Accounts and sessions
Openbox uses authenticated sessions, server-side identity checks, and bounded account-recovery flows to protect learner and administrator access.
Security and Privacy Overview
Openbox Learn LLC ("Openbox") uses layered technical and operational practices designed to reduce risk to accounts, learning records, payments, and private course content. No system can promise absolute security, and this page describes practices rather than guarantees.
Last reviewed: July 29, 2026
Openbox uses authenticated sessions, server-side identity checks, and bounded account-recovery flows to protect learner and administrator access.
Server-side permission checks, organization context, and database policies are designed to limit each request to the user, role, organization, and record it is allowed to access.
Stripe processes checkout and billing. Openbox does not store full card numbers in its application.
When configured, videos, private files, and learning packages use signed or time-limited access, bounded requests, and server authorization to reduce unauthorized delivery.
When secure upload workflows are enabled, private files can be quarantined for malware checks. Completion records and certificates are derived from server-side learning records rather than browser-only values.
Application logs and health checks help identify failures and support investigation where they are configured. Openbox also maintains recovery procedures for the services it operates.
This page is a high-level description, not a security audit, penetration-test report, compliance certification, service-level commitment, or guarantee. It does not claim SOC 2, ISO, HIPAA, PCI, or other certification. Organization customers may receive separately reviewed security materials during contracting. Any contractual security commitment must appear in a signed customer agreement; that agreement controls if it conflicts with this overview. For data-use and legal terms, review the Privacy Policy and Terms of Use.
Report a security concern