Security
The technical and operational controls we use to protect student and teacher data and to keep course content inside the protected teaching app.
Security overview
MagiBox is built around a simple promise: courseware should reach learners without leaking, and student and teacher data should stay protected and in-region. This page describes the practices we use to keep both safe. We treat security as ongoing engineering work rather than a one-time checkbox.
Encryption in transit and at rest
- All traffic between clients and MagiBox is encrypted in transit using current TLS.
- Stored data, including course media and account records, is encrypted at rest.
- Encryption keys are managed separately from the data they protect and are rotated under defined procedures.
DRM content protection
Course video is DRM-protected and designed to play only inside the protected MagiBox teaching application. The renderer streams decoded frames to the screen rather than delivering downloadable files, and protected playback is bound to approved devices. This is intended to make casual copying, screen-scraping of source files, and offline redistribution substantially harder.
Device approval and binding
New PC and mobile devices remain pending until an administrator explicitly approves them, while TV activation requires an authorised manager to confirm pairing. Each device is fingerprinted and registered, device limits are enforced, and administrators explicitly disable hardware that is no longer in use. This keeps playback tied to known classrooms and staff machines.
Access control
- Role-based access separates headquarters, campus administrators, teachers, and students.
- Internal access to production systems and customer data is granted on a least-privilege, need-to-know basis.
- Authentication controls include configurable session timeouts and limits on failed log-in attempts.
Monitoring and resilience
We log security-relevant events, monitor for anomalous access and content-protection violations, and maintain encrypted backups with multi-region replication so service can be restored after a disruption. Our aim is rapid detection and recovery, not just prevention.
Breach response
If we become aware of a security incident affecting personal data, we will investigate, contain, and remediate it, and we will notify affected customers and relevant authorities where required by Singapore PDPA, Malaysia PDPA, or the Australian Privacy Act and its notifiable data breach scheme. We will provide the information customers need to meet their own obligations.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please contact us with enough detail to reproduce the issue and allow us reasonable time to investigate and fix it before public disclosure.
Questions?
If anything here is unclear, our team is happy to help. Reach out and we will get back to you.
security@magibox.aiThis page is provided for general information and does not constitute legal advice.