Skip to main content

Trust

Exam Security Without Surveillance: Aiseptor's Privacy Architecture

Aiseptor is designed around one rule: collect the minimum signal required to verify an assessment's integrity, nothing more. No webcam. No microphone. No keystrokes. No file contents. Session metadata only: network access requests and device activity signals.

Data collected during a session

Network access request records, a rotated session identifier, and device security signals (denylisted process names, GPU utilization delta, AI model file presence). No webcam, microphone, keystrokes, screen recording, or file contents, ever. The full signal list is below.

Retention schedule

No footage is captured, so there is none to retain. Post-exam records default to 90 days and are configurable from 7 to 365 days by the administering institution. Longer windows are available under a signed DPA. Server logs are IP-truncated and kept 30 days.

GDPR & CCPA/CPRA

Legal basis for processing, data subject rights (access, deletion, correction, portability), and the CCPA "right to know" and opt-out disclosures are documented in full, not summarized as a badge.

Privacy Policy §8

Subprocessors

Every third party involved in delivering Aiseptor, what each one does, the data category it touches, and the region it runs in. Published in full, including the parts we are still working on.

Full subprocessor list

Data processing agreements

Institutional customers requiring a signed DPA can request one directly. We notify customers before a new subprocessor begins handling their data.

Terms of Service

Every signal the agent collects

Collection begins when the candidate joins and ends when the session closes. No persistent agent remains on the device afterwards.

Network-layer telemetry

  • Network access request records and timestamps (no payload contents)
  • Session cryptographic identifier, rotated each exam
  • Assigned ephemeral VPN IP address
  • Outbound destinations falling outside the exam whitelist

Device security signals

  • Running process names checked against a known-AI-tool denylist (the full process list is never transmitted)
  • GPU VRAM utilization delta, to detect on-device LLM inference (raw readings are not stored)
  • Presence of known AI model file extensions at standard install paths
  • Access policy and network configuration integrity status

What is never collected

  • Webcam or microphone streams
  • Screen recordings or screenshots
  • Keystrokes or clipboard content
  • Browser history outside the exam session
  • Personal files, documents, or application data

Aiseptor processes candidate exam data as a processor on the instructions of the administering institution, which is the controller and sets retention.

How enforcement actually works

The full path, from the candidate device to the destinations they can and cannot reach, and exactly which signals cross the boundary between them.

Aiseptor enforcement pathA candidate device runs a user-space agent which opens a per-session WireGuard tunnel to an Aiseptor gateway. The gateway applies a default-deny policy using DNS resolution, SNI inspection and nftables. Assessment-approved destinations are reachable; AI APIs, remote-access services and unauthorised cloud storage are blocked. Only network access requests and device integrity signals cross the trust boundary, never webcam, microphone, keystrokes, screen contents or files.CANDIDATE DEVICEUnmanaged laptopAiseptor agent, user-spaceNo kernel driverNo persistent installRemoves itself at session endWireGuardper sessionTRUST BOUNDARYAISEPTOR GATEWAYDefault denyDNS resolver, allow-listSNI inspectionnftables peer isolationPer-request decision logALLOWEDAssessment platform, approved toolsExplicitly whitelisted per examBLOCKEDAI APIs, remote access, cloud storageEverything not on the allow-list,whatever the process is namedWHAT CROSSES THE BOUNDARYSentNetwork access requests, rotated session IDDenylisted process names, GPU VRAM deltaAI model file presence at standard pathsNever sentWebcam, microphoneKeystrokes, clipboard, screen contentsFiles, browsing outside the sessionOUTPUTSigned per-session integrity reportYour platform decides what a flag means

Security controls

Encryption

Candidate traffic runs inside a per-session WireGuard tunnel. Dashboard and API traffic is TLS-only, with HSTS preloaded. Data at rest is encrypted with AES-256 by the managed infrastructure services we run on, using provider-managed keys.

Access control

Single sign-on via Google (OIDC), plus role-based access control with distinct admin and proctor roles scoped to your organisation. SAML and Microsoft Entra sign-in are not yet available; we will list them here when they ship, not before.

Incident response

If we become aware of a personal-data breach affecting your candidates, we notify the administering institution within 72 hours, aligned with GDPR Article 33. Notification includes what happened, which data categories were involved, and what we are doing about it.

Vulnerability disclosure

A public bug bounty with three in-scope classes: network escape, device-side bypass, and signal spoofing. We commit to a 90-day disclosure window and do not require a gag clause.

Bug bounty program

Not yet available

SOC 2 Type II attestation is in progress, targeted for Q3 2026. SAML and Microsoft Entra sign-in are not yet available. We'd rather leave this section short than link to something that doesn't exist yet.

We use essential cookies to run this site and, with your consent, first-party analytics cookies to understand how it's used. We don't use advertising or third-party tracking cookies. Read our cookie policy