Security.

In force from 29 September 2026

The short version

Every connection is HTTPS, passwords are hashed and cannot be read, and a course made from your adverts is served to nobody but you.

Every query is scoped to one account. Vulnerabilities go to hello@tutorbadger.com.

This summary is here to be read. The clauses below are what actually binds.

In transit

Every connection is HTTPS, enforced with HSTS.

Passwords

Hashed with PBKDF2 SHA 256, 100,000 rounds and a unique salt. They cannot be read, only reset. Resetting a password signs out every other device.

Isolation

Every course, lesson, lesson recording and progress record belongs to one account, and every query filters by it, in the query itself. Anyone else asking for one, signed in or not, is told it does not exist.

Signing in

Repeated sign in, sign up and reset attempts from one address are slowed down. The cookie is HttpOnly, Secure and signed.

Infrastructure

Tutor Badger runs on Cloudflare: Workers, D1, KV and R2. Every page carries a strict Content Security Policy. A lesson runs the one script it needs, and no other page runs any.

Reporting a vulnerability

Email hello@tutorbadger.com, also published in security.txt. Reports are read by a person and answered.

Something here unclear?

Ask, and the wording gets fixed rather than explained.

Email about this