Encryption
TLS in transit; encryption at rest with managed keys for databases, file storage and backups.
This page explains the controls we operate today, how we handle your data, and what is still in preparation. We distinguish implemented controls from planned ones, and we do not claim certifications we do not hold.
We do not currently hold SOC 2, ISO 27001, HIPAA, FERPA, GDPR or PDPA certification, and we do not claim full compliance with any framework. We operate PDPA-ready controls (detailed below) and can support your own security and procurement review. Where a control is planned rather than implemented, we say so.
Implemented today across the managed platform.
TLS in transit; encryption at rest with managed keys for databases, file storage and backups.
MFA for portal access, role-based access enforced server-side, and least-privilege operational access.
Administrative and AI actions are logged; governance actions (spend, redaction, approvals) are recorded for review.
Encrypted backups run daily, and automated restore drills run weekly to verify they actually restore — not just that they were taken. Recovery objectives are set per plan and deployment.
Databases and caches are not publicly exposed; public access is fronted by CDN, WAF and a load balancer.
HTTPS-only with HSTS, a Content-Security-Policy and strict security headers, and an AWS-managed WAF (managed rule sets, IP-reputation and per-IP rate limiting) at the CDN edge.
Your data can be exported; on deprovisioning it is deleted per the agreed retention and deletion process.
Region selection is available for dedicated enterprise deployments; the default processing region is Asia-Pacific.
We use AWS as the primary infrastructure and AI (Amazon Bedrock) subprocessor; a full subprocessor list is available on request.
A defined process to assess and notify affected customers of qualifying security incidents; formal SLA per contract.
The AI assistant is designed to answer from approved learning content, provide citations, and refuse when sufficient supporting information is unavailable. Every AI action runs through a governance gateway with per-tenant spend caps, an audit trail, best-effort PII redaction, in-region processing on Amazon Bedrock, and human review on anything that changes a grade or a course. See the AI Suite
We publish these as they complete legal review. Until then, current drafts are available to prospective customers on request — we do not present unreviewed drafts as binding policy.
Legal review in progress
Available to prospective customers on request.
Legal review in progress
Available on request.
Available on request
Provided for signature as part of enterprise engagements.
Available on request
Current infrastructure and AI subprocessors.
Legal review in progress
Governs platform and AI usage.
Process in preparation
Report suspected issues via the security contact below.
A public status page is in preparation. In the meantime, report a suspected outage or incident and we will respond.
For security questions, disclosures or a procurement review, contact us and we will route it to the right team.
Contact our team