Security and privacy
For your security and privacy team. Nothing on this page requires action; it documents how the embed behaves.
No cookies, no storage, no tracking
Section titled “No cookies, no storage, no tracking”Neither the iframe nor the widget sets cookies or uses local storage. Neither loads analytics or consent scripts. The script widget requests data without credentials.
Data flow
Section titled “Data flow”- Your visitors’ browsers request the catalog from
www.edgeaifoundation.org, hosted on Vercel. - Only standard request metadata reaches us: IP address, the origin hostname of the embedding page and your partner ID.
- Course images load directly from Thinkific’s image CDN (CloudFront, United States).
- Clicking a course opens our public website in a new tab. Our own privacy and cookie policies apply there.
Isolation
Section titled “Isolation”- The script widget renders inside a Shadow DOM and never inserts unescaped remote content into your page.
- The iframe is restricted to your registered hostnames through a
frame-ancestorspolicy set by our server. Browsers refuse to render it anywhere else. - Partner tokens only prove that a snippet was issued for your partner ID. They grant no access to anything else.
Accessibility
Section titled “Accessibility”We target WCAG 2.2 AA.
- Every course is a single keyboard-reachable link with a visible focus ring.
- Motion respects
prefers-reduced-motion. - Loading and error states are announced to screen readers.
- The iframe snippet carries a descriptive
title.