Trust

Security & privacy

This page is maintained by the FlyHigh team to answer common security and privacy questions about the platform. It describes current practices and enabled controls — it is not an independent certification or audit report.

  • Access and authentication

    Every account signs in with an individual credential. Roles — administrator, instructor, and student — are stored separately from user profiles and are the only source of permission decisions. Role checks are enforced on the server for every request, not in the browser.

  • Row-level data isolation

    Database access is governed by row-level security policies. A learner can read their own enrollment, submissions, and grades; instructors see their courses; administrators see institution-wide reporting. There is no shared credential that bypasses these policies from the application.

  • Platform and hosting

    FlyHigh runs on Lovable Cloud, a managed application and database platform. Traffic is served over HTTPS, and database storage is managed by the platform provider with automated encrypted backups.

  • Student data use

    Student records are used to operate the institution's learning environment and produce reporting for that institution. FlyHigh does not sell student data and does not use it for behavioral advertising. Institutions remain the data owner under their agreement.

  • Retention and deletion

    Course, enrollment, and assessment records are retained for the life of the institution's agreement so transcripts and grade books stay intact. Institutions can export their data at any time and request deletion of records at the end of an agreement, subject to the retention terms in that agreement.

  • Vulnerability reporting

    If you believe you have found a security issue, email security@flyhigh.com with steps to reproduce. We acknowledge reports within two business days. Please do not test against another institution's tenant or access data that is not yours.

Shared responsibility

The platform provides

  • Authentication and session handling
  • Row-level authorization enforcement
  • Encrypted transport and managed backups
  • Audit-friendly role separation

FlyHigh is responsible for

  • Correct permission policies for every record type
  • Server-side validation of all submitted data
  • Publishing accessibility and privacy practices
  • Timely response to reported issues

Your institution is responsible for

  • Provisioning and deprovisioning staff accounts
  • Assigning administrator and instructor roles
  • Reviewing what course content is published
  • Its own records-retention and consent obligations

FERPA-aligned handling

FlyHigh is designed so that an institution can meet its obligations under the Family Educational Rights and Privacy Act: education records are visible only to the student and to institution officials with a legitimate educational interest, access is role-based, and institutions retain export and deletion rights. Specific FERPA contractual terms, including school-official designation, are set out in the institutional agreement rather than on this page.

Questions from your security review team?

We complete security questionnaires and provide accessibility documentation during procurement. Send us the forms your review process requires.