AIReady Security and Data Privacy
Built for trust, transparency, and enterprise-grade protection.
AIReady integrates AI-powered learning experiences into your existing LMS and authoring tools while protecting your organization’s data, learners, and IP.
Why Organizations Trust AIReady
1) Your Data Stays Yours, Always
Your proprietary content is your advantage. AIReady is designed to preserve data sovereignty.
- No AI model training: Your content is used only to generate responses for your organization. AIReady does not use your documents, prompts, or conversations to train models.
- Contractual protections: Our AI providers are contractually restricted from using your data for model training.
- Purpose limitation: We process only what’s needed to fulfill the learning request, not to build datasets.
- Automatic Deletion: All AI query data is deleted from our AI provider systems within 30 days, ensuring confidentiality and minimal data retention.
2) Data Residency and Processing
We separate where data is stored from where inference is processed.
- Storage (US-only): Customer documents and platform data are stored on Amazon Web Services infrastructure in the United States.
- Inference (US by default): AI inference requests are routed to US-based enterprise-grade AI models.
- Non-US processing (by exception): We do not change processing regions unless a customer explicitly requests it and it is intentionally configured.
3) Multi-Layer Security Protection
Defense-in-depth, from your LMS to our API.
- Encryption in transit: TLS 1.2+ for all requests.
- Encryption at rest: Data encrypted using AWS KMS.
- Tenant isolation: Each organization’s data is logically isolated in our multi-tenant environment to prevent cross-client access.
4) Secure Access Controls
Practical controls that reduce real-world risk.
- Unique API keys: Required for all access to AIReady.
- Multi-domain allow-listing: Restrict requests to approved domains (LMS, staging, review tools). Requests from unapproved origins are blocked to reduce key misuse.
Technical Controls and Transparency
Logging and Retention
- Minimal by default: We retain only what’s required for operations and billing by default.
- Configurable audit posture: Additional logs can be enabled for analytics and troubleshooting upon request.
Learner Privacy and PII
- PII-minimizing by design: AIReady does not require personally identifiable information to function.
- Pseudonymous identifiers supported: If you need learner tracking, we recommend pseudonymous IDs rather than names or emails.
- Focus on the learning query: We optimize for instructional relevance, not learner identity.
Ready to move forward?
Have more questions?
Reach out to our security team to schedule a call or ask specific technical questions.
Need a Summary?
Download our one-page security overview to share with your internal stakeholders.