Public-site security

Security, privacy, and responsible access matter

Student literacy data deserves careful handling. The static site is deployed with a private S3 origin behind CloudFront, HTTPS-only access, managed security headers, and DNS records controlled in Route 53. Application features such as reporting and video sessions should remain behind authenticated services, not on the public site.

Private content origin

The website bucket is not publicly readable. CloudFront accesses it through Origin Access Control.

HTTPS and browser protections

Traffic is redirected to HTTPS and the distribution applies AWS managed security headers.

Controlled DNS

Custom domain aliases are managed in Route 53 once the domain is delegated to the hosted zone.

Scope boundary

The static site does not expose student records, direct video access, or private admin tools.