Security Overview
How GradeLogic™ protects data. Our strongest control is architectural: most sensitive data never leaves your browser in the first place.
Local-first by design
Rosters, student identities, original exam files, identity mappings, and accepted results are stored only in your browser (IndexedDB). They are not transmitted to GradeLogic™. The cloud pipeline receives only redacted, identity-free assessment content that you explicitly approve.
Encryption
All network traffic to GradeLogic™ and its subprocessors is encrypted in transit over HTTPS (TLS). Local data is held in your browser's storage and protected by your device and operating system.
Authentication & access
Sign-in uses Google OAuth; we never see your Google password. There are no user-managed AI API keys — model routing and credentials are handled server-side. Sessions are short-lived.
Backend & data handling
Paid AI operations run on a managed cloud backend. Approved redacted artifacts are held only for the single AI run you authorized and are deleted once the result is returned; we do not maintain a permanent repository of assessment content. Logs capture only content-free operational metadata (operationId, operation type, timing, status), never assessment content. Subprocessors are listed on our Subprocessor List.
Current maturity
GradeLogic™ is an early-stage product. We do not yet hold formal certifications such as SOC 2, and have not commissioned an independent penetration test. This page describes the controls that are in place today; we will update it as our security program matures rather than imply assurances we have not earned.
Reporting a vulnerability
Found a security issue? Please follow our Vulnerability Disclosure Policy or email security@gradelogic.ai.