Security

How we protect your knowledge and your learners

What we protect, and why

A tutor is built from a creator’s own knowledge, and a learner’s progress through it is personal: how fast they’re moving, what they got wrong, what a tutor privately noted about their performance. We designed the platform around protecting both from day one, not bolting it on after.

Encryption at rest

Sensitive content is encrypted at rest: the materials a creator uploads, generated lesson content, a learner’s quiz answers, a tutor’s written feedback on a learner’s performance, and stored third-party credentials like a Google Drive connection. It uses authenticated symmetric encryption and is decrypted only at the moment it’s read. A database-level compromise alone doesn’t expose that content in readable form.

Grounded answers, not guesses

Every tutor answers from the creator’s own materials first, retrieved by meaning rather than keyword match, so a learner gets an answer traceable to what the creator provided instead of the underlying model’s general knowledge alone. That’s also what keeps a tutor’s answers reviewable: a creator can tell what their tutor is drawing on.

Workspace isolation

A workspace’s materials, tutors, and learner data are scoped to that workspace and the members you’ve explicitly added, each with an owner, admin, or editor role. A tutor’s knowledge only folds into the workspace it belongs to. Nothing crosses between organizations, and nothing is shared across customers by default.

Account protection

Sign-in is a one-time emailed code or an OAuth provider, so we don’t store passwords to leak. An OAuth sign-in is only accepted once the provider confirms the email is verified, and sign-in attempts are rate-limited per account and per address to curb automated abuse.

Infrastructure

The application, database, and file storage run on managed infrastructure with the database and generated media kept separate from the application layer, so a compromise of one doesn’t hand over the other. Generated media (a tutor’s avatar, voice, or in-lesson images) is served through short-lived, scoped links rather than a public bucket.

Abuse prevention

Sign-in, chat, and public read endpoints are all rate-limited per account and per address, so a single actor can’t flood the service or brute-force their way into someone else’s account.

Deleting your data

Deleting a tutor or an account removes its materials, generated content, and learner progress along with it. It’s not a soft flag: an actual removal, initiated by you at any time from your workspace.

For schools, districts, and enterprises

SSO and audit logs are coming to Team plans, for organizations managing tutors across a group. If you’re a school, district, or company evaluating alltutors.ai and need a data processing agreement, reach out and we’ll work through it with you. See our Privacy policy for how we handle data on an organization’s behalf.

Report a vulnerability

Found a security issue? Email us at security@alltutors.ai. We take reports seriously and will get back to you.