For your DPO, IT security and procurement

Trust pack

Where every claim about Eklipse Verifi stands, who processes data on an institution's behalf, and which documents exist for a procurement review. Nothing on this page is stronger than what a reviewer could verify.

Last reviewed . Eklipse Technologies. Questions: [email protected].

01What Verifi is, and what it is not

Verifi lets a learner explain their own coursework, spoken, typed or in a faculty-led conversation, and gives the instructor an organised, sourced summary of that explanation to read before the instructor decides what happens next. Its purpose is to make a human conversation about understanding practical at scale.

  • No software output is a mark, a verdict or a judgement about a learner. Every decision of record is a named member of faculty's, recorded with their reason, and it cannot be edited after it is recorded.
  • There is no AI-content detection, no proctoring, no biometrics and no behaviour analysis. The system does not try to work out whether a learner used AI, and records no risk of any kind.
  • Learners never see an AI signal. What a learner sees is what their instructor chose to publish.
  • The AI's suggestions to faculty are recorded with what the person did with them: accepted, edited or rejected. That record is the human-oversight record an EU AI Act deployer needs.

We treat Verifi as a high-risk use in education under the EU AI Act and design for Article 14 human oversight and Article 26 deployer duties accordingly. The instructions for use and the technical file are listed under Documents.

02Where each claim stands

Three states only. In place means a DPO could verify it today. In progress means work exists and is not finished. Planned means nothing exists yet. Certification and conformance are words for an auditor to write, not for this page.

EU AI ActIn progress
Treated as a high-risk use in education. Human oversight is by design: every decision of record is a named person's, and the AI's suggestions are recorded with what that person did with them. Exportable oversight records and the Annex IV technical file are in progress.
GDPR / UK GDPRIn progress
Data processing agreement on Article 28 terms is in preparation for pilots. The privacy notice covers what is recorded, the lawful basis, retention and learner rights.
Data residencyIn progress
Single-region hosting today; the region and every subprocessor are named in the trust pack. Customer-selectable residency is not offered yet.
DPIA supportIn progress
A DPIA input pack (processing description, data flows, retention schedule, human-oversight design) is being assembled for pilot institutions.
SubprocessorsIn progress
The list of subprocessors (hosting, media storage, transcription and question generation) is published in the trust pack and changes are notified in advance.
FERPA postureIn place
Student-consented context only; nothing is scraped from the LMS beyond the assignment being verified.
Data ownershipIn place
The institution owns its data and can export or erase it.
Model-training policyIn place
Student data is never used to train models.
Retention and deletionIn place
Per-activity recording windows, a scheduled purge, per-learner export and audited erasure. The window is an institution setting.
Audit and human controlIn place
Faculty decisions cannot be edited after they are recorded; deletion happens only through audited institutional erasure. Full provenance for every AI suggestion, and an exportable per-session oversight record.
EncryptionIn progress
In transit everywhere. At rest: requested on every media object and backup; verification of the host volume is pending, so it is stated as in progress until it is.
Accessibility conformance reportIn progress
WCAG 2.2 AA is the target; typed, audio and faculty-led paths are equal. An accessibility conformance report is being prepared.
LTI 1.3In progress
Blackboard and Canvas launch, roster (NRPS) and completion passback (AGS) are built; a round-trip inside a customer LMS is still pending.
Institutional SSO / SAMLPlanned
Not built yet. OIDC federation (Entra, Okta, Google; Shibboleth via a bridge) is the next identity milestone and replaces the closed demonstration gate before any institutional rollout. No self-service accounts.
Multi-factor authenticationPlanned
Not built yet. TOTP on the demonstration gate is scheduled ahead of federation.
SOC 2Planned
Type II audit is planned and not yet certified.

03Hosting and infrastructure

These are the third parties that may process personal data on an institution's behalf. If a party is not on this list, it does not receive personal data from the product. The list is maintained with the deployment runbook and reviewed on the date shown above.

PartyRoleDataRegionNotes
Hetzner Online GmbHVirtual machine hosting the application, the database and, in local-storage mode, mediaAll product dataGermanyOne stateful host. The database is a SQLite file on the VM disk; disk-level encryption of that volume is not yet verified (see Encryption).
Cloudflare, Inc.Tunnel and DNS in front of the application; TLS termination at the edgeRequest metadata in transitGlobal edge (EU and US points of presence)No product data is stored at Cloudflare.
Backblaze, Inc.Private object storage for raw recordings and nightly database backups (S3-compatible API)Raw audio and video recordings; database backupsSet per deployment. An EU institution is provisioned an EU bucket and the region is stated in its DPA annex.Private bucket; every object is written with server-side encryption requested; playback only through 90-second signed links issued to authenticated faculty.

04Model and speech providers

Which provider is active is a deployment decision made through configuration, and the deployment's DPA annex records the choice. Every call is written to an AI-call ledger with its purpose, provider, model and prompt version, and the per-session oversight record exports it.

PurposeProviderData sentRetention at provider
Claim mapping, question generation, evidence summaries, interview probes, question translationAnthropic, PBC (Claude API) when configured for the deployment; otherwise a built-in deterministic stand-in with no network callsSubmission text, transcripts, the assignment prompt and rubric. No learner name or email is included in any prompt.Per the provider's API data policy. The product does not opt into training and sends nothing for that purpose.
Transcription of recordingsOpenAI (speech-to-text API) when configured; otherwise the built-in stand-inRaw audio, for transcription onlyPer the provider's API data policy
The interviewer's voice (text-to-speech)Self-hosted on the same VM. ElevenLabs or Fish Audio may be enabled as an optional voice vendor for a deployment; they are off unless configured.Question text only, never learner speechNone on the host; per vendor policy if an optional vendor is enabled, and the deployment's DPA annex says so

05Not subprocessors

  • The institution's LMS (Canvas, Blackboard) is the institution's own system. Verifi is a tool the institution connects to it through LTI 1.3; nothing is read from the LMS beyond the assignment being verified and the roster the institution chooses to share.
  • Eklipse Technologies staff may access the production host for operations under named operator roles. They are the processor, not a subprocessor, and their access is logged.

06Encryption, honestly

  • In transit: TLS everywhere, terminated at the edge and carried to the host over a private tunnel.
  • Object storage: server-side encryption is requested on every recording and backup written, and is expected to be the bucket default.
  • Database and local media on the host: the runbook does not yet record an encrypted volume.

Until an operator has verified an encrypted volume under the database, the honest state for encryption at rest is In progress, and every questionnaire answer we give says so. We would rather a reviewer read that here than discover it later.

07Data residency

Single-region hosting today, in Germany, with recording storage in the bucket region recorded for the deployment. Customer-selectable residency is not offered yet. Transfers to model providers are covered by the provider's standard contractual terms and are listed in the DPA annex; an institution that requires no transfer outside its region can run the deployment on the built-in stand-in providers at the cost of question quality, and we will say so plainly rather than pretend otherwise.

08Security practices in plain terms

  • Faculty sign-in is closed by default: an access code and a participant allowlist, both supplied out of band, and no self-service accounts. Institutional SSO is planned and not built; the sign-in page says the same.
  • No passwords are collected anywhere in the product. Learners reach a verification from the LMS or a secure link, never an account.
  • Failed sign-in attempts are throttled and locked out. Only a hash of a coarse requester hint is kept; no raw address or user agent is stored.
  • The audit log is append-only at the database level: triggers refuse updates and deletes. Faculty decisions cannot be edited after they are recorded.
  • Recordings are played back only through 90-second signed links issued to authenticated faculty, and every access is logged.
  • Nightly backups are taken consistently, kept for 14 days on the host and copied off-host to private object storage.
  • The incident response procedure names an incident lead, a data-protection contact and the institution's contact, and commits to notifying an affected institution within 24 hours of an incident being confirmed, with what is not yet known stated as such.

No third-party penetration test has been commissioned yet and no SOC 2 report exists. Both are planned. A reviewer who needs either before a pilot should say so; we will not describe internal testing as if it were an external one.

09Documents for a procurement review

DocumentWhereState
Privacy notice (the learner-facing text, adoptable by the institution)/privacyPublished
Accessibility statement (self-assessment against WCAG 2.2 AA)/accessibilityPublished
Pilot terms/termsPublished
Data processing agreement on Article 28 terms, with annexes for data categories, retention, subprocessors and transfer mechanisms, and technical and organisational measuresOn request from [email protected]Template ready for counsel
Incident response procedureShared with institutions under the DPAIn place
Instructions for use (EU AI Act Art. 13) and technical documentation on Annex IV headingsOn requestIn progress
DPIA input pack: processing description, data flows, retention schedule, human-oversight designOn requestIn progress
HECVAT or an institution's own vendor questionnaireAnswered on requestNot yet published
Accessibility conformance report (VPAT or ACR)With the independent auditPlanned

10Change control

A new subprocessor is added to this page, the DPA annex and the privacy notice in the same change, before it receives any data. Institutions on a signed DPA are notified in advance under the notice period the DPA sets. The review date at the top of this page moves whenever any row changes.

11Contact

Security, privacy and procurement questions go to [email protected], the one mailbox in use today, read by a person. Put Security, Privacy or Procurement in the subject line. A responsible disclosure of a vulnerability is answered within two working days, and we will not act against anyone who reports one in good faith.