Security · 보안
Security notice · 보안 안내
Version 2026-08-12.security-notice-v1. This page describes how COMMIT's security controls work today.
버전 2026-08-12.security-notice-v1. 이 페이지는 COMMIT 보안 통제가 현재 어떻게 작동하는지 설명합니다.
Authority boundaries · 권한 경계
Identity, youth eligibility, entitlement, and optional consent decisions are checked on the server. Client user IDs, plans, policy versions, timestamps, regions, and consent cookies do not grant access.
신원, 연령 자격, 이용 권한 및 선택적 동의는 서버에서 확인합니다. 클라이언트의 사용자 ID, 요금제, 정책 버전, 시각, 지역 및 동의 쿠키는 접근 권한을 부여하지 않습니다.
Sensitive content · 민감 콘텐츠
The v1.3 design requires application-layer encryption and no routine raw provider transcripts. Local unit tests cover the envelope contract, but production database application, key recovery, deletion, dump scans, and provider validation are not complete. Do not treat the current build as independently audited.
v1.3 설계는 애플리케이션 계층 암호화와 일상적인 원본 제공업체 기록 미보관을 요구합니다. 로컬 단위 테스트는 암호화 봉투 계약을 확인하지만, 프로덕션 데이터베이스 적용, 키 복구, 삭제, 덤프 검사 및 제공업체 검증은 완료되지 않았습니다. 현재 빌드를 독립 감사를 받은 것으로 간주하지 마세요.
Logs and optional analytics · 로그 및 선택적 분석
Content or PII-shaped analytics properties are dropped rather than logged. Browser analytics and session replay remain technically disabled. Authenticated server analytics requires an exact current database grant and fails closed on database errors or withdrawal.
콘텐츠 또는 개인정보 형태의 분석 속성은 로그로 남기지 않고 폐기합니다. 브라우저 분석과 세션 재생은 기술적으로 비활성화되어 있습니다. 인증된 서버 분석은 데이터베이스의 정확한 최신 동의가 있어야 하며 데이터베이스 오류 또는 철회 시 차단됩니다.
Reporting · 신고
A verified public security-reporting contact is not yet published. Do not include credentials, student records, essays, or exploit payloads in an unverified channel. This missing path blocks broader release claims.
검증된 공개 보안 신고 연락처는 아직 게시되지 않았습니다. 검증되지 않은 채널에 로그인 정보, 학생 기록, 에세이 또는 공격 페이로드를 보내지 마세요. 이 연락 경로가 없으므로 더 넓은 출시 주장은 차단됩니다.