Hey Indie Hackers 👋 I’m Justin, the maker of PTEcorepractice.
I built it because PTE Core prep is often scattered across random resources, and it’s hard to know what to fix after each practice. PTEcorepractice puts practice + scoring + clear feedback in one simple flow, so learners can improve consistently.
What it does (today):
Realistic PTE Core-style practice
Quick scoring + actionable feedback
A focused experience to help you improve week by week
Who it’s for:
Anyone preparing for PTE Core who wants structured practice and faster improvement.
Link: https://ptecorepractice.com/
What I’d love feedback on:
Does the positioning make sense? (“practice, score, improve”)
What feature would you want most: more question types, full mock tests, or a study plan/progress tracking?
Happy to answer any questions — and if you’re also building in edtech or test prep, I’d love to connect.
Congrats on the launch, looks solid. How are you currently thinking about acquiring early users and gathering feedback?
Thanks a lot — really appreciate it.
For early users, we’re focusing on a tight loop:
1) reaching learners where they already are (PTE communities + search),
2) getting them into a fast “practice → score → improve” flow,
3) iterating weekly based on real usage.
For feedback, we use both in-product feedback and direct learner interviews, then prioritize by impact and frequency. Early stage for us is all about shipping fast, measuring what actually improves outcomes, and tightening that loop.
Congrats on shipping! Test prep is a clear, painful problem, and “practice → score → improve” is a clean loop.
Since you’re handling scoring and potentially written or spoken answers, how are you protecting user submissions and progress data?
• Are answers stored with proper isolation between users?
• Are scoring requests processed strictly server side?
• Do you have rate limiting in place to prevent answer scraping or abuse of scoring endpoints?
In edtech, especially exam prep, trust is part of the product. Learners want to know their data, scores, and personal progress won’t leak or be manipulated.
Curious how you’re thinking about protecting learner data as usage grows.
Great question — we agree that trust is part of the product.
Current approach:
- User data isolation: practice/progress data is scoped to each user account, with database-level row-level security policies.
- Server-side scoring: scoring requests are handled through server APIs; provider keys are kept server-side.
- Abuse controls: scoring/auth flows have server-side quota and rate checks (with 429 responses on limit), including guest quota controls.
- Security baseline: we also enforce standard security headers and continue to harden abuse detection as usage grows.
We treat this as ongoing work and keep tightening controls as traffic scales.
Strong foundation. Row level isolation and server side scoring are the right starting points.
As usage grows, a few areas usually become critical in edtech:
• Encryption at rest for answers and progress data, especially written responses
• Strict separation between scoring logic and public APIs
• Monitoring for unusual scoring patterns or automated scraping attempts
• Clear retention policy for inactive accounts
Exam prep data has real value. Score manipulation or data leaks damage credibility fast.
It helps to make this visible:
• Short security overview page
• Clear data retention statement
• Simple explanation of how answers are protected
In learning products, trust drives retention.
As a security team building Nautillo Pro, we follow the same approach. Strong isolation. Server side control. Continuous validation of exposed paths.
We also offer a free version.
If you ever want to test how your platform behaves from an external attacker perspective, Nautillo Pro is available to run a controlled simulation.