Security at Infinilearn

Student data is not loot.

Infinilearn is played by thousands of kids, so the bar is simple: guard every player like they were ours. Here is how we do it, in plain English.

No ads. No selling data. No open chat. No student emails.

The short version · The rest of this page is the proof

The oath

Four things that will never change.

No ads, ever.

The game shows no ads and runs no ad tracking. Nothing a student touches carries a marketing pixel, and there is no targeted advertising anywhere.

We never sell student data.

Not to brokers, not to partners, not anonymized, not ever. Our revenue is memberships, so families are the customer, never the product.

Students never give us an email.

Kids sign in with a username and a six-digit PIN. Even our Google sign-in option only proves identity; the email behind it is never stored.

No open chat.

Players talk through preset phrases and emotes only. Parents and teachers can switch multiplayer off entirely, and it applies within a minute.

Defense in depth

Locked down by default.

  • Student data is encrypted in transit and at rest
  • Deny-by-default access rules: nothing is readable unless a rule explicitly allows it
  • Automated tests prove the denies as well as the allows before any rules change ships
  • Sensitive changes like roles and subscriptions happen only on our servers, never from a browser
  • Continuous backups with point-in-time recovery, and we have run real restores
  • Built on Google Cloud and Vercel, infrastructure holding SOC 2 and ISO 27001 certifications
  • Enforced email authentication: SPF, DKIM, and DMARC set to reject

For school IT teams

Aligned with NIST CSF 2.0.

The NIST Cybersecurity Framework is what we name on district data sharing agreements. Here is what each function looks like in practice, and we are happy to walk your team through the full mapping.

Govern

Security has one accountable owner, written policies, and a signed data sharing agreement with every school that asks for one.

Identify

We keep a full inventory of what student data exists, where it lives, and who can reach it. Our DSA data schedules are filled out from that inventory, not from memory.

Protect

Encryption everywhere, deny-by-default access rules, least privilege, and server-only writes for anything sensitive.

Detect

Production errors and anomalies are exported and reviewed every day, not once a quarter.

Respond

Reported issues get triaged, fixed, and written up with a root cause. Every security finding ever reported to us has been resolved.

Recover

Continuous backups, point-in-time restore, and Git-driven deploys that can roll back in minutes.

Proof, not promises

We invite people to try to break in.

Independent security researchers have tested Infinilearn from the outside, and we run recurring audits of our own code from the inside. Every real finding, from either direction, has been fixed. Not filed in a backlog. Fixed.

Our access rules ship with automated test suites that run against a real database emulator: over a hundred cases proving that the right people get in and, just as deliberately, that everyone else stays out.

Classrooms are why we exist, so the legal side is built in, not bolted on. Students can play without ever providing contact information, which is how we approach COPPA. When schools use Infinilearn, they own their students' records and we act as a school official under FERPA, bound by the data sharing agreements we sign. When a school or parent asks us to delete data, we delete it and confirm in writing.

Found a vulnerability? Email adrian@infinilearn.com. Reports go straight to the person who can fix them, usually the same day.

Questions about security?

Ask the person who wrote the code.

Email Adrian