StackMentor
How it worksWhy StackMentor?PricingUpcomingFAQ
Back to Front Page

Security

Privacy PolicyTerms of ServiceRefundsSupportSecuritySubprocessorsSchool DPACustom Program PlanStudent Privacy

Last updated: August 2, 2026

StackMentor is designed to protect account, school, course, code, and conversation data. This page describes the controls currently used by the product. It does not claim a security certification or a guarantee that security incidents can never occur.

Current controls

  • Authentication is required for private service actions, and access is checked against school, course, and role membership.
  • Backend authentication and backend-controlled database actions use separate Supabase clients and protected server credentials.
  • Web refresh sessions use an HTTP-only cookie. The extension uses VS Code secret storage for its session.
  • School, teacher, and student capabilities are separated by role. Teachers do not receive individual student conversations.
  • Mentor requests use zero-data-retention provider routing through OpenRouter.
  • Common secret files and paths are skipped by the extension, but users must review editor context before sending it.
  • School invite credentials are kept out of request URLs and stored in the database only as irreversible digests.
  • Security and operational data is limited to what is needed for access control, reliability, abuse prevention, support, and legal operation.

Customer responsibilities

Do not send passwords, private keys, access tokens, certificates, or unnecessary confidential information. Keep your account credentials private, review code context before sending a request, and use your institution's approved process for handling student data.

Custom Program Plans

A custom agreement may include additional security, availability, hosting-region, retention, audit, or incident-response commitments. Such commitments apply only when written in the signed Custom Program Plan Order or its attached security schedule. This public page does not promise a security certification, dedicated infrastructure, a particular hosting region, or 24/7 monitoring.

Incident reporting

Report suspected security or privacy incidents immediately to support@stackmentor.dev. We investigate and document incidents and notify affected institutions or individuals without undue delay when required. A school Data Processing Addendum may include additional notification deadlines.

Vulnerability reports

Please do not publish vulnerability details or customer data in a public issue. Follow the instructions in the repository's SECURITY.md or email support@stackmentor.dev privately.