Security & governance

Secure by default — in plain language.

The controls IT and compliance reviewers expect, explained without an AWS deep-dive — and with claims we can actually stand behind.

Platform controls

The essentials, covered.

Identity & access

Multi-factor authentication with an authenticator app, and role-based access control across the platform.

Encryption & networking

Encryption in transit and at rest with managed keys, private networking with no public database or cache, and a web application firewall at the edge.

Backups & continuity

Automated, encrypted backups with retention — and tested restore drills. High-availability and disaster-recovery options for dedicated enterprise deployments.

AI governance

Per-tenant spend caps, a full audit trail, acceptable-use policy, best-effort PII redaction, and in-region processing — with human review on grade- or course-changing actions.

Auditability & data handling

Application audit logging and data-residency options. We provide PDPA-ready controls and documentation.

Deployment isolation

Cost-efficient shared infrastructure for smaller programs; dedicated, isolated stacks with scoped access for enterprise and government.

AI, governed

Turn AI on without losing oversight.

Every AI action runs through a governance gateway. AI runs on Amazon Bedrock inside our AWS account — you don't manage API keys, and processing stays in-region.

  • Cost control — per-tenant spend caps, enforced.
  • Accountability — a full audit trail of AI usage and cost.
  • Data — in-region processing, best-effort PII redaction, keyless.
  • Human control — teacher review on grades and course changes; the tutor answers only from course content, with citations.
AI governance overview
Monthly AI spendwithin cap
Every request audited
In-region model · apac
Policy accepted by users
Straight talk

What we claim — and what we don't.

Security reviewers appreciate honesty. Here's exactly where we stand today.

What we provide today

  • MFA, RBAC, encryption with managed keys, private networking, WAF.
  • Automated encrypted backups with tested restore drills.
  • Governed AI: spend caps, audit, best-effort PII redaction, in-region.
  • PDPA-ready controls & documentation; data-residency options.
  • Dedicated, isolated deployments for enterprise & government.

What we're careful not to overstate

  • We do not hold SOC 2 or ISO 27001 certification.
  • PII redaction is best-effort risk reduction, not guaranteed data-loss prevention.
  • High-availability and disaster-recovery are options for dedicated deployments, not a default on every plan.
  • SLA targets are set per plan or contract — we don't publish a blanket uptime promise.

Need to run a security questionnaire or discuss data-processing terms? Talk to our team

Bring your security and compliance questions.

We'll walk your IT and compliance reviewers through the controls, deployment isolation options and data handling — in plain language.