Skip to main content
← AristAI Accessibility Suite

Trust

Trust & Security

You are handing us course files, scanned documents, and sometimes student work. This page describes how that content is protected, who can reach it, and what happens to it afterwards.

Last updated August 10, 2026

Where your content lives

The Suite runs on Amazon Web Services. Files are stored in object storage, job records in a managed database, and encryption keys in a managed key service. Traffic is encrypted in transit with TLS, and content is encrypted at rest. Upload and download links are short-lived and scoped to a single file.

Who can reach it

  • Every job is bound to the account that created it and to that account’s institution. One institution cannot read another’s files or reports.
  • Administrators see usage and job records for their own institution, and can manage roles and quota. Seeing a record is not the same as opening a file.
  • Access to production data by our staff is limited to the people who operate the service, and is used for support and incident response — not for reading customer content.
  • LMS and storage connections use the permissions you grant at connection time, and stop working the moment you disconnect them.

What the AI touches

Some steps — OCR, captioning, transcription, alternative-text drafting, the voice agent — run through speech and language model providers. Content is sent for the duration of that job and for no other purpose. It is not used to train general-purpose models. If your institution needs a job pipeline that excludes a particular provider, tell us before you sign and we will tell you honestly what is and is not possible.

Retention and deletion

Files and reports stay available while you keep them, so you can re-download a remediated file or produce the record for an auditor later. Delete a job and it leaves the active service; backups age out on their normal cycle. Close an account and its content is deleted, apart from the minimum billing and job-count records we are required to keep. Institutions can agree a specific retention window with us in writing.

Student records

Where we process records covered by FERPA, we act under the institution’s direction as a school official with a legitimate educational interest, and we use the content only to perform the service. Ask us for a data protection addendum and we will provide one.

Availability and incidents

Jobs are queued and retried, so a failed worker does not lose your file. We monitor the service and investigate anomalies. If an incident affects your content, we will tell the affected institution what happened, what we know, and what we are doing about it, without waiting for a full post-mortem to be finished.

The product is itself accessible

It would be a poor advertisement if the accessibility tool were not accessible. The app is built to WCAG 2.2 AA: keyboard reachable, screen-reader labelled, visible focus, reduced motion honoured, and contrast checked against the same rules we check your content against. If you find a barrier in our own interface, report it to support and we will treat it as a defect, not a feature request.

Before you sign

Procurement usually wants the current list of sub-processors, a data protection addendum, an accessibility conformance report for the app itself, and a security questionnaire answered by a person rather than a form. Ask support@aristai.io and we will send what we have.

Questions about this page? Write to support@aristai.io.