Security & compliance

The data is yours. So is the decision.

Written plainly, because a security page that needs interpreting is a security page hiding something. Where we have not certified yet, this says so.

The part most vendors bury

Four things this product will never do

These are architectural, not policy. There is no configuration flag that turns them on, because the product's value depends on students trusting it enough to say what they actually think.

Never built

Proctoring

No webcam monitoring, no screen capture, no eye tracking. Surveillance produces compliance, not understanding.

Never built

AI-detection scoring

Detectors are unreliable and disproportionately accuse second-language writers. We will not ship a number that ends someone's degree.

Never built

Automated decisions

Orin does not grade, does not flag a student to administration, and never has the last word. Every judgement is a human's.

Never built

Training on your learners

Your data never trains a model that serves anyone else, and there is no shared model between tenants.

How it is built and run

Data residency and tenancy

Region is selectable at contract, and data does not leave it. Single tenancy is available where a regulator or a board requires it.

Self-hosting on your own infrastructure is supported — the product is built on Frappe, so this is a normal deployment rather than a special case.

Access and identity

SSO through your identity provider — SAML or OIDC — with role-based access mapped to your existing groups. MFA is enforced for staff roles.

Encryption in transit and at rest. Audit logs cover every access to a learner record, exportable.

Safeguarding, in Class

Age-appropriate limits are on by default, not opt-in. Staff-pupil communication is logged, and a designated safeguarding lead has a dedicated view.

Orin's behaviour with under-18s is narrower by design and cannot be widened by a teacher.

Accessibility

WCAG 2.2 AA throughout, keyboard-complete, and the operating system's reduced-motion setting is honoured without the user configuring anything.

Colour is never the only signal, and no text in the product falls below 13px.

Certification status

Stated honestly, including what is in progress

A vendor claiming every certificate on a marketing page is a vendor you will catch out in due diligence. Current status, and our security lead will confirm any of it in writing.

GDPR & DPA

Data processing agreement available, sub-processors listed, DPIA support provided.

ISO 27001

In progress. Controls implemented; audit scheduled. Ask us for the current stage.

SOC 2 Type II

In progress. Observation window under way — we will not claim it before the report.

Penetration testing

Annual third-party test. Summary letter shared under NDA.

Send us your questionnaire

Our security lead answers it directly rather than pointing you at a PDF and hoping. Attach it to an enquiry and it goes straight there.

Enquire now