Security and Privacy Overview

Practical safeguards for accounts, course access, and learning records.

Openbox Learn LLC ("Openbox") uses layered technical and operational practices designed to reduce risk to accounts, learning records, payments, and private course content. No system can promise absolute security, and this page describes practices rather than guarantees.

Last reviewed: July 29, 2026

Accounts and sessions

Openbox uses authenticated sessions, server-side identity checks, and bounded account-recovery flows to protect learner and administrator access.

Authorization and separation

Server-side permission checks, organization context, and database policies are designed to limit each request to the user, role, organization, and record it is allowed to access.

Payment security

Stripe processes checkout and billing. Openbox does not store full card numbers in its application.

Protected course delivery

When configured, videos, private files, and learning packages use signed or time-limited access, bounded requests, and server authorization to reduce unauthorized delivery.

Uploads and record integrity

When secure upload workflows are enabled, private files can be quarantined for malware checks. Completion records and certificates are derived from server-side learning records rather than browser-only values.

Monitoring and recovery

Application logs and health checks help identify failures and support investigation where they are configured. Openbox also maintains recovery procedures for the services it operates.

What account holders can do

  • Use a unique password and protect access to your email and Openbox account.
  • Do not share paid access, session links, signed media links, or organization records.
  • Upload files only through approved workflows and only when you have authority to use them.
  • Report suspected account misuse, exposed data, or another security concern promptly.

Scope of this overview

This page is a high-level description, not a security audit, penetration-test report, compliance certification, service-level commitment, or guarantee. It does not claim SOC 2, ISO, HIPAA, PCI, or other certification. Organization customers may receive separately reviewed security materials during contracting. Any contractual security commitment must appear in a signed customer agreement; that agreement controls if it conflicts with this overview. For data-use and legal terms, review the Privacy Policy and Terms of Use.

Report a security concern