Menu
play_circleHow it works
query_statsCase studies
paymentsPricing
shieldPrivacy
helpFAQ
playlist_addJoin the waitlistSign in
GradeLogic™
How it worksCase studiesPricingPrivacyFAQ
Sign inplaylist_addJoin the waitlist

Security Overview

Draft — not currently in effect · Effective date: TBD

How GradeLogic™ protects data. Our strongest control is architectural: most sensitive data never leaves your browser in the first place.

On this page

  1. Local-first by design
  2. Encryption
  3. Authentication & access
  4. Backend & data handling
  5. Current maturity
  6. Reporting a vulnerability

Local-first by design

Rosters, student identities, original exam files, identity mappings, and accepted results are stored in your browser (IndexedDB) and are not intentionally included in cloud payloads. Before a cloud run, the client builds the payload from the instructor-reviewed redaction manifest. The server verifies the attestation and records the submitted payload fingerprint, but cannot independently prove that every identity or item of PII was detected and removed.

Encryption

All network traffic to GradeLogic™ and its subprocessors is encrypted in transit over HTTPS (TLS). Local data is held in your browser's storage and protected by your device and operating system.

Authentication & access

Sign-in uses Google OAuth; we never see your Google password. There are no user-managed AI API keys — model routing and credentials are handled server-side. A session lasts 30 days; signing out deletes it immediately, and deleting your account signs you out everywhere. See our Cookie Policy for the cookies involved.

Credentials being server-side does not mean the processing posture is out of your hands. Which credential serves your account — and with it whether processing is restricted to EEA providers and whether those providers may retain your content — follows an account setting under Settings › AI Configuration, subject to the limits described in our Privacy Policy. The setting is resolved on the server on every request and cannot be overridden by anything the browser sends.

Backend & data handling

Paid AI operations run on a managed cloud backend. Instructor-approved, client-redacted artifacts are held only for the single AI run you authorized and are deleted once the result is returned. The result itself is retained for approximately seven days so that a repeated request replays it instead of re-running and re-charging it, and is then deleted. We do not maintain a permanent repository of assessment content. Logs capture only content-free operational metadata (operationId, operation type, timing, status), never assessment content. Subprocessors are listed on our Subprocessor List.

Current maturity

GradeLogic™ is an early-stage product. We do not yet hold formal certifications such as SOC 2, and have not commissioned an independent penetration test. This page describes the controls that are in place today; we will update it as our security program matures rather than imply assurances we have not earned.

Reporting a vulnerability

Found a security issue? Please follow our Vulnerability Disclosure Policy or email security@gradelogic.ai.

GradeLogic™

AI exam grading, with student names kept in your browser.

playlist_addJoin the waitlist

  • How it works
  • Case studies
  • Pricing
  • Privacy
  • Join the waitlist

  • FAQ
  • Changelog

  • Trust Center
  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • Other Policies
  • Cancel contracts here

© 2026 GradeLogic™. All rights reserved.

Privacy Policy|Terms of Service|Cookie Policy|Trademarks|FAQ|