How it worksProvenanceSecurityPricingAboutSign inBook a walkthrough

Security and your data

Your documents build your academy. They don't train anyone's AI.

The first question a serious buyer asks about AI is where their data goes and whether it could leak or be trained on. That question deserves a documented answer, not reassurance. Here is ours, including the parts we do not yet claim.

Data residency

Where your data stays, and the little that ever leaves.

Personal data has one home. Only two things ever cross a border, and neither of them is your personal data.

Stays in the EUFrankfurt

All personal data

  • Your learners and their records
  • Your client and account data
  • Your finished course content
  • Hosted in Frankfurt (eu-central-1), under GDPR-grade protection
  • Row-level isolation to your tenant, continuously audited
Crosses to the USOnly two

Metadata and licensed content

  • Request metadata for serving the site (no personal data store)
  • Course scripts and narration, sent to the licensed AI and media services that render video and audio
  • Web research runs through a ring-fenced service, never touching confidential source material
  • Never the learner or client personal-data store

A deliberately small footprint: no payment processor, no analytics, no advertising or tracking pixels, no third-party CDN. Fewer places for data to be is the strongest control there is.

The controls

Six answers to the two real questions.

Buyers worry about two distinct things: that AI will be trained on their content, and that their content could leak. They are different problems, and they get different answers.

No training

Never used to train a model

Production runs on enterprise AI, not the consumer tools that learn from what people type. The strictest no-training terms are activated before any confidential material is uploaded. Your content builds your academy and nothing else.

Isolation

Walled off, and verified

Your material and learners sit in your own tenant, enforced at the database. Isolation is continuously checked by an automated security suite, and a routine audit that found cross-tenant gaps had them closed and re-verified. Checked, not asserted.

Mediated

No open pipe to a chatbot

Every AI action runs through the platform and its validation gate. There is no raw model to converse with that could carry one client's material into another's course. The AI is an ingredient, never an exposed endpoint.

Minimised

The less we keep, the less can leak

The design goal at ingest is to keep as little of your raw source as possible: use it to produce the course, then hold your finished content rather than the confidential originals. Fewer copies, shorter-lived, is the leak answer.

Your IP

Yours to keep, and to take

You own the academy you build. Export it, in standard formats, and take it with you. Leaving does not strand your content, and we do not hold your library hostage to a renewal.

On paper

Documented, not just promised

A data-processing agreement you can sign, a named sub-processor register, and a data flow you can walk your security team through. The kind of thing a vendor risk assessment actually asks for.

Two tiers

What is live for everyone, and what a higher-assurance engagement adds.

We would rather be exact than impressive. Some controls are live today; others are real engineering we provision for an enterprise pilot, not a switch we flip.

Base · live today

Standard

  • Personal data EU-resident in Frankfurt
  • Row-level tenant isolation, continuously verified
  • Operator-side AI, no model key in the live app
  • The closed sub-processor set, no payments, analytics or tracking
  • Signable DPA and sub-processor register
Enterprise · provisioned per engagement

High assurance

  • A dedicated per-tenant database
  • EU-pinned AI processing in your cloud boundary where required
  • Self-hosted voice and avatar, so narration need not leave the boundary
  • Vendor enterprise no-training tiers activated before confidential content
  • Deeper isolation and residency options on request

The nos, first

What we do not claim.

A trustworthy security page is as clear about its limits as its strengths. So, plainly:

Not yet certified

No SOC 2 or ISO certificate

We do not hold one, and we will not imply that we do. The controls above are real and documented; a formal certification is a road we can discuss, not a badge we are wearing.

New to market

Pre-client, on standard tiers today

There are no client references because there are none yet. The video and audio services run on their standard tiers today; their enterprise no-training tiers are activated before any client-confidential material, not after.

Honest about pilots

Enterprise controls are builds, not toggles

The dedicated database, EU-pinned processing and self-hosted media are real engineering we stand up for a pilot. We would rather scope them properly with you than pretend they are a checkbox.

Not legal advice

Educational content, expertly reviewed

Courses are training, grounded in your sources and reviewed by a named expert. They are not a legal opinion, and we are clear about that in the terms.

For your security team

Walk the data flow with us, before you upload a thing.

We will take your team through the sub-processor register, the data-processing agreement and the residency picture, and answer a vendor security questionnaire directly. On a pilot, we honour deletion live.