Trust & Safety
Last updated: June 2025
Prodlake handles sensitive professional knowledge. Engineers trust us with their production stories, and learners trust that the content they pay for is authentic and safe. This page explains how we protect both sides of that trust.
1. Our Principles
Instructor ownership is absolute
Instructors own their content. We never repurpose, resell, or use instructor material outside the platform relationship. If an instructor deletes their content, it's gone.
Secrets never leave the gate
Every experience passes through content review before publication. We scan for patterns matching API keys, tokens, connection strings, and credentials. Anything flagged is blocked from publication and the instructor is notified privately.
AI Studio is a tool, not a source of truth
AI-generated teaching assets are backdrops for instructor narration. We do not represent AI output as authoritative production data. Instructors review and take responsibility for what they publish.
Learner payment data stays with Stripe
We never store full payment credentials on our infrastructure. All payment processing happens through Stripe's PCI-compliant systems.
2. Content Security
Pre-publication scanning: Automated pattern matching scans uploaded content for common secret formats (AWS keys, GitHub tokens, database connection strings, private keys). Flagged content is held from publication.
Human review: Every new experience is reviewed by our team before it goes live. Reviewers check for prohibited content, quality standards, and accurate metadata.
Ongoing monitoring: Published content is periodically re-scanned as our detection patterns improve. If previously-published content is found to contain secrets, it is immediately unpublished and the instructor is contacted.
3. Account Security
- Authentication via Clerk with support for multi-factor authentication (MFA).
- Instructor payout accounts require identity verification through Stripe Connect.
- Session tokens expire after inactivity and cannot be transferred between devices.
- Suspicious login patterns (new geography, multiple failed attempts) trigger additional verification.
4. Intellectual Property Protection
For instructors: We take DMCA takedown requests seriously. If your content is being redistributed outside Prodlake, report it and we will act. We also implement technical measures to prevent bulk downloading of video content.
For third parties: If you believe content on Prodlake infringes your intellectual property or contains your organization's confidential information, contact trust@prodlake.com with specific details. We respond to legitimate claims within 48 hours.
5. Platform Integrity
- Review manipulation: Fake reviews are detected and removed. Accounts engaged in review manipulation are permanently banned.
- Content authenticity: Experiences must represent genuine engineering knowledge. Plagiarized or fabricated content is removed.
- Fair payouts: Our 70/30 split is transparent and consistent. Payout calculations are auditable by instructors in their dashboard.
6. Incident Response
If we discover a security issue — exposed credentials in published content, unauthorized access, or data breach — our response process is:
- Immediately contain (unpublish content, revoke access).
- Notify affected parties within 24 hours.
- Investigate root cause and implement prevention measures.
- Publish a post-mortem for incidents affecting multiple users.
7. Reporting
Report trust or safety concerns to trust@prodlake.com. For credential exposure or active security issues, include "URGENT" in your subject line for expedited handling.