Trust & safety
Security
Last updated: 12 August 2026
Exams ITforAll uses layered controls intended to reduce account, application and data risks while keeping the platform practical for teachers.
Password protectionPasswords are stored as one-way password hashes rather than readable passwords.
Secure sessionsSession cookies use HTTPS, HttpOnly and SameSite protections, with idle-session limits.
Request protectionState-changing forms use CSRF tokens and database access uses prepared statements.
Rate limitingRepeated login and password-reset attempts are limited to reduce automated abuse.
Password recoveryReset links use random one-time tokens stored only as hashes and expire after 30 minutes.
AI credentialsConfigured Gemini API keys are encrypted before storage and are not shown to teacher accounts.
Responsible use
Do not share account credentials. If you believe an account or generated paper has been compromised, change the password and contact platform support.
Security reports
If you discover a security weakness, please report it privately through the support contact published by the service. Do not publicly disclose exploit details or access data that does not belong to you.
No absolute guarantee
Security controls reduce risk but cannot eliminate every possibility of compromise, hosting failure or third-party service incident.