Workspace isolation
Database row-level controls apply workspace and membership claims to protected records. Runtime credentials are restricted and do not own the tenant tables.
Governed by design
Application checks matter, but they are not the final boundary. DEEP also constrains the database roles, records and processing paths that sit underneath the product.
Database row-level controls apply workspace and membership claims to protected records. Runtime credentials are restricted and do not own the tenant tables.
Teacher and department records retain their visibility and ownership scope. A valid school membership alone does not grant access to every personal record.
Provider processing remains unavailable until the relevant governance profile, processor decision and data region are recorded.
Retention, restriction, legal hold and approved erasure are explicit controller decisions with recorded proof. Expired evidence becomes a limited capsule rather than silently surviving.
Audit findings, citations, generated responses and progress reviews retain safe lineage without placing raw prompts, hashes or internal identifiers in the user interface.
Compliance boundary
DEEP provides controls and records that support a data controller. It does not declare that a school is compliant with GDPR, US state law, Australian privacy law or UAE requirements without the controller's own approved profile and applicable review.
Jurisdiction, processor approval, retention purpose and authorised roles must be configured deliberately. When they are missing, processing fails closed and names what must be resolved.
Review the data-control process