LMS White

Blog · Licence guides

Security model: no absolute security warranty

Updated 5 September 2026 · Based on our Software Licence & Services model

Why no LMS can honestly promise “100% secure” or “unhackable” — and how shared responsibility works after handover.

What this means for you

LMS White uses security-focused architecture and reasonable safeguards. Still, no software, cloud platform, OS or mobile app can be guaranteed completely error-free, vulnerability-free or immune from attack.

We do not advertise the Platform as “100% secure”, “unhackable” or “hacker-proof”. Later discovery of a vulnerability does not, by itself, prove negligence. Client-caused events (shared passwords, disabled MFA, phishing, leaked API keys) sit primarily with the Client after handover.

Why absolute security promises are dishonest

Every major cloud and OS vendor publishes shared-responsibility models and security updates for the same reason: attackers evolve, dependencies change, and humans make mistakes. Education platforms that promise perfection set clients up for disappointment and legal fiction.

Examples of threat categories (illustrative)

  • Account takeover via stolen admin passwords → MFA and password hygiene.
  • Phishing where staff hand credentials to attackers → awareness and passkeys.
  • Misconfigured cloud rules exposing data → production security rules and testing.
  • Supply-chain issues in dependencies → patching and dependency review.

What LMS White works on: secure coding for proprietary code, Corrective Fixes for Supported Versions, and initial security configuration in scope.

What LMS White does not become: a lifetime SOC, a guarantee against every cybercrime loss, or the owner of your passwords after handover.

Supporting references