Lowp tae content

Lairnin records

RODMENA LRS

Comin sune

The evidence store for learning: what happened, recorded once, kept exactly.

RODMENA LRS is a Learning Record Store: it receives records o learning activity in the xAPI format, stores thaim unchanged, an returns thaim throu the staunart xAPI query interface. It passes ivery test in the ADL LRS Conformance Test Suite for xAPI 1.0.3 an xAPI 2.0. Ivery customer's records are isolated frae ivery ither customer's inside the database itsel. Record contents are encrypted at rest, an learner identifiers are stored only in a keyed, pseudonymous form. Stored records cannae be altered; a learner's personal data can be erased on request, an ilk erasure is written tae a tamper-evident log.

Wha it is for. Lairnin platforms an trainin providers that need a conformant place tae keep learner activity records. It is a back-end service: products ir biggit on it an caa it fae their servers. Learners an browsers dae no talk tae it directly. REES is its first consumer.

Status
Comin sune
Pairt o
Offerins
Licence
Proprietary. Copyright RODMENA LIMITED, all rights reserved.
Conformance
1,365 xAPI 1.0.3 conformance tests, aa passed
1,435 xAPI 2.0 conformance tests, aa passed
Verified 23 September 2026
Tags
xAPILairnin recordsConformanceMulti-tenantData protectionAudit trail

Technical specification

Stated for a technical assessor. A row wi nae measured value is left oot.

Standards

xAPI 1.0.3
ADL Experience API Specification, version 1.0.3
xAPI 2.0
IEEE 9274.1.1-2023
Version selection
Per request, by the X-Experience-API-Version heider. 1.0.x an 2.0.x is accepted; a missin or unkent version is refused wi 400.
Conformance suite
ADL LRS Conformance Test Suite, last run 23 September 2026
Conformance result
xAPI 1.0.3: 1,365 o 1,365. xAPI 2.0: 1,435 o 1,435.
Ayont the suite
Requirments the suite states it disnae test are ilkane covered by a dedicated check. Sax suite tests that assert naethin were identified an covered separately.
By design
OAuth 1.0 is no accepted, for it is deprecated. The service is cried server to server by the products biggit on it, an doesna tak cross-origin calls fae a browser.

Interface

Réssources
Statements, State, Activity Profile, Agent Profile, Activities, Agents an About, wi HEAD on ilka GET route.
Authentication
HTTP Basic wi creddentials the service issues. 256-bit secrets, hained only as a keyed verifier. Onkent, disabled an expired creddentials get byte-identical 401 responses.
Alternate Request Syntax
Supported unner 1.0.3 an refused unner 2.0, as that specification requires.
Signed statements
JWS wi RS256, RS384 an RS512, verified whan a certificate is included.
Attachments
multipart/mixed, matched by SHA-2 hash. 5 MiB per attachment an 1 MiB per statement body, baith configurable.
Paging
Signed stateless cursors that bide valid owre a restart, wi the xAPI consistency heidder on ilka statements response.
Idempotency
Re-sendin an identical statement id is accepted athoot duplication. A conflicting yin is refused wi 409.
Rate limiting
Per credential, wi a separate budget fur failed authentication per client address.

Isolation an security

Tenant isolation
PostgreSQL row-level security, enablit an forced on ivery table haudin tenant data. The application database role awns naethin an cannae by-pass it. Ilka transaction taks its tenant frae the authenticated credential alane.
Isolation, enforced
A catalogue test fails the build if ony tenant table, or ony partition creatit at runtime, wants the policy.
Encryption at rest
AES-256-GCM on statement bodies, documents, attachments, activity definitions an credential identities, unner a per-record key derived wi HKDF-SHA256.
Ciphertext bindin
Ilka ciphertext is bund tae the identity o its row, sae it cannae be moved tae anither row an still decrypt.
Key custody
Thrie keys haudit ootside the database, in 0600 key files or the environs. Thair is nae default key, an the service refuses tae stairt withoot thaim.
Key rotation
The index key rotates by an offline, resumable rekey, an rotatin the credential key reissues credentials. Ilka record stores the id o the key that wrote it, sae a rotation needs nae data migration.
Learner identifiers
Keepit ainly as HMAC-SHA256 tokens unner a per-tenant key, sae the same learner in twa tenants gies tokens that hae nae connection. Nae column hauds a learner identity in clear.
Scopes o creentials
The xAPI scope set: statements/write, statements/read, statements/read/mine, state, profile, all/read and all. The narrest reads only the statements that the credential itsel wrote.
Immutability
Statements an attachments is append-only, enforced by database triggers that refuse UPDATE, DELETE an TRUNCATE. The only permitted chynges is the voidin flag an an erasure.
Database transport
TLS wi full certificate an hostname verification is mandatory; the service refuses tae start otherwise.
Request audit events
Ae structurt event per request cairryin request id, credential key id, tenant, method, resoorce, status, record coont, duration an filter names. Learner values in filters is tokenised afore thay are logged.
Tamper evidence
The erasure log is hash-chained, an a single command verifies the hale chain end tae end.

Data protection

Erasure
A pseudonymisin redaction. The learner is replaced wi a random pseudonym in ivery poseetion a statement can name them, free-text responses an attachments is remuived, an their State an Agent Profile documents is deletit. Physical deletion isnae uised.
Erasure, recordit
Ilka erasur is written tae the hash-chained log. The command refuses an erasur that matches naethin, sae a mistypit learner canna leuk like a compleated yin.
Backups
Ane erasure is complete ance backups taen afore it hae expired. Efter a restore, the erasure log is replayed.
Retention
By calendar month, per instance. The month is detached, exported as one file per tenant, and dropped. The drop is refused unless the exported row count matches.
Keepin, per customer
A customer needin its ain retention period needs its ain instance.
Export on exit
The staunart xAPI interface. A customer can page throu ivery record as xAPI JSON, wi its attachments, an tak the lot.
Residency
A instance rins in the region a contract needs. The service needs only a PostgreSQL database.

Operations an verification

Deployment model
A shared multi-tenant instance, or a dedicated instance per customer.
Probes pruive they can fail
Ilkane o the 47 behavioural probes maun be shawn tae FAIL agin a build that's been broke on purpose afore its pass is coontit, an the harness hauds that tae. The conformance suite is run agin broken builds for the same reason.

Whit it daes

  • Conformance-tested

    Passes aa 1,365 tests o the ADL LRS Conformance Test Suite fur xAPI 1.0.3, an aa 1,435 fur xAPI 2.0.

  • Records niver chynge

    Eence it is stored, a statement cannae be edited or owrewritten, only voided, as the staundart specifies.

  • Isolatit by design

    Ilka customer's records is sindered by rules that is enforced in the database, an no juist by application code.

  • Encrypted an pseudonymous

    Record contents is encryptit at rest, an learner identifiers is indexed ainly as keyed tokens.

  • Erasure wi an audit trail

    A learner’s personal data is taen oot o their records on request, an ilka erasure is recordit in a tamper-evident, hash-chained log.

  • Scoped credentials

    Ilka credential is limitit tae the operations it needs, doun tae readin anely the records it wrat itsel.

For documentation, a pilot or an integration, contact us.