Safety Check

Trust and security details

We show clear trust signals, not vague promises. This page shows current safety-check status, what is already being watched, and what still must pass before the public label can move to verified.

Current status: VerifiedLast check: 9/28/2026, 8:56:02 PMOpen attention items: 0Auto-fixes logged: 2
What we tell users publicly
Latest browser safety check ran on 9/28/2026, 8:56:02 PM.
Current browser-visible safety-check probes are clean and the public badge is verified.
Protected tables denied anonymous reads. 1 Project Pals table(s) are public by design.
Browser-visible secrets posture checks are currently clean.
Badge language rule

We do not claim the site is 100% safe or formally certified unless a real external certification exists. Verified will only appear after the checkpoint program clears critical and high-risk findings and the latest browser checkpoint is still fresh.

Current safety-check board
Secrets and key safety
Passed
Browser-visible secrets posture checks are currently clean.
Database protection
Passed
Protected tables denied anonymous reads. 1 Project Pals table(s) are public by design.
Permissions and admin access
Passed
Protected tables denied anonymous reads during the latest safety check.
Storage isolation
Passed
Storage isolation complete. Owner-scoped RLS on all private buckets (plans, uno-attachments, uno_uploads, security-feedback). Email-based admin grants replaced with is_app_admin(). File-size and MIME-type guards enforced on all 7 buckets. All private bucket reads in the app use signed URLs. RLS always-true policies patched on ad_events and dp_image_cues. function_search_path hardened on 28 public functions.
Payment safety controls
Not Started
Payment processor integrity remains a later safety-check track.
Public trust UX
Passed
Trust messaging is now verified because browser-visible probes are clean and fresh.
If you are paying through the site
  • Payment safety controls are part of the checkpoint program and are not treated as optional.
  • Hosted checkout or tokenized payment flows are the preferred direction so raw card data does not live inside the app.
  • Webhook authenticity, replay protection, and paid-status integrity must pass before public verified status is allowed.
Need help or want more detail?

If you have a trust or security question, use the contact path below. We would rather explain the current state clearly than pretend a safety check is farther along than it is.

Before you continue
SchoHome — Terms v1.3 · Privacy v1.2

SchoHome is a software platform, not the actor. We provide tools and connections only.

You are responsible for your decisions, actions, and interactions on this platform. We do not guarantee outcomes, performance, safety, or results.

Every user-created save must be marked Private or Public. Private saves are hidden from other users, but authorized SchoHome administrators may access them to operate, support, secure, or moderate the service.

Always verify information independently and use licensed professionals where required.

By clicking I Agree, you accept our Terms of Service and Privacy Policy.

AI outputs may be inaccurate. Contractor "Verified" status is admin-reviewed, not independently certified. Always verify with licensed professionals.