πŸ”’ Security

Security at LessonHQ

Our technical controls, data residency and how to report a vulnerability.

We take the security of teacher and school data seriously. This page summarises our technical controls. Report a vulnerability to [email protected] (see also our security.txt).

In transit & hosting

  • All traffic is served over HTTPS/TLS; HTTP is redirected to HTTPS.
  • HSTS is enabled (2-year max-age, preload) to force secure connections.
  • Hosted on Hetzner cloud servers in the EU (Germany).

Application security

  • Security headers: Content-Security-Policy, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy.
  • Authentication via industry-standard session tokens; hCaptcha protects sign-up/sign-in against bots.
  • Access controls gate every account-scoped resource; the image optimiser is locked to an allow-list of image hosts.
  • Payments are handled entirely by Stripe - we never see or store card numbers.

Data & deletion

  • You can export your content (editable PowerPoint, Word, Google Slides/Docs and PDF) and it is yours to keep.
  • Accounts can be deactivated and personal data erased on request - see our Privacy Policy.
  • Third-party processors are listed on our Subprocessors page.