For technical evaluators

Understand the architecture without starting in the source code.

Review the trust boundaries, deployment choices, data store, device modes, and release model before opening the operator documentation.

The assessment trust flow.

Each system keeps the responsibility it is best positioned to enforce.

Canvas establishes identity

Signed LTI 1.3 launches identify the Canvas tenant, deployment, user, course, and role.

The service creates policy

Instructor settings, course defaults, and school presets become the approved SEB configuration.

SEB proves the configuration

A current Config Key proof is required before the Canvas access code is released inside the approved session.

Canvas serves the assessment

Canvas keeps its own authorization and assessment behavior while SEB enforces the device and URL policy.

The architecture at a glance.

These are the details most technical evaluators need before moving into installation and operations documentation.

Application stack

NestJS 11 on Express, React 19 with Vite, and a Node.js 24 container.

State and concurrency

PostgreSQL 17 stores assessments, courses, OAuth grants, sessions, transient state, operation locks, and administrator data.

Deployment

Cloud Run with Cloud SQL and Docker Compose on a VPS use the same released container image and migration model.

Device modes

Certificate wrapping is the stronger default. Compatibility mode supports instances that cannot distribute a private identity to BYOD devices.

Release model

v1.0.1 ships immutable release artifacts for Cloud Run and Docker Compose with checksums and provenance.

Source license

Safe Online Exam is source-available under PolyForm Noncommercial. Safe Exam Browser is a separate open-source project.

Go deeper where your review requires it.

The marketing overview stops here. The security model and operator documentation retain the exact routes, variables, timing, deployment, and recovery details.

Security and trust

Launch validation, Config Key proof, secret handling, key custody, rate limits, and known limits.

Self-hosting

Cloud Run, Cloud SQL, Docker Compose, PostgreSQL, migrations, cleanup, backup, and device responsibility.

SEB Canvas LTI

The LTI identity and session bridge between Canvas and Safe Exam Browser.

Operator documentation

The complete install, connect, verify, operate, troubleshoot, and reference path.

Bring your technical and assessment teams together.

A demo can cover the user experience first, then move into deployment, device policy, source review, and operational responsibility.