Trust
What we can claim today.
Dated statuses instead of adjectives. If something is not reviewed, certified or built, this page says so — that is more useful to you than a badge.
Security and compliance posture
Last reviewed 31 July 2026.
A full review of the Rust core, Tauri configuration, dependencies and frontend was carried out in February 2026: 32 findings, of which 21 were fixed as of the March remediation pass.
Not yet commissioned. The credential vault, identity system and integrity layer are the areas we would want reviewed first.
Readiness work in progress. Not certified, and nobody has assessed us against it.
The architecture helps — personal data stays on the learner’s device — but a deployment still needs its own assessment. No DPA is published yet.
No formal WCAG audit has been done. The interface needs design work generally, and this is part of it.
None offered. There is no managed service to attach them to yet.
Where the data is
- Where learner data lives
- On the learner’s device, in an encrypted SQLite database. Not on our servers, because there are no servers holding it.
- What relays see
- Relays help peers find each other. They carry no authority over what passes through them, anyone can run one, and a deployment can use its own.
- What this website collects
- An email address if you join the waiting list or send an enquiry, plus the role and platforms you pick. Analytics are cookieless and carry no personal identifiers.
- Credential verification
- Runs in your browser. A credential you check on this site is never uploaded — there is nowhere for it to go.
The full policy for this website is on the privacy page. The implementation is in the technology page.
Reporting something
Security findings go to admin@ifftu.dev. We would rather hear it from you than read about it later, and we will credit you unless you ask us not to.