AboutContact
Koderax LMS Portal

Access control first — certifications when they’re real

Education data deserves careful handling. LMS Portal leads with role-based access and department scoping, and we only publish compliance claims we can stand behind.

Controls

How we protect institutional data today

Practical security controls in the private beta — without overstating formal certifications.

Role-based access control

Four roles — Institution Admin, HOD, Teacher, Student — each with navigation and APIs scoped to what that role can do.

Department-scoped HODs

Department admins only see and change their own faculty. Cross-department visibility is blocked by design.

Secure session login

Email/password authentication with secure session cookies, forced password change on first login, and idle auto-logout.

Least-privilege by default

Teachers stay on assigned classes; students see only their own enrollment, submissions, and published results.

Dedicated institution deploy

Private beta deployments are institution-scoped — not a shared multi-tenant marketplace of unrelated campuses.

Honest about certifications

We do not claim SOC 2, FERPA, GDPR, or WCAG certification until those programs are complete. Ask us what is in place today.

Data practices

You own your institution's data

Clear ownership and scoped access matter more than badge walls — especially in private beta.

  • Your institution owns its data in the deployment database
  • Bulk CSV provisioning for users — controlled by Institution Admin
  • Login session auditing for sign-in and sign-out events
  • Accessibility improvements ongoing — no formal WCAG claim yet
  • Sub-processor list available on request once hosting is finalized
  • Backup strategy included as part of production deployment
Security review

Need a security questionnaire completed?

Our team is happy to walk through your institution's security review as part of an evaluation — with honest answers on what is shipped today.