Our approach
We design Erudite around practical safeguards appropriate to an early-stage, cloud-hosted authoring platform. We limit the information collected by public forms, separate public and non-public product areas, validate requests at service boundaries, and restrict access to workspace and administrative functions.
We do not currently claim SOC 2, ISO 27001, HIPAA, FedRAMP, or similar certification on this page. If your pilot requires a particular control or contract, raise it during scoping so we can confirm fit before sensitive content is provided.
Data in the product
- Account and workspace data: used to authenticate users, organize content, manage access, and support collaboration.
- Source and course content: processed to provide authoring, generation, narration, media, localization, review, and export features you use.
- Pilot requests: limited to name, company, business email, request source, status, and timestamps, with network information used temporarily to rate limit abuse.
- Diagnostics and analytics: used to understand reliability, secure the service, and improve product and website performance.
Protective measures
- HTTPS for connections to the hosted service.
- Authentication and authorization checks around non-public product areas.
- Input validation, request-size limits, origin checks, and throttling on public intake.
- Secrets kept in server-side environment configuration rather than public client code.
- Operational logging and error handling used to investigate service failures and abuse.
No internet service can guarantee absolute security. We review safeguards as the product changes and prioritize remediation based on risk.
AI and infrastructure providers
Erudite relies on cloud and specialist providers for hosting, databases, storage, analytics, and selected AI capabilities. A prompt, uploaded source, script, or media asset may be sent to the provider needed to perform the feature you choose. Provider availability and data handling can vary by feature and pilot configuration.
We can review proposed content types and enabled AI features with pilot customers so sensitive information is not sent to a service that the customer has not approved.
Your role
Customers should use unique credentials, limit workspace access to authorized people, review collaborators and shared links, and avoid uploading regulated or unusually sensitive information unless the use has been approved. Exported packages and files are governed by the security controls of the systems where customers place them.
Incidents and security questions
We investigate suspected security events, work to contain and remediate confirmed issues, and notify affected customers when required by law or contract. Security questions, suspected vulnerabilities, and data-handling requirements can be raised through the pilot form on the homepage or the support channel provided to your organization. Please do not include exploit details in a public form.