Lowp tae content

Learning records

RODMENA LRS

Comin sune

The evidence store for learning: whit happened, recorded once, keepit exactly.

RODMENA LRS is a Learning Record Store: it receives records o learning activity in the xAPI format, stores thaim unchanged, and returns thaim throu the staundart xAPI query interface. It passes ivery test in the ADL LRS Conformance Test Suite for xAPI 1.0.3 and xAPI 2.0. Ivery customer’s records are isolated frae ivery ither customer’s inside the database itsel. Record contents are encrypted at rest, and learner identifiers are stored anely in a keyed, pseudonymous form. Stored records canna be altered; a learner’s personal data can be erased on request, and ilk erasure is written tae a tamper-evident log.

Wha it is for. Learning platforms and training providers that need a conformant place tae keep learner activity records. It is a back-end service: products are biggit on it and cry it frae their servers. Learners and browsers dinnae talk tae it directly. REES is its first consumer.

Status
Comin sune
Pairt o
Offerins
Licence
Proprietary. Copyright RODMENA LIMITED, aw richts reserved.
Conformance
1,365 xAPI 1.0.3 conformance tests, aw passed
1,435 xAPI 2.0 conformance tests, aw passed
Verified 23 September 2026
Tags
xAPILearning recordsConformanceMulti-tenantData protectionAudit trail

Technical specification

Stated for a technical assessor. A row wi nae measured value is left oot.

Standards

xAPI 1.0.3
ADL Experience API Specification, version 1.0.3
xAPI 2.0
IEEE 9274.1.1-2023
Version selection
Per request, by the X-Experience-API-Version heider. 1.0.x and 2.0.x are acceptit; a missin or unkent version is refusit wi 400.
Conformance suite
ADL LRS Conformance Test Suite, last run 23 September 2026
Conformance result
xAPI 1.0.3: 1,365 o 1,365. xAPI 2.0: 1,435 o 1,435.
Ayont the suite
Ilka requirement that the suite says it disnae test is covered by a dedicatit check. Sax suite tests that assert naething were identifee'd and covered sindry.
By design
OAuth 1.0 isna acceptit, acause it is deprecated. The service is cried server to server bi the products biggit on it, and disna tak cross-origin cries fae a browser.

Interface

Resources
Statements, State, Activity Profile, Agent Profile, Activities, Agents and About, wi HEAD on ilka GET route.
Authentication
HTTP Basic wi creddentials the service issues. 256-bit secrets, stored anely as a keyed verifier. Unkent, disabled an expired creddentials get byte-identical 401 responses.
Alternate Request Syntax
Supportit unner 1.0.3 and refused unner 2.0, as that specification requires.
Signed statements
JWS wi RS256, RS384 an RS512, verified whan a certificate is includit.
Attachments
multipart/mixed, matched by SHA-2 hash. 5 MiB per attachment and 1 MiB per statement body, baith configurable.
Paging
Signed stateless cursors that bide valid across a restart, wi the xAPI consistency heider on ilka statements response.
Idempotency
Re-sendin an identical statement id is acceptit withoot duplication. A conflictin ane is refusit wi 409.
Rate limiting
Per credential, wi a sindry budget for failed authentication per client address.

Isolation and security

Tenant isolation
PostgreSQL row-level security, enabled and forced on ilka table haudin tenant data. The application database role ains naething and cannae bypasse it. Ilka transaction taks its tenant frae the authenticated credential alane.
Isolation, enforced
A catalogue test fails the build if ony tenant table, or ony partition creatit at runtime, lacks the policy.
Encryption at rest
AES-256-GCM on statement bodies, documents, attachments, activity definitions and credential identities, under a per-record key derived wi HKDF-SHA256.
Ciphertext bindin
Ilka ciphertext is bund tae the identity o its ain row, sae it canna be muived tae anither row an still decrypt.
Key custody
Three keys haudit ootside the database, in 0600 key files or the environment. Thare is nae default key, an the service refuses tae stairt withoot thaim.
Key rotation
The index key rotates by an offline, resumable rekey, and rotating the credential key reissues credentials. Every record stores the id of the key that wrote it, so a rotation needs nae data migration.
Learner identifiers
Keepit anely as HMAC-SHA256 tokens unner a per-tenant key, sae the same learner in twa tenants gies tokens that are no relatit. Nae column hauds a learner identity in clear.
Credential scopes
The xAPI scope set: statements/write, statements/read, statements/read/mine, state, profile, all/read and all. The nairaest reads only the statements that the credential itsel wrote.
Immutability
Statements and attachments are append-only, enforced by database triggers that refuse UPDATE, DELETE and TRUNCATE. The only permitted changes are the voiding flag and an erasure.
Database transport
TLS wi full certificate and hostname verification is mandatory; the service winna stairt itherwise.
Request audit events
Ae structured event per request cairryin request id, credential key id, tenant, method, resource, status, record coont, duration and filter names. Learner values in filters are tokenised afore they are logged.
Tamper evidence
The erasure log is hash-chained, and a single command verifies the hale chain end tae end.

Data protection

Erasure
A pseudonymisin redaction. The learner is replaced bi a random pseudonym in ilka poseetion a statement can name thaim, free-text responses and attachments are remuived, and thair State and Agent Profile documents are deletit. Physical deletion isnae uised.
Erasure, recordit
Ilka erasure is written tae the hash-chained log. The command refuses an erasure that matches naething, sae a mistypit learner canna leuk like a completit ane.
Backups
An erasure is complete ance backups taen afore it hae expired. Efter a restore, the erasure log is replayed.
Retention
By calendar month, per instance. The month is detached, exported as one file per tenant, and dropped. The drop is refused unless the exported row count matches.
Keepin, per customer
A customer needin its ain retention period needs its ain instance.
Export on exit
The staunart xAPI interface. A customer can page throu ilka record as xAPI JSON, wi its attachments, an tak the lot.
Residency
An instance rins in the region a contract requires. The service needs only a PostgreSQL database.

Operations and verification

Deployment model
A shared multi-tenant instance, or a dedicated instance per customer.
Probes prove they can fail
Ilkane o the 47 behavioural probes maun be shawn tae FAIL against a deliberately broken build afore its pass is coontit, an the harness enforces that. The conformance suite is run against broken builds for the same reason.

Whit it dis

  • Conformance-tested

    Passes aw 1,365 tests o the ADL LRS Conformance Test Suite for xAPI 1.0.3, an aw 1,435 for xAPI 2.0.

  • Records niver cheenge

    Efter it is stored, a statement cannae be editit or owersetten, only voided, as the staundart specifies.

  • Isolatit bi design

    Ilk customer's records are separatit by rules enforced in the database, and no juist by application code.

  • Encryptit an pseudonymous

    Record contents are encrypted at rest, and learner identifiers are indexed only as keyed tokens.

  • Erasure wi an audit trail

    A learner’s personal data is taen oot o their records on request, and ilka erasure is recordit in a tamper-evident, hash-chained log.

  • Scoped credentials

    Ilka credential is limitit tae the operations it needs, doun tae readin anely the records it wrote itsel.

For documentation, a pilot or an integration, contact us.