Procta Proof Assets

Short-form trust, security, retention, and reporting assets for procurement, sales decks, and institutional review. Updated May 2026.

Operational Proof

Health Endpoint
/health

Checks API, Supabase, disk, storage write, Redis, worker heartbeat, and email configuration.

Admin Ops
Live

Authenticated operators see queue depth, failed jobs, active sessions, failed submits, release version, and service checks.

Release Gate
Automated

Local and CI gates run tests, dependency audits, dashboard build, Docker config validation, and security scans.

Security Controls Overview

AreaControl
AuthenticationEmail verification, email-based two-factor authentication, suspicious-login alerts, lockout after failed attempts.
Application securityCSRF on JWT-authenticated mutations, per-route rate limits, strict Pydantic validation, CSP headers, dependency audits.
Data protectionTLS in transit, encrypted database/storage at rest, hashed one-time login codes (bcrypt), hashed API keys, least-privilege service keys.
AI governanceAI grades and proctoring flags are recommendations. Teachers review evidence before final decisions.
OperationsSentry integration, structured JSON logs, RQ background workers, health checks, Docker Compose deployment, rollback runbook.

Retention Summary

DataDefault RetentionNotes
Exam screenshots90 daysCleanup job documented in deploy runbook.
Phone camera frames24 hoursEphemeral live-review evidence.
Violation logs and audit trails1 yearUsed for appeals, institutional review, and incident reconstruction.
Exam answers and scoresAccount durationExportable and deletable through privacy workflows.
LTI learner recordsLMS-managedLMS remains the source of truth for learner identity and roster data.

Sample Scorecard

The public sample scorecard shows the evidence format institutions receive: identity summary, score, timeline, detection confidence, human-review notes, and appeal-ready audit language.

Claims Policy

Public sales material should use verifiable operational claims only. Do not use institution-count claims unless the source list and permission status are documented.