Product
Resources
Security
The same boring engineering that protects banks protects your courses. Encryption everywhere, role-based access, regional data residency, and a phone number that picks up when something is wrong.
Least privilege
No engineer, contractor, or AI assistant gets access to learner data without an audited business reason. The default is "no."
Boring by design
We use the same encryption, key management, and infrastructure primitives a Nigerian bank does. New is not better: proven is better.
Plain communication
When something goes wrong, you hear it from us first, in language a human can read. No press-release prose.
The short version is below. We can hand a longer technical brief to anyone evaluating Learnkasts for a school or an organisation: just ask sales.
01 · Encryption
Every request between you, our servers, and our database runs over TLS 1.2+. Files at rest: videos, attachments, certificates, payment metadata: are encrypted with AES-256. Encryption keys rotate on a schedule and live in a dedicated key management service, separate from the application that uses them.
02 · Compliance
We treat the Nigerian Data Protection Regulation as the floor, not a stretch goal. We are GDPR-aligned for European learners and provide data export, deletion, and rectification on request. Every privileged action: login, role change, content publish, payout: is logged with the actor, target, and a timestamp.
03 · Access control
Owner, admin, instructor, finance, support: every member of your organisation gets exactly the permissions they need and nothing more. Two-factor authentication is one click. Single sign-on through Google Workspace, Microsoft Entra, or any SAML 2.0 provider is included on Pro and Enterprise.
04 · Infrastructure
Our primary database and storage live in Lagos. Disaster-recovery replicas sit in two other African regions. We do not move learner data outside Africa unless you explicitly opt in: your school keeps data sovereignty by default.
05 · Incident response
If something breaks, you hear it from us within the hour: not from Twitter. Enterprise customers get a named incident commander and a published post-mortem within five business days of resolution. Smaller plans get the same response time, summarised in the changelog.
Responsible disclosure
If you find a vulnerability in Learnkasts, please email security@learnkasts.com. We acknowledge every report within 24 hours, work in private until a fix ships, and credit researchers who would like the credit.
We do not run a paid bounty programme yet, but we send a thank-you and your name on this page if you want it.
Email security@learnkasts.comWe can hand you a full security brief, our DPA, and a half-hour technical walkthrough with the team that built this. No spin, no slides.