Security
Last updated: 6 October 2026 · Version 2026-10-06
Bema holds things students would not want read by anyone else — draft essays, family finances, immigration status, disciplinary history. This page says how we protect them and how to tell us when we have not.
How your account is protected
- Passwords are hashed with bcrypt. We never store or transmit your actual password, and we cannot see it. If you ask us what your password is, we cannot tell you — we can only send you a reset link.
- Passwords cannot be one of the common ones. "password123" and its relatives are refused at signup, and so is your own name or email address.
- Sessions use signed tokens that carry only your user id, email and role, and every token is invalidated the moment you change or reset your password.
- Password resets expire in 30 minutes and can be used once. Email confirmation links expire in 3 days.
- Sign-in is rate-limited, and after three wrong passwords on one address the human check is required before the password is even compared. Signup and email requests have their own, tighter limits.
- Signup has a human check. hCaptcha checks that a person is there, with our own picture or written check as the fallback and a hidden trap field for bots. hCaptcha sees device and interaction signals from the check, never your name, email or work (see the Privacy Policy).
- AI features have per-account allowances and an app-wide daily ceiling, so a stolen token or a scripted account cannot run up an unbounded bill or starve everyone else.
- Links are sanitised. Anything a person or the AI supplies as a link is kept only if it is a normal http(s) address, on the way in and again when displayed, so a link can never carry a script to another family member.
- The app ships with a Content Security Policy that stops the browser running any script that was not part of the build.
- Identity numbers are refused. SSNs, FSA IDs, ITINs, A-Numbers and license numbers are rejected by the server by name and by shape.
- Secrets live only in the server's environment. The AI provider key, the token-signing secret and the mail credentials are never in the app, never in the code, and never in the repository — the build is checked for them.
- Dependencies are audited against known vulnerabilities on every push.
- Every request for a student's data is authorised individually. The server checks whether the requester is that student or a parent that student has connected with, on every route, before it reads a row. There is no path through the API that returns one family's data to another.
- Parent accounts are read-only by default. The list of things a parent may write is deliberately short — a task, a comment, a suggested edit — and everything else is refused by the server rather than merely hidden in the interface.
- The AI cannot delete on its own. When you ask Bema to remove something, it asks you to confirm first, and what it removed can be put back from Settings for 30 days. Text the AI reads, like an essay or a pasted email, can never trigger a removal by itself.
- You can see who signed in. Settings shows your recent sign-ins, wrong password attempts, password changes and data downloads, and a "Sign out everywhere" button.
- We keep a security log of sign-ins, exports, deletions and team access, without content or email addresses, and are alerted to bursts of failed sign-ins or repeated downloads from one account.
- Demo accounts cannot send email or invitations to anyone.
- Database queries use prepared statements, so data can never be interpreted as a command.
- Traffic is encrypted in transit with TLS, and the database is encrypted at rest.
What you can do
- Use a password you do not use anywhere else. Length beats punctuation.
- Sign out on a shared or school computer.
- Use an email address you will still control after you graduate — a school address that gets switched off can lock you out of your own account.
- Nobody at Bema will ever ask for your password, or for your Common App,
College Board or StudentAid.gov login. If something claiming to be us does, it
is not us. Forward it to
getbemaai@gmail.com.
Reporting a vulnerability
If you have found a security problem, please tell us. We would much rather hear it from you.
Email getbemaai@gmail.com with enough detail to reproduce it. If you can,
include the URL or endpoint, the steps, and what you were able to access that you
should not have been.
What we will do: acknowledge within 2 business days, tell you our assessment within 7 days, keep you updated while we fix it, and credit you publicly if you would like.
What we ask: give us a reasonable window before disclosing publicly. Do not access, modify or delete data belonging to anyone but yourself — if you can reach another account, stop at the point that proves it and tell us. Do not run denial-of-service tests, spam, social engineering, or anything physical.
Our commitment in return: if you follow the above in good faith, we will not pursue legal action against you, and we will say so to anyone who asks.
We do not run a paid bug bounty yet. We will say so honestly rather than imply one exists.
If something goes wrong
If a breach affects your personal information, we will tell you. Not a vague notice weeks later — what happened, what data was involved, when, what we have done about it, and what you should do. We will notify affected users within 72 hours of confirming a breach, and regulators where the law requires it.
What we are still working on
Being straight about the gaps is part of being trustworthy:
- Two-factor authentication is not yet available for user accounts. It is planned. The team's own accounts on our hosting, code and email providers require it.
- No independent penetration test has been carried out. One is planned before general availability; the code has had internal security reviews, most recently on 16 September 2026.
- Session tokens are stored in browser local storage, which is standard for applications of this kind but is more exposed to a cross-site scripting flaw than an HTTP-only cookie would be. The Content Security Policy and link sanitising above are the mitigation; moving to HTTP-only cookies is on the list.
- Email confirmation is optional for day-to-day use. It gates only the team's internal views, so a confusing link never locks a student out of their own essay.
Contact: getbemaai@gmail.com