Security
The technical and operational controls we use to protect student and teacher data and to keep course content inside the protected teaching app.
Security overview
MagiBox is built around a simple promise: courseware should reach learners without leaking, and student and teacher data should stay protected and in-region. This page describes the practices we use to keep both safe. We treat security as ongoing engineering work rather than a one-time checkbox.
Encryption in transit and at rest
- All traffic between clients and MagiBox is encrypted in transit using current TLS.
- Stored data, including course media and account records, is encrypted at rest.
- Encryption keys are managed separately from the data they protect and are rotated under defined procedures.
DRM content protection
Course video is DRM-protected and designed to play only inside the protected MagiBox teaching application. The renderer streams decoded frames to the screen rather than delivering downloadable files, and protected playback is bound to approved devices. This is intended to make casual copying, screen-scraping of source files, and offline redistribution substantially harder.
Device approval and binding
Administrators can require device approval so that protected content only plays on hardware the organisation has authorised. Each device is fingerprinted and registered, per-account and per-device limits are enforced, and stale devices can be released automatically after a configurable period. This keeps playback tied to known classrooms and staff machines.
Access control
- Role-based access separates headquarters, campus administrators, teachers, and students.
- Internal access to production systems and customer data is granted on a least-privilege, need-to-know basis.
- Authentication controls include configurable session timeouts and limits on failed log-in attempts.
Monitoring and resilience
We log security-relevant events, monitor for anomalous access and content-protection violations, and maintain encrypted backups with multi-region replication so service can be restored after a disruption. Our aim is rapid detection and recovery, not just prevention.
Breach response
If we become aware of a security incident affecting personal data, we will investigate, contain, and remediate it, and we will notify affected customers and relevant authorities where required by Singapore PDPA, Malaysia PDPA, or the Australian Privacy Act and its notifiable data breach scheme. We will provide the information customers need to meet their own obligations.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please contact us with enough detail to reproduce the issue and allow us reasonable time to investigate and fix it before public disclosure.
Questions about this page?
Reach our data protection team and we will respond within a reasonable period. For data access, correction, or deletion requests, please include the campus or account involved.
[email protected]This page is provided for general information and does not constitute legal advice. It should be reviewed by qualified legal counsel in each operating jurisdiction before go-live.