Security & Privacy First
Your data, your control. We built Academic Workflow Suite with privacy and security as core principles.
Our Privacy Guarantees
100% Local Processing
All student data processing happens on your local machine. No information is sent to external servers without your explicit consent.
Encrypted Storage
All data at rest is encrypted using AES-256 encryption with your personal passphrase. Only you have access to your data.
Complete Audit Trail
Every action is logged with tamper-proof audit trails. Full transparency into who accessed what data and when.
Zero Telemetry
We don't collect usage analytics, crash reports, or any telemetry without your explicit opt-in consent. Your usage patterns stay private.
Open Source
Complete source code transparency. Security experts and the community can audit our code at any time. No hidden backdoors.
Offline Capable
All core features work completely offline. No internet connection required means no data can leak over the network.
AI Isolation Technology
Our unique AI isolation system provides an additional layer of privacy protection when using AI-assisted feedback generation.
Anonymization
Student names, IDs, and other PII are automatically stripped from submissions before AI processing.
Sandboxed Processing
AI model runs in an isolated environment with no network access or disk write permissions.
Re-identification
Generated feedback is safely re-associated with student information after processing.
Isolation Modes
Standard Mode
Local AI processing with basic privacy protections. Suitable for most use cases.
Isolation Mode
Full PII stripping and sandboxed AI processing. Best for sensitive assignments.
Manual Mode
AI disabled. All feedback written manually. Maximum privacy and control.
GDPR & Compliance
Academic Workflow Suite is designed to help educational institutions meet their data protection obligations under GDPR and other privacy regulations.
GDPR Compliance Features
Data Minimization
Only essential data is collected and processed. No excessive data gathering.
Right to Access
Export all data in standard formats (JSON, CSV) for data subject access requests.
Right to Erasure
Securely delete student data with cryptographic wiping. Unrecoverable deletion.
Data Portability
Export data in machine-readable formats for transfer to other systems.
Processing Records
Comprehensive audit logs documenting all data processing activities.
Privacy by Design
Privacy and security built into the architecture from day one.
Need a Data Processing Agreement?
Since all processing happens locally on your machine, Academic Workflow Suite acts as your tool, not a data processor. However, we can provide documentation to help with your institution's compliance requirements. Contact us for assistance.
University Approval Process
Getting approval from your institution's IT security or data protection office? Here's what they need to know.
Security Documentation Package
We provide comprehensive documentation for institutional review:
- Architecture Overview: Technical documentation of system architecture, data flows, and security controls.
- Security Assessment: Independent third-party security audit reports and penetration testing results.
- Privacy Impact Assessment: Detailed DPIA template pre-filled for Academic Workflow Suite.
- Compliance Mapping: How AWS meets GDPR, FERPA, COPPA, and other relevant regulations.
- Source Code Access: Full source code available for security review via GitHub.
Common Questions from IT Security
Does it store student data in the cloud?
No. All student data is stored locally on the educator's machine with AES-256 encryption. Optional cloud sync (for backup) uses end-to-end encryption.
What network connections does it make?
Only when explicitly configured: (1) LMS API connections for import/export, (2) Optional cloud sync for backups, (3) Optional software update checks. All connections use TLS 1.3.
Can we deploy it on managed devices?
Yes. We provide enterprise installers (MSI, PKG, DEB, RPM) that support silent installation, centralized configuration, and IT management tools.
How are security updates handled?
Automatic security updates can be enabled (opt-in). For managed environments, updates can be controlled through your standard software deployment pipeline.
What about AI model security?
AI models run locally with no internet access. They cannot exfiltrate data. Models are cryptographically signed and verified on installation.
Need Help with Institutional Approval?
We're happy to provide additional documentation, answer technical questions from your IT team, or participate in security reviews.
Contact UsTrust & Transparency
Bug Bounty
Responsible disclosure program with rewards for security researchers.
Report VulnerabilityUniversities Using Academic Workflow Suite
Trusted by IT security teams at leading institutions worldwide:
Security Best Practices
Recommendations for using Academic Workflow Suite securely:
Use Strong Passphrases
- Minimum 16 characters
- Use a password manager
- Don't reuse passphrases
- Enable two-factor authentication for cloud sync
Regular Backups
- Enable automated backup to encrypted cloud storage
- Test restoration periodically
- Keep backups for data retention compliance
- Use
aws backup createcommand
Software Updates
- Enable automatic security updates
- Review changelog before major updates
- Keep operating system up to date
- Monitor security advisories
Access Control
- Use OS-level user accounts for multi-user systems
- Lock your computer when away
- Don't share your encryption passphrase
- Enable disk encryption on your device
Report Security Issues
Found a security vulnerability? We take security seriously and appreciate responsible disclosure.
Responsible Disclosure Process
- Email security details to security@academic-workflow.org
- Do not disclose publicly until we've issued a fix
- We'll acknowledge your report within 48 hours
- We'll provide updates on fix progress
- We'll credit you in our security advisory (if desired)
PGP Key: Download our PGP public key for encrypted communication.
Qualifying vulnerabilities may be eligible for rewards through our bug bounty program. See our security policy for details.