Identity & access
Multi-factor authentication with an authenticator app, and role-based access control across the platform.
The controls IT and compliance reviewers expect, explained without an AWS deep-dive — and with claims we can actually stand behind.
Multi-factor authentication with an authenticator app, and role-based access control across the platform.
Encryption in transit and at rest with managed keys, private networking with no public database or cache, and a web application firewall at the edge.
Automated, encrypted backups with retention — and tested restore drills. High-availability and disaster-recovery options for dedicated enterprise deployments.
Per-tenant spend caps, a full audit trail, acceptable-use policy, best-effort PII redaction, and in-region processing — with human review on grade- or course-changing actions.
Application audit logging and data-residency options. We provide PDPA-ready controls and documentation.
Cost-efficient shared infrastructure for smaller programs; dedicated, isolated stacks with scoped access for enterprise and government.
Every AI action runs through a governance gateway. AI runs on Amazon Bedrock inside our AWS account — you don't manage API keys, and processing stays in-region.
Security reviewers appreciate honesty. Here's exactly where we stand today.
Need to run a security questionnaire or discuss data-processing terms? Talk to our team
We'll walk your IT and compliance reviewers through the controls, deployment isolation options and data handling — in plain language.