SetFlow
SetFlow
Trust & security

The trust story, in one document.

Built for schools, students, and small teams who actually read this page before signing. Press coverage, research, security architecture, compliance commitments, privacy transparency, and the procurement contact — all in one place.

Effective Last updated May 24, 2026

Why trust SetFlow

Built so that a breach of SetFlow can't expose your students' data.

Under BYODB, student records live in your institution's own database — never on SetFlow's servers. LTI integrations are verified via DNS domain control. We commit to 72-hour written breach notification. We sign your DPA within 5 business days.

Procurement? [email protected] — the founder replies directly.

1. Press coverage

SetFlow has been covered by independent local press in Wichita Falls, Texas — coverage tied to the May 2026 response to the Canvas / Instructure data breach.

  • CBS News Channel 6 (KAUZ) — May 15, 2026. Reporter Shun'de Hooks covered the AI education platform built by an MSU Texas international student. <a href="https://www.newschannel6now.com/2026/05/15/msu-texas-international-student-develops-ai-platform-support-educational-learning/">newschannel6now.com</a>. SetFlow write-up at <a href="/blog/setflow-featured-cbs-news-msu-texas-international-student-ai-education-platform">/blog</a>.

  • Fox News Channel 3 (KFDX/KJTL — Texoma's Homepage) — May 18, 2026. Reporter Eddison Stewart covered SetFlow's BYODB Canvas alternative built after the cyberattack. <a href="https://www.texomashomepage.com/news/local-news/midwestern-state-university-student-develops-alternative-to-canvas-following-cyberattack/">texomashomepage.com</a>. SetFlow write-up at <a href="/blog/setflow-featured-fox-news-msu-student-canvas-alternative-cyberattack">/blog</a>.

  • Royal Institute Colombo alumni feature. SetFlow's founder, Sanithu Hulathduwage, was featured in the Royal Institute Colombo alumni programme as the first international student to ship a US-market AI platform from MSU Texas.

2. Research

The BYODB architecture is described in an academic working paper:

  • BYODB: A Decentralized Database Architecture for Learning Management Systems. Published on SSRN — May 2026. Abstract ID: 6798778. Read at <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6798778">papers.ssrn.com/sol3/papers.cfm?abstract_id=6798778</a>. The paper formalises the BYODB threat model and shows why centralised LMS data architectures produced the Canvas breach.

3. Security architecture

SetFlow is built so that a complete compromise of SetFlow's infrastructure cannot expose student records. The three load-bearing controls:

  • BYODB student-data sovereignty. Schools on the institutional plan can hold classroom data in their own database. SetFlow stores only an encrypted connection string. Under BYODB, a breach of SetFlow cannot leak student records because we never held them. Full technical details on the <a href="/security">security page</a>.

  • LTI 1.3 with DNS domain verification. Every LMS integration is cryptographically signed against the platform's published keys, plus a DNS TXT-record check that the institution controls the domain. Same trust model as SSL Domain-Validation certificates.

  • 72-hour written breach notification. We will deliver written breach notice to the institution's designated contact within 72 hours of confirming unauthorized access to their data. No "let us understand the full scope" delay.

Read the full security architecture →

4. Compliance commitments

Read the schools / FERPA doc →

5. Privacy transparency

See the Privacy Center →

6. Procurement contact

Ready to evaluate SetFlow for your institution?

We have a packet ready: written security policies, data-flow diagram, sample DPA, sub-processor list, and incident-response plan. The founder replies directly.

Contact

Privacy questions, data requests, DPAs: [email protected]. Security disclosures: [email protected]. General product support: [email protected]. Sanithu (founder) replies directly.

See also /security for the threat model and disclosure policy, /privacy-center for every privacy artifact, and /status for current uptime.

Questions? [email protected] — the founder replies directly.