Trust Center

Security, privacy and governance you can actually review.

This page explains the controls we operate today, how we handle your data, and what is still in preparation. We distinguish implemented controls from planned ones, and we do not claim certifications we do not hold.

Where we stand on certification

We do not currently hold SOC 2, ISO 27001, HIPAA, FERPA, GDPR or PDPA certification, and we do not claim full compliance with any framework. We operate PDPA-ready controls (detailed below) and can support your own security and procurement review. Where a control is planned rather than implemented, we say so.

Data handling

The controls we operate

Implemented today across the managed platform.

Encryption

TLS in transit; encryption at rest with managed keys for databases, file storage and backups.

Access control

MFA for portal access, role-based access enforced server-side, and least-privilege operational access.

Audit logging

Administrative and AI actions are logged; governance actions (spend, redaction, approvals) are recorded for review.

Backups & restore

Encrypted backups run daily, and automated restore drills run weekly to verify they actually restore — not just that they were taken. Recovery objectives are set per plan and deployment.

Private networking

Databases and caches are not publicly exposed; public access is fronted by CDN, WAF and a load balancer.

Secure edge & transport

HTTPS-only with HSTS, a Content-Security-Policy and strict security headers, and an AWS-managed WAF (managed rule sets, IP-reputation and per-IP rate limiting) at the CDN edge.

Data export & deletion

Your data can be exported; on deprovisioning it is deleted per the agreed retention and deletion process.

Data residency options

Region selection is available for dedicated enterprise deployments; the default processing region is Asia-Pacific.

Subprocessor transparency

We use AWS as the primary infrastructure and AI (Amazon Bedrock) subprocessor; a full subprocessor list is available on request.

Incident notification

A defined process to assess and notify affected customers of qualifying security incidents; formal SLA per contract.

AI governance

How the AI is governed

The AI assistant is designed to answer from approved learning content, provide citations, and refuse when sufficient supporting information is unavailable. Every AI action runs through a governance gateway with per-tenant spend caps, an audit trail, best-effort PII redaction, in-region processing on Amazon Bedrock, and human review on anything that changes a grade or a course. See the AI Suite

Legal & policies

Policies & documents

We publish these as they complete legal review. Until then, current drafts are available to prospective customers on request — we do not present unreviewed drafts as binding policy.

Privacy Policy

Legal review in progress

Available to prospective customers on request.

Terms of Service

Legal review in progress

Available on request.

Data Processing Agreement

Available on request

Provided for signature as part of enterprise engagements.

Subprocessor list

Available on request

Current infrastructure and AI subprocessors.

Acceptable Use & AI Acceptable Use

Legal review in progress

Governs platform and AI usage.

Vulnerability disclosure

Process in preparation

Report suspected issues via the security contact below.

Service status

Status & incident reporting

A public status page is in preparation. In the meantime, report a suspected outage or incident and we will respond.

Security contact

For security questions, disclosures or a procurement review, contact us and we will route it to the right team.

Contact our team