Scholasticus
OverviewPricingAboutBlog
Sign inCreate an account

Legal

Acceptable Use Policy

What the platform is for, and the conduct expected of everybody using it. It forms part of the Terms of Service, and it applies to every person a workspace admits.

Version
1.0
In effect from
24 August 2026

In short

A summary, not a substitute for the text below.

  • The platform is for running institutional assessment. Use it for that.
  • Tell candidates what is recorded before they sit. Covert monitoring is a breach of this policy.
  • A connection record is a reason to look into something, never a finding of misconduct, and no consequence may be automatic.
  • Security research is welcome — but never against a live exam.

Contents

  1. Who this applies to, and what the platform is for
  2. What must not be done
  3. Sitting an exam
  4. Using the monitoring features
  5. Files you put on the platform
  6. Load, automation and rate limits
  7. Security research and reporting
  8. What we do about a breach, and how to report one

1. Who this applies to, and what the platform is for

This policy applies to everybody who uses the Scholasticus platform: the institution that holds a workspace, every administrator, author, invigilator and grader in it, and every candidate who sits an exam through it. It forms part of the Terms of Service.

If you run a workspace, you are responsible for the conduct of the people you admit to it. Passing this policy on to them is part of that.

The platform exists to run assessment for institutions: to author exams, to publish them to a known group of people, to observe an exam while it is open, to grade what was submitted, and to keep the record afterwards. Use it for that. Anything that is not recognisably that purpose is outside what the platform is offered for, whether or not it is listed below.

2. What must not be done

Do not use the platform, or let anybody use it, to:

  • Break the law, or help somebody else break it.
  • Upload or distribute malware, or anything designed to interfere with a device, a network or the platform.
  • Infringe somebody’s copyright, trade mark, database right or confidence — including by putting third-party material into an exam paper without the right to use it.
  • Harass, threaten, defame or discriminate against a person, in exam content, in feedback, in a message to a candidate, or anywhere else.
  • Collect personal data beyond what running the assessment needs, or collect it for a purpose you have not told the person about.
  • Impersonate another person or misrepresent an institution.
  • Probe, scan or test the security of the platform except as section 7 permits, or attempt to reach a workspace, an account or a record you have not been given access to.
  • Circumvent a plan limit, a rate limit, an authentication step or any other control — including by creating multiple accounts or workspaces to do so.
  • Resell, sublicense or provide the platform to a third party as your own service, or use it to build a competing one.
  • Publish an unpublished exam paper, or extract one in order to distribute it.

3. Sitting an exam

If you sit an exam through the platform, your institution’s own academic rules apply to you and this policy adds to them. While an attempt is open, do not:

  • Sit an exam as somebody else, or let somebody else sit yours.
  • Share your credentials, or use credentials that are not yours.
  • Take assistance the institution has not permitted, from a person or from a tool.
  • Copy, photograph, transcribe or redistribute the paper, unless the institution has said you may.
  • Interfere with the platform’s record of your attempt — the times, the connection events, the answers as submitted.
  • Use another candidate’s device or account, or interfere with their attempt.

What happens if you do is your institution’s decision, taken under its own process. We do not make findings about candidates and we do not impose academic penalties.

4. Using the monitoring features

These are conditions of using the monitoring features, not advice. An institution that uses a connection record as a finding of misconduct is using the platform outside this policy.

While an exam is open the platform records presence, focus, reconnection, timing, the browser and operating system the attempt reported, the network address it came from, and any intervention an administrator made. The Terms of Service list them in full, and the Privacy Policy says how long they are kept.

Tell candidates before they sit. Every person sitting an exam must be told, in advance and in terms they can understand, what is recorded and what it may be used for. Covert monitoring is a breach of this policy, and in most jurisdictions of the law.

Do not treat a signal as a finding. A focus change means the page stopped being in front. A gap means a connection was not held. Neither means a candidate cheated, and neither identifies who was at the keyboard. Use them to decide what to look into, and never as the evidence that closes a case.

Keep a human in every consequence. No academic penalty, no exclusion and no allegation may be generated automatically from these signals. The platform will not do it; you must not build a process that does.

Use them for the exam, and then stop. These records exist to run and to account for one assessment. Do not use them to profile a person, to assess their productivity, to infer anything about their health or circumstances, or for any purpose you did not tell them about.

Let people explain. A candidate who is questioned on the basis of a record must be able to see what the record says and to answer it. A train tunnel and a closed laptop produce different traces, and only the candidate can say which it was.

If you are unsure whether a use is within this policy, ask at [email protected] before you rely on it.

5. Files you put on the platform

Files attached to an exam are stored privately and delivered through a signed URL that identifies one file. That makes them hard to reach by accident and does not make them secret from the people you give the exam to. Two rules follow:

  • Upload only what the assessment needs. A scanned identity document, a medical certificate or a personnel file does not belong in an exam attachment.
  • Upload only what you have the right to distribute, and nothing containing malware.

Plan limits apply to how much may be stored. We may remove a file that breaches this policy or the law, and will tell the workspace when we do.

6. Load, automation and rate limits

The platform is sized for real exams: hundreds of candidates holding a live connection at once is ordinary use and is what the capacity is planned around. What is not ordinary use is load that has nothing to do with an assessment.

  • Do not send automated traffic — load generators, scrapers, crawlers of the exam interfaces — outside a test we have agreed with you.
  • Do not open or submit attempts programmatically. An attempt is a person sitting an exam.
  • Do not hold connections open, or reconnect in a loop, in order to occupy capacity.
  • Do not work around a rate limit. It is there because something on the other side of it is shared.

If you are planning an unusually large sitting, or a load test before one, tell us first at [email protected]. We would rather help you plan it than discover it.

7. Security research and reporting

We welcome security research and would rather hear about a problem than read about it. Report what you find to [email protected] with enough detail to reproduce it. We will acknowledge it, tell you what we find, and credit you if you would like us to.

While you are looking:

  • Never test against a live exam. The cost of a broken attempt falls on a candidate who had no part in your research. Use a workspace of your own, with no real exam open in it.
  • Do not access, modify or exfiltrate anybody else’s data. If a proof of concept requires it, stop and describe it instead.
  • Do not run denial-of-service tests, and do not use automated scanners against the production platform.
  • Do not use social engineering against us, our members or our providers.
  • Give us a reasonable period to fix what you found before you publish it.

Research carried out within those limits is not a breach of this policy, and we will not treat it as one.

8. What we do about a breach, and how to report one

Where we believe this policy has been breached we act proportionately, and in this order where the circumstances allow it:

  1. We tell the workspace what we have seen and ask about it.
  2. We restrict the feature involved, or remove the content involved.
  3. We suspend the workspace or the account.
  4. We end access under the Terms of Service.

Where an exam is open, we will not interrupt it unless leaving it running is the greater harm — a live exam is the thing we protect first, including from our own enforcement.

Where the law requires it, or where somebody is in danger, we may report a matter to the authorities. Where we are permitted to tell you that we have, we will.

To report abuse of the platform, or a use of it that worries you, write to [email protected]. Say what you saw and where; if it concerns an exam, tell us the workspace and whether the exam is still open, because that changes what we can do about it and how quickly.

Scholasticus

Exam software for institutions. One workspace per institution, a sign-in directory of its own, and a record of every attempt that survives the exam ending.

Platform

OverviewPricingAbout

Resources

BlogDocumentationSupport

Get started

Create an accountSign inOpen dashboard

© 2026 Alireza Hajebrahimi, trading as Scholasticus

TermsAcceptable usePrivacy

Built with <3 in Copenhagen.