todo.academy Try a free chapter

Security and data

Know which safeguards exist and which boundaries still matter.

This public summary describes the current product controls in plain language. It is not an audit certificate, penetration-test report, data-processing agreement, or promise about controls that have not been verified.

Payments

Payment details stay with the payment processor.

Checkout is handled by Lemon Squeezy for Phoenix Soft Inc. The public website bundle does not store payment-card details.

Paid access

A typed email is not enough to unlock a purchase.

Passwordless sign-in verifies the learner session before server-side entitlement records are returned. Refunded or reversed orders can remove access.

Course content

Public pages exclude protected paid lesson content.

Public marketing data contains course facts, counts, and chapter summaries. Protected lesson files, proof rules, commands, and solutions are not published in that marketing model.

Product analytics

The event contract excludes high-risk learning content.

The analytics adapter is designed to exclude names, email addresses, checkout tokens, restore tokens, terminal history, commands, and user-entered lab content. Collection remains disabled until governance and consent are approved.

Support and administration

Private records use authenticated routes.

Paid support records and administrative tools are not exposed as public database reads. Authorization is checked before private records are returned.

Learner responsibility

Do not paste production secrets into a training workspace.

Use course-provided values and synthetic practice data. Keep passwords, API keys, customer data, private keys, and production configuration out of learning exercises.

Current boundary

Institutional security documents are not yet a public product.

A paid pilot still needs an explicit review of subprocessors, retention, support access, data location, incident handling, and procurement requirements.

Review team pilot readiness