Security
Last updated September 14, 2026
CramLoop is built to limit unnecessary access to teacher, student, assessment, and account information while supporting normal school and home use.
Encryption and transport
CramLoop is served over HTTPS. Data sent between a user’s browser and CramLoop is encrypted in transit using modern TLS provided through our hosting infrastructure.
Authentication and access control
Accounts are authenticated through Supabase. CramLoop uses application roles and database access controls to separate teacher, student, and administrative workflows. Teacher-only information, including protected answer-key and reporting data, is not intended to be exposed through normal student workflows.
Hosting and infrastructure
The application is hosted and delivered through Vercel. Authentication and database services are provided through Supabase. CramLoop does not require schools to install browser extensions, executables, or device-management software for normal web access.
Browser and network requirements
CramLoop requires outbound HTTPS access on TCP port 443 to cramloop.app, www.cramloop.app, and the CramLoop Supabase service domain kbouetjaefilebcyotbw.supabase.co. Schools using web filters, proxies, SSL inspection, or category-based blocking may need to allow these domains.
Security headers
CramLoop uses browser security headers intended to reduce framing, MIME-type confusion, unnecessary browser permissions, and other common web risks.
Data minimization
CramLoop is designed to collect information needed for accounts, assessment delivery, reporting, study activity, support, and security. It is not designed to collect precise location, biometric identifiers, contact lists, or student advertising identifiers.
Vulnerability and incident handling
Security issues are reviewed and remediated as they are identified. If CramLoop determines that a security incident materially affects school or user information, we will work to provide appropriate notice and remediation consistent with applicable obligations.
School review
School or district technology teams may review the Privacy Policy, School & Student Privacy, Terms of Use, and Acceptable Use Policy. Additional reasonable technical or privacy questions can be addressed as part of a district review.