Security and trust

How Allure LMS protects an academy.

What we do, who processes data on our behalf, and what we do not claim. Written from the product and our Privacy Policy, not from a certificate we do not hold.

What we do

Practices built into the product.

  • Separate workspaces

    Access controls keep each organization’s workspace separate. Roles are enforced on the server; learners cannot promote themselves.

  • One family sign-in

    Everyone signs in with Allure Account, a single security surface across Allure products.

  • Encryption in transit

    Traffic is encrypted in transit. API keys are scoped, logs are redacted, and important actions leave an audit trail.

  • Age bands for learners

    Every learner has an age band. Under-13s need parental consent evidence in a school-managed workspace; under-18s count only in totals in the Allure Skill Graph.

  • Privacy requests

    People can make privacy requests through a form or by email; organizations can export their data, with 30 days to do so after a workspace closes.

  • Breach notice

    If a breach affects your data, we will tell you and the authorities as the law requires.

Who processes data

Named service providers.

Organizations get 30 days’ notice before we add a subprocessor that handles their workspace data.

The full register, with regions and transfer terms, and our data processing addendum (with Standard Contractual Clauses) are available to organizations at info@allurelms.com.

Service providers for Allure LMS, from the Privacy Policy section 7
ProviderWhat for
VercelHosting, file storage and AI Gateway routing
ConvexDatabase and backend
ClerkSign-in and user management
StripePayments, subscriptions and tax calculation
Cloudflare R2Course package storage and delivery, through Allure Connect
ResendEmail delivery
Google (Firebase Cloud Messaging)Push notifications to mobile apps
SentryError tracking, with personal data minimised
Anthropic (through Vercel AI Gateway)AI skill indexing of course activity titles, in Allure Connect
AnthropicCourse experience drafting and theme suggestions for course builders
OpenAICourse experience drafting, theme suggestions, image generation and a safety check on uploaded course artwork
What we do not claim

No certificate we do not hold.

  • We do not hold SOC 2, ISO 27001 or any other third-party security certification, and no audit is underway.
  • The enterprise security overview is a document we write about our own practices. It is not a third-party assessment.
  • Our internal trust evidence report is operational evidence only: not legal advice, a certification, or proof of deployment.
Your next step

Need more for your security review?

Tell us what your review needs and we will send what we have, labelled for what it is.