Security & data

Understand the data flow.

Vecole is educator authoring software. Student records are not needed to generate assessments. This overview describes implemented controls; it is not an independent audit, security certification, or guarantee that incidents cannot occur.

Accounts and authorization

Studio uses authenticated sessions and ownership checks for educator content. Access is arranged through our team. Google connection is an optional authorization flow tied to the signed-in Vecole account; it does not automatically merge accounts based on email.

Google tokens

Google refresh tokens are encrypted server-side with AES-256-GCM and account-bound authenticated data. OAuth state is one-use and expires; PKCE protects the authorization exchange. Tokens are not placed in quiz images or student links. Disconnect removes the local connection and attempts Google revocation.

Published and exported content

Teacher review precedes publication and explicit sharing. PDF answer keys and QTI packages contain scoring information and must be handled as teacher material. Forms answer keys are sent to Google as quiz grading configuration. Teachers must check when Google releases scores and correct answers.

Legacy student worksheet links and temporary image URLs are bearer links: possession permits access while the link is valid. They are not proof of class membership. Google Forms responder permissions are controlled in Google, not by a Vecole roster check.

Providers and institutional review

Read Privacy for the service providers and processing purposes. Ask us for deployment-specific details on hosting, retention, backup handling, access controls, and contracts before a district rollout. We do not claim SOC 2 certification, guaranteed data residency, or FERPA/COPPA certification on this page.

Report a concern

Email contact@vecole.com. Use synthetic examples and do not include secret credentials or student data in the report.