Pillars

Security and reliability controls

Tenant isolation

Ready

The runtime separates each institution. Content, attempts, and exports do not move between tenants.

Signed launch and bootstrap

Ready

QFlowLearn signs each launch token and limits its duration. The edge service verifies the bootstrap before it gets the package.

Immutable content versions

Ready

QFlowLearn does not change a published version. A correction creates a new version. Each attempt keeps its version reference.

Attempt event ledger

Ready

QFlowLearn adds each attempt event to a ledger. The events include start, item view, response, navigation, accommodation, and submit.

Operational audit

Ready

The runtime records rescoring, version overlays, and evidence exports.

Recovery plan

Ready

The recovery process uses IndexedDB recovery storage, durable submit records, and attempt reconciliation.

Cloudflare platform services

Ready

Workers, Durable Objects, Queues, R2, and the global edge each have a defined role in launch, delivery, submission, evidence, or export.

Data retention and redaction

Evidence in progress

QFlowLearn documents retention periods and redaction rules for each evidence type.

Hostnames and boundaries

Public hostnames

QFlowLearn separates marketing, authoring, and learner delivery by hostname. Each host has its own authentication, asset, and cross-origin resource sharing (CORS) rules.

qflowlearn.com

This host contains marketing, RFP, and evidence pages. Cloudflare Workers runs the site.

app.qflowlearn.com

This host contains the authoring application. It has host authentication and a specified CORS allowlist.

take.qflowlearn.com

This host contains the learner delivery runtime. It uses launch tokens and does not use marketing cookies.

Request the architecture summary

QFlowLearn will send the architecture summary, runtime contract, retention rules, redaction rules, and launch artifact list for your security review.