Privacy & data usage
Your learners are not our training data.
Marking software reads the most personal thing a learner produces. Here is exactly what Sokros does with it, what it never does — and how to check any vendor's answer, including ours.
UK-based
UK processing by default, with EU and Gulf in-region options — or fully on-premise on hardware you control.
No LLM APIs in the marking path
Proprietary models on dedicated infrastructure under Sokros control. Learner work is never sent to consumer AI services.
Not trained on your learners
Learner data does not train models — and the architecture doesn't need it to. Calibration uses dozens of scripts your assessors already marked.
Minimisation by design
The pipeline stores decisions and quoted evidence — not behavioural profiles, not browsing data, not anything marking doesn't require.
Retention on your instruction
Records are kept because audits need them — for as long as you say, deleted when you say, encrypted in transit and at rest.
Evidence, not surveillance
Integrity signals are about the work, carry their evidence, and land with a human. No automated penalty touches a learner.
The marking path, drawn honestly.
A submission enters the boundary, is read, checked, judged and recorded — and the feedback sheet comes back out. Nothing in between calls a consumer AI service, and nothing that enters becomes training material.
Proprietary models, dedicated GPU infrastructure, Sokros-controlled
Encryption in transit and at rest
Multilingual extraction inside the boundary — including Arabic
Read any grading tool's policy next to ours.
Privacy policies are public. Some grading platforms' policies describe collecting learner, tutor and third-party personal data — names, emails, dates of birth — and using data to train their models. Ours can't say that, because the architecture doesn't do it.
| What the policy says | Sokros | Typical grading-AI tools* |
|---|---|---|
| Learner work used to train models | Never | Common — often the default |
| Name, email, date of birth in training data | No | Disclosed by some policies |
| Third-party LLM APIs in the marking path | None | Frequently |
| Needs your assessment history to work | No — dozens to calibrate | Often hundreds to thousands |
| On-premise / in-region deployment | Yes — UK · EU · Gulf | Rarely offered |
| Retention and deletion on centre instruction | Yes | Varies by provider |
*Based on competitors' own published privacy policies at the time of writing — for exampleGraide's policy, which describes collecting learner, tutor and third-party personal data including name, email and date of birth, and using data to improve its models. Policies change — read the current version yourself, and hold ours to the same standard.
The data questions, answered.
01What data does Sokros hold about a learner?
The submitted work, the structured evidence extracted from it (with verbatim quotes), every marking decision with its reasoning, and the rendered feedback sheet — keyed by learner, cohort, unit, brief year and attempt. That record exists because quality assurance depends on it, and it is retrievable and deletable on centre instruction.
02Does any learner data leave our deployment boundary?
No learner data is sent to third-party model APIs anywhere in the marking path. On sovereign deployments, nothing leaves your infrastructure at all; on Sokros-operated deployments, data stays in the region you choose.
03Is our centre's data used to improve Sokros for other centres?
No. Units are isolated configuration — there are no cross-unit fallbacks, and another centre's marking never shapes yours. Behavioural changes to the engine are numbered amendments, replay-tested, never silent retraining on customer data.
04How should we compare grading tools on privacy?
Read the published privacy policy and look for three things: whether learner data trains models, which personal fields are collected and why, and whether a third-party AI service sits in the marking path. Policies state these plainly — ours does, and so do our competitors'.
Put it to your DPO.
We'll answer every data-protection question in writing — boundary diagrams, retention terms, deployment options and all.