TeachSmartHQ™ · IT & Allowlist

Blocked at school? Here's everything your IT team needs.

Some districts filter classroom tools by default — not because there's a problem, but because filters block what they don't recognize. If TeachSmartHQ™ isn't loading on your school network, your technology team can clear it in a couple of minutes.

Everything they need is on this page. Send them the link, or use the ready-made email below.

01

District tech teams

The three domains

TeachSmartHQ™ runs on three hostnames. Allowlisting all three, over HTTPS on port 443, is sufficient for full functionality.

teachsmarthq.com app.teachsmarthq.com play.teachsmarthq.com
DomainWho uses itWhat it does
teachsmarthq.comPublicMarketing site, pricing, documentation. No login.
app.teachsmarthq.comStaff onlyThe teacher application. Requires an authenticated educator account.
play.teachsmarthq.comStudentsStudent activity endpoint. No account, no sign-in.

If you allowlist by organizational unit, note that app.teachsmarthq.com is a staff tool and play.teachsmarthq.com is the only hostname students need. Teachers and students typically sit in different OUs with different policies — clearing a domain for staff does not clear it for students.

What happens on the student endpoint

play.teachsmarthq.com serves practice activities a teacher has already created and assigned.

There are no student accounts and no student sign-in. A student opens a link their teacher gives them. There is no registration, no email field, and no name field. A student who visits play.teachsmarthq.com without a class link sees a single line telling them to ask their teacher for one.

Students do not interact with an AI system on this endpoint. They open material a licensed educator generated, reviewed, and assigned.

Student data

The four statements below are the ones a district reviewer usually needs. Each was checked against the running code, not against our own marketing.

  • The student surface is identity-free by design. A student is represented by a chosen icon and an opaque token, not by a name. There is no field anywhere on the student endpoint that asks a student who they are.
  • What we store: teacher-created instructional content, and a limited record of practice activity used to generate progress information for the teacher — kept against an anonymous activity token, never against a student's name. We do not store grades, demographic records, or student information imported from a district system.
  • Personally identifying text is scrubbed server-side before it reaches an AI provider, and the scrubber is fail-closed: if it cannot complete, the request is dropped rather than forwarded unscrubbed.
  • Our AI provider is contractually prohibited from training on our customers' inputs or outputs. The provider is Anthropic; the restriction is in their commercial terms.

On third parties, specifically: the student endpoint makes no third-party requests at all. The code that serves play.teachsmarthq.com contains no outbound calls to any external service — no analytics, no AI provider, no font or script CDN.

The teacher application does use outside services, all on the staff side of the login: Anthropic for generation, Stripe for payments, Brevo for transactional email, and Cloudflare Turnstile for bot protection on the sign-in form. None of them receive student data. If you need the complete subprocessor list for a Data Privacy Agreement, ask and we'll send it.

Is this an AI tool?

Yes, on the teacher side, and we'd rather say so plainly than have you find out from a filter.

Educators use TeachSmartHQ™ to generate worksheets, lesson plans, and documentation drafts. That generation is AI-assisted and it happens on app.teachsmarthq.com, behind an authenticated staff login.

Some filters categorize us under a general "Artificial Intelligence" bucket on that basis. If your district blocks that category on student devices, we'd note that play.teachsmarthq.com — the only hostname students use — has no accounts, no sign-in, and no student-facing AI interaction. It serves material a teacher already made.

Current categorizations

Each row shows the date it was last checked · most recent August 20, 2026
DatabaseCategoryVerifiedHow
Ativion (ContentKeeper / Impero) Education August 20, 2026 Classified Education by Ativion support, ticket #389078; subdomains inherit the same classification.
Securly EdTech August 19, 2026 Recategorized for all Securly customers by Securly support, ticket #1087442.
Cisco Talos / Umbrella Education August 20, 2026 Read directly from the Talos reputation center.
Symantec / Broadcom WebPulse Education August 18, 2026 Confirmed by Broadcom, ticket #26015725.
Fortinet FortiGuard Education August 19, 2026 Already categorized Education; no change was required.
Trellix Education August 19, 2026 Read from the vendor lookup during our 2026-08-19 sweep.
OpenText / BrightCloud (Webroot) Education August 19, 2026 Read from the vendor lookup during our 2026-08-19 sweep.
Palo Alto Networks Education August 19, 2026 Read from the vendor lookup during our 2026-08-19 sweep.

This list covers the vendors we have verified directly. It is not every filter in use. If yours isn't here, contact us and we'll submit.

Listed but not reportable — we name this rather than leave it out, so a reader can tell “there is nothing to report” apart from “we didn’t look”:

  • Norton Safe Web — publishes a site safety rating, not a content category — there is no category to report

Questions

Email hello@teachsmarthq.com and a human will answer. If you need a Data Privacy Agreement, an NDPA, or a security review for vendor approval, say so and we'll start that conversation.

02

For teachers

Copy the email below, fill in the two brackets, and send it to your school or district technology team. That's the whole process.

One thing worth knowing: if your district runs student devices in allowlist-only mode, no amount of correct categorization will help — the domains have to be added by name. That's what this request does.

© 2026 TeachSmartHQ™ · No Lost Learner™