Account protection
Passwords are handled in protected form rather than stored as readable text. Sign-in sessions use secure browser protections, and users can enable time-based two-step verification with recovery codes. Administrators can deactivate accounts and reset MFA when appropriate. Users should choose a unique password, enable MFA, safeguard recovery codes, and sign out of shared devices.
Access controls
MyClassroom Planner uses roles to control administrative functions. Information marked private is intended for the individual user; shared information is available to the authorized team according to the feature’s visibility setting. Administrators are responsible for assigning appropriate roles, reviewing active accounts, and promptly removing access when a staff member leaves or changes responsibilities.
Encryption and Site Vault
Connections to the production Services are protected with HTTPS. Site Vault uses a separate password to encrypt vault content on the user’s device before it is stored. That vault password is not transmitted to or retained by Project Bright Cornerstone. This design improves privacy but means forgotten vault passwords cannot be recovered; a reset permanently deletes the affected encrypted entries.
Infrastructure and backups
Production services use restricted server access, managed service processes, encrypted web connections, database backups, and operational checks appropriate to the deployment. Backups support recovery from operational failures, but they are not a substitute for school-required exports or official record systems. Backup schedules and retention may differ by service plan or written school agreement.
AI privacy controls
The AI Lesson Helper is optional and only sends information when a user requests a draft. Selected workflows are designed to remove certain obvious identifiers before transmission. Users remain responsible for excluding unnecessary personal information, medical details, parent contact information, credentials, photographs, and other sensitive records. AI output is never automatically added to a student record or lesson plan.
Logging and monitoring
We may record authentication events, authorization failures, service errors, security events, and limited technical details needed to investigate problems and protect the Services. We design logs to avoid passwords, API keys, vault contents, session secrets, and unnecessary student information. Access to operational logs is restricted.
Data minimization and retention
Users should enter only information needed for legitimate educational or organizational purposes. We retain data for the period needed to operate the Services, meet contractual and legal duties, maintain security records, and complete backup cycles. Schools may request information about exports, deletion, or service-specific retention.
Incident response
We investigate credible reports of unauthorized access, service compromise, or loss of protected information. If an incident requires notification, we will work to provide notice to affected organizations or individuals as required by applicable law and contractual commitments.
Shared responsibility
Security depends on both the platform and its users. Schools should approve the information entered, maintain accurate staff access, train users, secure their devices, and identify which systems are appropriate for official or highly sensitive records. Users should report suspicious activity promptly and never share account passwords, MFA recovery codes, API keys, or vault passwords.
Report a security concern
If you believe an account or the Services may be at risk, contact hello@projectbrightcornerstone.com. Include a description and safe contact information, but do not email passwords, API keys, student records, or exploit code containing personal information.
Back to home