Security and trust
How Allure LMS protects an academy.
What we do, who processes data on our behalf, and what we do not claim. Written from the product and our Privacy Policy, not from a certificate we do not hold.
Practices built into the product.
Separate workspaces
Access controls keep each organization’s workspace separate. Roles are enforced on the server; learners cannot promote themselves.
One family sign-in
Everyone signs in with Allure Account, a single security surface across Allure products.
Encryption in transit
Traffic is encrypted in transit. API keys are scoped, logs are redacted, and important actions leave an audit trail.
Age bands for learners
Every learner has an age band. Under-13s need parental consent evidence in a school-managed workspace; under-18s count only in totals in the Allure Skill Graph.
Privacy requests
People can make privacy requests through a form or by email; organizations can export their data, with 30 days to do so after a workspace closes.
Breach notice
If a breach affects your data, we will tell you and the authorities as the law requires.
Named service providers.
Organizations get 30 days’ notice before we add a subprocessor that handles their workspace data.
The full register, with regions and transfer terms, and our data processing addendum (with Standard Contractual Clauses) are available to organizations at info@allurelms.com.
| Provider | What for |
|---|---|
| Vercel | Hosting, file storage and AI Gateway routing |
| Convex | Database and backend |
| Clerk | Sign-in and user management |
| Stripe | Payments, subscriptions and tax calculation |
| Cloudflare R2 | Course package storage and delivery, through Allure Connect |
| Resend | Email delivery |
| Google (Firebase Cloud Messaging) | Push notifications to mobile apps |
| Sentry | Error tracking, with personal data minimised |
| Anthropic (through Vercel AI Gateway) | AI skill indexing of course activity titles, in Allure Connect |
| Anthropic | Course experience drafting and theme suggestions for course builders |
| OpenAI | Course experience drafting, theme suggestions, image generation and a safety check on uploaded course artwork |
No certificate we do not hold.
- We do not hold SOC 2, ISO 27001 or any other third-party security certification, and no audit is underway.
- The enterprise security overview is a document we write about our own practices. It is not a third-party assessment.
- Our internal trust evidence report is operational evidence only: not legal advice, a certification, or proof of deployment.
Need more for your security review?
Tell us what your review needs and we will send what we have, labelled for what it is.
