Skip to content

Security and privacy

For your security and privacy team. Nothing on this page requires action; it documents how the embed behaves.

Neither the iframe nor the widget sets cookies or uses local storage. Neither loads analytics or consent scripts. The script widget requests data without credentials.

  • Your visitors’ browsers request the catalog from www.edgeaifoundation.org, hosted on Vercel.
  • Only standard request metadata reaches us: IP address, the origin hostname of the embedding page and your partner ID.
  • Course images load directly from Thinkific’s image CDN (CloudFront, United States).
  • Clicking a course opens our public website in a new tab. Our own privacy and cookie policies apply there.
  • The script widget renders inside a Shadow DOM and never inserts unescaped remote content into your page.
  • The iframe is restricted to your registered hostnames through a frame-ancestors policy set by our server. Browsers refuse to render it anywhere else.
  • Partner tokens only prove that a snippet was issued for your partner ID. They grant no access to anything else.

We target WCAG 2.2 AA.

  • Every course is a single keyboard-reachable link with a visible focus ring.
  • Motion respects prefers-reduced-motion.
  • Loading and error states are announced to screen readers.
  • The iframe snippet carries a descriptive title.