Tenant isolation
ReadyThe runtime separates each institution. Content, attempts, and exports do not move between tenants.
QFlowLearn separates tenant data, signs launches, preserves published versions, and records attempt events so institutions can verify delivery and investigate results.
The runtime separates each institution. Content, attempts, and exports do not move between tenants.
QFlowLearn signs each launch token and limits its duration. The edge service verifies the bootstrap before it gets the package.
QFlowLearn does not change a published version. A correction creates a new version. Each attempt keeps its version reference.
QFlowLearn adds each attempt event to a ledger. The events include start, item view, response, navigation, accommodation, and submit.
The runtime records rescoring, version overlays, and evidence exports.
The recovery process uses IndexedDB recovery storage, durable submit records, and attempt reconciliation.
Workers, Durable Objects, Queues, R2, and the global edge each have a defined role in launch, delivery, submission, evidence, or export.
QFlowLearn documents retention periods and redaction rules for each evidence type.
QFlowLearn separates marketing, authoring, and learner delivery by hostname. Each host has its own authentication, asset, and cross-origin resource sharing (CORS) rules.
This host contains marketing, RFP, and evidence pages. Cloudflare Workers runs the site.
This host contains the authoring application. It has host authentication and a specified CORS allowlist.
This host contains the learner delivery runtime. It uses launch tokens and does not use marketing cookies.
QFlowLearn will send the architecture summary, runtime contract, retention rules, redaction rules, and launch artifact list for your security review.