Protecting the beta

Security at ExamGen

ExamGen uses practical safeguards suited to its current teacher-only beta and provides a clear way to report security concerns.

Last updated 17 July 2026

Current safeguards

  • Encrypted HTTPS connections for the ExamGen website and APIs.
  • Individual authentication with email/password and optional Microsoft sign-in.
  • Organisation-separated database access rules so teachers can access only their own workspace data.
  • Separate platform-administrator access with sensitive service credentials kept on the server.
  • Daily backups of the primary Supabase database.
  • Restricted invitation-based onboarding rather than open public registration.

Beta scope and limitations

ExamGen is an early-stage service and does not currently claim its own ISO 27001, SOC 2 or government security certification. It relies on the security controls and contractual arrangements of its infrastructure providers alongside application-level access controls.

The beta is deliberately limited to teacher accounts, question-bank material and saved resource structures. It is not approved for student personal information, results, health or wellbeing information, staff HR records or other sensitive school information.

Report a security concern

If you believe you have found a vulnerability, unauthorised access or a security incident, email mark@examgen.com.au. Include the affected page, what you observed, when it occurred and safe steps for reproducing it. Do not include passwords, setup links or unnecessary personal information.

Responsible reporting

  • Act in good faith and avoid disrupting the service.
  • Do not access, alter, retain or share another user's data.
  • Stop testing and report the issue if you encounter personal or confidential information.
  • Allow reasonable time for investigation before making an issue public.

ExamGen does not currently operate a paid bug-bounty program, but responsible reports are appreciated and will be acknowledged.

Incident handling

Reported concerns will be assessed, contained and investigated as soon as reasonably practical. Where an incident affects a participating organisation or individual, ExamGen will provide appropriate notification consistent with applicable obligations and the available facts.