Build and typecheck gates before shipping application changes.

Student data commitments

  • We do not sell student data.
  • We do not use student data for targeted advertising.
  • Lectern is intended for SAT/ACT/AP prep students who are 13 or older.
  • Customer data is used to provide, secure, support, and improve the service as described in the Privacy Policy and customer agreement.
  • AI-assisted features are used for service delivery, such as test ingestion, answer review, and report workflows.
  • Customer student data is not used by Lectern to train general-purpose AI models.

For more detail, see the Privacy Policy and Terms of Service.

Subprocessors

The services below are the main subprocessors Lectern uses or has wired for service delivery. Actual use can vary by feature, environment, and customer configuration.

ProviderPurposeData involved
Vercel
Application hosting, deployment, edge infrastructure
Application traffic, logs, deployment metadata
Supabase
Database, authentication, private file storage
Account, academy, student, parent, operational, and uploaded file data
Resend
Transactional email
Recipient email addresses and message content
Inngest
Background jobs and workflow orchestration
Job metadata and workflow payloads needed to run platform tasks
Anthropic
AI-assisted document and test processing
Selected uploaded materials, extracted text, images, and review context
OpenAI
AI-assisted review, vision, embeddings, and extraction
Selected uploaded materials, extracted text, images, and review context
Cloudflare Turnstile
Bot and abuse prevention on public intake
Challenge metadata, IP/device signals handled by Cloudflare
Upstash
Rate limiting where enabled
Request keys and rate-limit counters

Retention and deletion

We retain information as long as needed to provide the service, support customers, protect security, satisfy legal obligations, and maintain business records. Customer platform data should be governed by the customer agreement.

On request or termination, Lectern can help export or delete customer data, subject to backups, legal requirements, security logs, and operational constraints.

Vendor review packet

Before onboarding additional academies at scale, these items should be converted from posture into attorney-reviewed, signed documents.

  • Master Services Agreement or platform subscription agreement.
  • Order form covering scope, pricing, implementation, support, renewal, and termination.
  • Data Processing Agreement and student-data addendum.
  • Subprocessor notice and change process.
  • Retention, export, deletion, and incident-notification terms.
  • Customer-specific FERPA, state student-privacy, and procurement language where required.
Need a security review or data-processing packet? Email jake@lectern.systems.