Lectur · Legal
Security at Lectur.
What is in place today, what an institution can verify for itself, and how to report a vulnerability to us.
Last updated — August 2026
Measures in place
TLS on all traffic and a private internal network. Encryption at rest of data volumes at the hosting provider, and AES-256-GCM encryption of authentication secrets and certificates. Per-institution isolation applied at the application layer: route registration in the permissions registry and data classification are verified at every build. Role-based access control with a central per-route permissions registry. Immutable audit log of administrative actions. Calls to AI providers go through a single, logged egress point with no bypass path in the code, and raw identifiers are replaced by markers beforehand.
Development and monitoring
Static analysis and dependency analysis on every change and daily; any critical or high vulnerability blocks deployment. An automated weekly internal review covers the application layer, and gaps are recorded and tracked as remediation items. Encrypted backups on 35 rolling days.
Authentication
Per-institution OIDC single sign-on, with Google Workspace or Microsoft Entra. Another OIDC provider can be added by agreement, under the sub-processor notice and objection process. The institution supplies its own identity provider and role mappings. The platform is invitation-only: no open registration is possible, and every account is created by the institution or on its written instruction.
Certifications and verification
Lectur holds no certification of its own to date. What an institution can verify: the infrastructure, meaning hosting, encryption, physical security and backups, is operated by Microsoft Azure, whose SOC 2 and ISO 27001 certifications are audited by third parties; and the application layer is subject to the blocking controls described above. A partner institution may also have the platform audited once per twelve-month period, on notice and at its cost, under confidentiality, and after an incident without regard to that limit. Our agreements require us to carry cyber-risk and professional liability insurance from the moment the platform goes live with students, and to give the institution the attestation.
Incidents and responsible disclosure
We notify the institution's person in charge of the protection of personal information without delay of any real or suspected incident, and of any violation or attempted violation of the confidentiality obligations whether or not it amounts to one, then provide a written notice no later than 72 hours after becoming aware of it. Each entry in the incident register is kept for 5 years, and closing an incident is blocked until notification to the Commission d'accès à l'information is recorded where the serious-injury threshold is met. If you believe you have found a vulnerability, please do not publish it. Write to us with enough detail to reproduce it; we acknowledge within two business days and keep you informed until the fix ships.
Questions
Write to contact@lectur.ca.