Security & privacy

Safe for students. Straightforward for IT.

An overview of how CyberLab is designed to protect schools. Detailed documentation is available on request.

Activities must only be performed within authorized CyberLab environments.

Student data

Each school is provisioned as its own organization. Every record — users, classes, attempts and responses — carries an organization identifier, and pages only show records from the signed-in user’s organization.

We collect the minimum information needed for learning: name, school email, class membership and lab activity. See the privacy notice for details and how to request export or deletion.

Access control

Four roles — Platform Admin, School Admin, Teacher and Student — determine what each user can see and do. Role checks run on the server for every restricted page, and teachers can only open classes they teach.

CyberLab is currently a prototype. Production authentication, database-level row security, multi-factor authentication and audit logging are planned but not yet in place. We do not hold any third-party security or privacy certifications.

Authorized use policy

CyberLab teaches defensive cybersecurity. Every lab uses simulated evidence and reserved documentation IP addresses, and no activity ever interacts with real systems.

Students agree to use techniques learned only within authorized CyberLab environments. Attempting to apply them against real systems without permission may be illegal.

School security & privacy

Built to pass your IT and safeguarding review

Security education should model security practice. CyberLab is designed with the controls schools expect.

Tenant isolation
Each school is a separate organization, and pages are scoped to the signed-in user’s school.
Role-based access
Platform admins, school admins, teachers and students are each limited to pages their role allows, checked on the server.
Safe simulations
Every lab runs against simulated evidence. Lab tools never make network requests or run commands.
Minimal student data
We collect only what learning requires, and users can request export or deletion.