Skip to content

The platform

Everything that is in it, on one page.

One page rather than six thin ones, because six pages about one product is a way of looking bigger than you are. Where a thing is designed and not yet running, the sentence that describes it says so — and none of it is deployed anywhere yet, because there are no customers to deploy it for.


What it is

An empty study app that becomes yours when your material goes into it.

It has no course of its own. There is no library of ready-made theory in here waiting to be switched on, and that absence is the product rather than a gap in it.

Your students study on their phones, from your book, under your name. Your staff work in a console holding your material, your drafts and your published versions. Both halves belong to one school and cannot see another: the database itself refuses a query that has not said which school is asking. The detail is on security and data.

We have no course of our own to sell you, and we will never sell your students anything — not a subscription, not an upgrade, not a course, not anything at all.

Page citations

Every claim carries the page it came from. Every paragraph says who wrote it.

So you never have to trust us sentence by sentence. You check us against the copy on your desk, three rules at a time.
Fig. 9 — the four labels, and the values behind them
  • From your material

    Your own words, lifted from your book and not rewritten.

    source_extracted

  • Written from your material

    Written from a section of your material, with the page it came from underneath it.

    ai_generated_from_source

  • Written without a source

    Written with nothing behind it. Nothing in the product can produce one today.

    ai_generated

  • Written by a person

    Somebody put their name to it — one of your people, or one of ours.

    human_authored

The shipped component and the shipped colours, at the size a student sees them, with the value stored on the row underneath each. Four states rather than three, because three cannot tell “written from your material” apart from “written from nothing”.

The label sits on the paragraph, in the lesson, not in a settings page nobody opens. It is applied by the renderer to every block rather than block by block, because “everything is labelled” is only true if it cannot be forgotten.

A citation is a page range and the quoted sentence, and it becomes a verified citation only once that sentence has been matched against the text of the page it names — the two are stored separately so the difference is queryable rather than a matter of opinion. Until then it is shown marked unverified. The matching is deterministic and is explicitly not a model judging whether a model cited correctly: normalise, collapse the whitespace, re-join words broken across lines, match against the cited page, then a fuzzy fallback above a fixed threshold. That checker is specified and not yet written, so today a person does it with the pages in front of them.

We will not generate a question we cannot point at a page for, and we will not show a citation we have not checked as though we had.

Your question bank

Your past papers go in as you wrote them, and the system records that they are yours.

Fifteen years of exam questions in a filing cabinet is the reason your course is worth paying for. Everybody has offered to replace it; we are offering to keep it.
Word for word
A question taken from your material is stored with its source recorded as extracted verbatim — a distinct value from a question somebody wrote later, so “these are our own past papers” is a fact the database holds rather than a claim on a page.
Your official bank
A bank can be marked as your own official one. A mock exam assembled from your official bank is a materially different thing from one assembled from questions we wrote, and the difference has to survive being asked about by a regulator.
Four question types
Single choice, multiple choice, true or false, and free text. That list is closed on purpose: adding to it is a decision, not a configuration screen.
Four states
Draft, approved, rejected, retired. A retired question is kept rather than deleted, because next year somebody will want to know what it used to say.
Every attempt kept
One row per answer, appended rather than overwritten, so a retry is a new row and the first attempt survives. That is what makes “which question does everyone get wrong” answerable a year from now.
Nothing invented
The vocabulary has a value for a machine-written question and nothing in the product can currently produce one, because nothing here calls a model. When that changes, the label on the screen changes with it.

We will not improve your questions. They go in as you wrote them or they do not go in.

What your students see

Your name at the top. Nothing on the screen names a supplier.

Your colours and your school’s name on every screen, and nothing anywhere in it that names a supplier.
  1. 1

    Your colours, from the first paint

    The branding is written into the page during the server render, so the first thing that appears is already yours. There is no moment where it is visibly the wrong colour and then corrects itself, which is the tell that a supplier has skinned somebody else’s product.
  2. 2

    The whole course in one request

    A student’s course arrives in a single call and is rendered on the server. No spinners, no half-loaded lesson, and it behaves on the connection your students actually have rather than on the one in our office.
  3. 3

    Pinned to the version they started

    A student stays on the version they enrolled on. Publishing a correction does not move somebody who is three lessons in, and a published version cannot be edited underneath them at all — a correction is a new version.
  4. 4

    A draft is never mistaken for the real thing

    Your staff can preview an unpublished version and it carries a banner saying so. A student cannot see one at all: the permission that unlocks a draft is not one the student role holds.
  5. 5

    Progress, and every answer

    Which lessons are done, how long they took, and every question attempt with its result. Enough to see who has stopped, without a surveillance product attached to it.
  6. 6

    How they get in

    An owner or an administrator generates an access link and hands it over. Nothing is emailed, because nothing in this product sends email; the link is shown once, is stored only as a hash, and expires after fourteen days.

Two things this does not do yet. Your students sign in — no download and no app store, but an account, and we are not going to call that no account. And your address on the web is a name we hold for you rather than a route that resolves: it is stored and checked against a reserved list, and served today under your school’s own path.

There is also no QR code. The database reserves the words for one — a code per branch, a code per instructor — and nothing reads them, because no such feature is built. It goes on this page the day it exists, not before.

We will not put our name on your students’ screens, and we will not contact them about anything, ever.

Your staff and their roles

Five roles for your people, and the useful question is what each one cannot do.

Fig. 10 — who can do what
Which organization roles hold which permissions, printed from the shipped matrix
CanOwnerAdminEditorInstructorAnalystStudent
Change the school itselfyesyesnononono
Add and remove peopleyesyesnononono
Publish to your studentsyesyesnononono
Write and edit lessonsyesyesyesnonono
Edit the question bankyesyesyesnonono
Upload your materialyesyesyesnonono
Hand out access linksyesyesnoyesnono
See every student’s progressyesyesnoyesyesno
Read the audit logyesyesnononono
Printed from the permission matrix the API enforces on every request, not drawn from a description of it. Nine of the thirty-one permissions; the sixth column is the student, which is why the code has six roles where this page says five.
Owner
Everything. The one thing the system protects is that there is always one: the change that would leave your school with no active owner is refused, whoever makes it, including the owner making it to themselves.
Admin
Runs your people, your branding and your courses, and can publish. Cannot promote anybody to owner and cannot mint an invitation link that hands out an admin role to whoever finds it — a link that privileged has to be addressed to a named person.
Editor
Writes and edits lessons, uploads your material, edits questions, builds a draft version — and cannot publish it. Making a version live needs an owner or an admin. Cannot touch your people or the school itself.
Instructor
Sees how students are getting on, and holds the permission to hand out access links — though the route behind that one is not built yet, so today the links come from an owner or an admin. Cannot edit a lesson, a question or a person.
Analyst
Reads results and reporting and changes nothing at all — not one write permission in the matrix.
The student
Studies the published course and sees their own progress. Not a staff role, and the reason the code has six values where this page has five.

Suspending somebody signs them out everywhere, immediately: their tokens are revoked and a revocation time is stamped on the account that every later request is checked against, so an open session stops working on its next click rather than whenever the cookie expires. It is the thing everybody assumes already works, and usually it does not. Every change to who can do what, and every publish, is written to an audit log that deleting the person does not erase.

Formats we accept

What the reader reads, and what it refuses.

The section a supplier normally answers with “any format”. Here is the real answer, including the three the upload takes and the reader turns down.
What happens to each format, and the limits that apply
PDF with a text layerRead end to end. This is the one to send.
PDF that is a scanRouted to optical character recognition in batches of 200 pages, up to 1,000 pages per document
Plain textRead directly
Word (.docx)Accepted by the upload, refused by the reader as an unsupported type
PowerPoint (.pptx)The same
PNG or JPEGThe same
Largest single file250 MB
Longest single document3,000 pages
Text extraction, per job400 pages
Password-protected PDFRefused, and told to you as that rather than as a failure
Encrypted, corrupt or empty fileReported as a result rather than a crash

Word, PowerPoint and image uploads are stored and then reported by the reader as an unsupported type — an actionable answer rather than a crash. Each is a separate library and a separate way of finding the headings in a document, and we would rather have two formats that work all the way through than five that work as far as the first table.

A document that fails does so by name: eleven named failures, each ending with what to do about it. “Page 47 could not be read — the scan resolution is 96 DPI, below the 150 DPI needed for reliable text extraction. Re-scan that page at 300 DPI and upload again.” The page number and both figures are measured rather than adjectives.

Reading a scan costs real money per page, so it is off by default and cannot be switched on outside a deployed environment at all — and there is no deployed environment. Nothing on this page is running anywhere yet. The first place any of it runs is on the chapter you send us.

We will not quietly retry a document that cannot be read. A file that fails stops, once, and somebody tells you why.

All of it is built on your book being yours. Who owns the converted course, what we check before we convert a page, and what you get on the day you leave: Your material

Send one chapter.

Not a demo of somebody else’s course. A chapter of yours, converted properly, so you can look at your own questions and your own page numbers and decide whether it is any good. Pick the chapter you know best. If it is no good, you have lost an email.

We will ask who owns the copyright before we convert anything. If you do not hold the rights to the material, we will say so rather than take the work.