Governed by design

Security enforced below the interface.

Application checks matter, but they are not the final boundary. DEEP also constrains the database roles, records and processing paths that sit underneath the product.

01

Workspace isolation

Database row-level controls apply workspace and membership claims to protected records. Runtime credentials are restricted and do not own the tenant tables.

02

Private work boundaries

Teacher and department records retain their visibility and ownership scope. A valid school membership alone does not grant access to every personal record.

03

Controlled AI processing

Provider processing remains unavailable until the relevant governance profile, processor decision and data region are recorded.

04

Evidence lifecycle

Retention, restriction, legal hold and approved erasure are explicit controller decisions with recorded proof. Expired evidence becomes a limited capsule rather than silently surviving.

05

Traceable decisions

Audit findings, citations, generated responses and progress reviews retain safe lineage without placing raw prompts, hashes or internal identifiers in the user interface.

Compliance boundary

The system does not invent legal approval.

DEEP provides controls and records that support a data controller. It does not declare that a school is compliant with GDPR, US state law, Australian privacy law or UAE requirements without the controller's own approved profile and applicable review.

Jurisdiction, processor approval, retention purpose and authorised roles must be configured deliberately. When they are missing, processing fails closed and names what must be resolved.

Review the data-control process