TrustPublic
Security and privacy
The launch boundary minimizes retained data and keeps signing material and LMS messages out of public surfaces.
Secure launch boundary
A learner does not reach the player merely because an LMS sends a request. RFM validates the platform and launch contract before resolving learning access.
- Registrations and deployments are scoped to one institution.
- Each resource link maps to an explicit published course version.
- Replay and unsupported-role checks occur before player access.
- The player receives an RFM-issued handoff rather than a raw LMS token.
Data boundary
Public documentation contains no private keys, signer references, provider secrets, raw JWTs, raw claims, learner identity, private course artifacts, or complete provider errors.
- Tool signing keys remain in the backend-managed signer boundary.
- LMS subjects are scoped to their registration and are not merged by email.
- Operational evidence uses bounded outcomes and correlation references.
- Support should never ask a school to email a token or full launch payload.
Security review boundary
Hosting, recovery, retention, and institution-specific operational evidence are published or shared only after their owners approve the current evidence. This page does not turn a hosting-provider claim into an RFM certification claim.
