Security & Privacy First

Your data, your control. We built Academic Workflow Suite with privacy and security as core principles.

Our Privacy Guarantees

100% Local Processing

All student data processing happens on your local machine. No information is sent to external servers without your explicit consent.

Encrypted Storage

All data at rest is encrypted using AES-256 encryption with your personal passphrase. Only you have access to your data.

Complete Audit Trail

Every action is logged with tamper-proof audit trails. Full transparency into who accessed what data and when.

Zero Telemetry

We don't collect usage analytics, crash reports, or any telemetry without your explicit opt-in consent. Your usage patterns stay private.

Open Source

Complete source code transparency. Security experts and the community can audit our code at any time. No hidden backdoors.

Offline Capable

All core features work completely offline. No internet connection required means no data can leak over the network.

AI Isolation Technology

Our unique AI isolation system provides an additional layer of privacy protection when using AI-assisted feedback generation.

1

Anonymization

Student names, IDs, and other PII are automatically stripped from submissions before AI processing.

2

Sandboxed Processing

AI model runs in an isolated environment with no network access or disk write permissions.

3

Re-identification

Generated feedback is safely re-associated with student information after processing.

Isolation Modes

Standard Mode

Local AI processing with basic privacy protections. Suitable for most use cases.

Manual Mode

AI disabled. All feedback written manually. Maximum privacy and control.

GDPR & Compliance

Academic Workflow Suite is designed to help educational institutions meet their data protection obligations under GDPR and other privacy regulations.

GDPR Compliance Features

Data Minimization

Only essential data is collected and processed. No excessive data gathering.

Right to Access

Export all data in standard formats (JSON, CSV) for data subject access requests.

Right to Erasure

Securely delete student data with cryptographic wiping. Unrecoverable deletion.

Data Portability

Export data in machine-readable formats for transfer to other systems.

Processing Records

Comprehensive audit logs documenting all data processing activities.

Privacy by Design

Privacy and security built into the architecture from day one.

Need a Data Processing Agreement?

Since all processing happens locally on your machine, Academic Workflow Suite acts as your tool, not a data processor. However, we can provide documentation to help with your institution's compliance requirements. Contact us for assistance.

University Approval Process

Getting approval from your institution's IT security or data protection office? Here's what they need to know.

Security Documentation Package

We provide comprehensive documentation for institutional review:

  • Architecture Overview: Technical documentation of system architecture, data flows, and security controls.
  • Security Assessment: Independent third-party security audit reports and penetration testing results.
  • Privacy Impact Assessment: Detailed DPIA template pre-filled for Academic Workflow Suite.
  • Compliance Mapping: How AWS meets GDPR, FERPA, COPPA, and other relevant regulations.
  • Source Code Access: Full source code available for security review via GitHub.

Common Questions from IT Security

Does it store student data in the cloud?

No. All student data is stored locally on the educator's machine with AES-256 encryption. Optional cloud sync (for backup) uses end-to-end encryption.

What network connections does it make?

Only when explicitly configured: (1) LMS API connections for import/export, (2) Optional cloud sync for backups, (3) Optional software update checks. All connections use TLS 1.3.

Can we deploy it on managed devices?

Yes. We provide enterprise installers (MSI, PKG, DEB, RPM) that support silent installation, centralized configuration, and IT management tools.

How are security updates handled?

Automatic security updates can be enabled (opt-in). For managed environments, updates can be controlled through your standard software deployment pipeline.

What about AI model security?

AI models run locally with no internet access. They cannot exfiltrate data. Models are cryptographically signed and verified on installation.

Need Help with Institutional Approval?

We're happy to provide additional documentation, answer technical questions from your IT team, or participate in security reviews.

Contact Us

Trust & Transparency

Open Source

Complete source code available on GitHub under MIT license.

View Source

Security Audits

Regular third-party security assessments and penetration testing.

Latest Report

Bug Bounty

Responsible disclosure program with rewards for security researchers.

Report Vulnerability

Community Reviewed

Thousands of developers and security experts review our code.

Security Policy

Universities Using Academic Workflow Suite

Trusted by IT security teams at leading institutions worldwide:

Security Best Practices

Recommendations for using Academic Workflow Suite securely:

Use Strong Passphrases

  • Minimum 16 characters
  • Use a password manager
  • Don't reuse passphrases
  • Enable two-factor authentication for cloud sync

Regular Backups

  • Enable automated backup to encrypted cloud storage
  • Test restoration periodically
  • Keep backups for data retention compliance
  • Use aws backup create command

Software Updates

  • Enable automatic security updates
  • Review changelog before major updates
  • Keep operating system up to date
  • Monitor security advisories

Access Control

  • Use OS-level user accounts for multi-user systems
  • Lock your computer when away
  • Don't share your encryption passphrase
  • Enable disk encryption on your device

Report Security Issues

Found a security vulnerability? We take security seriously and appreciate responsible disclosure.

Responsible Disclosure Process

  1. Email security details to security@academic-workflow.org
  2. Do not disclose publicly until we've issued a fix
  3. We'll acknowledge your report within 48 hours
  4. We'll provide updates on fix progress
  5. We'll credit you in our security advisory (if desired)

PGP Key: Download our PGP public key for encrypted communication.

Qualifying vulnerabilities may be eligible for rewards through our bug bounty program. See our security policy for details.