Sokros

Privacy & data usage

Your learners are not our training data.

Marking software reads the most personal thing a learner produces. Here is exactly what Sokros does with it, what it never does — and how to check any vendor's answer, including ours.

UK-based

UK processing by default, with EU and Gulf in-region options — or fully on-premise on hardware you control.

No LLM APIs in the marking path

Proprietary models on dedicated infrastructure under Sokros control. Learner work is never sent to consumer AI services.

Not trained on your learners

Learner data does not train models — and the architecture doesn't need it to. Calibration uses dozens of scripts your assessors already marked.

Minimisation by design

The pipeline stores decisions and quoted evidence — not behavioural profiles, not browsing data, not anything marking doesn't require.

Retention on your instruction

Records are kept because audits need them — for as long as you say, deleted when you say, encrypted in transit and at rest.

Evidence, not surveillance

Integrity signals are about the work, carry their evidence, and land with a human. No automated penalty touches a learner.

The marking path, drawn honestly.

A submission enters the boundary, is read, checked, judged and recorded — and the feedback sheet comes back out. Nothing in between calls a consumer AI service, and nothing that enters becomes training material.

Proprietary models, dedicated GPU infrastructure, Sokros-controlled

Encryption in transit and at rest

Multilingual extraction inside the boundary — including Arabic

Read any grading tool's policy next to ours.

Privacy policies are public. Some grading platforms' policies describe collecting learner, tutor and third-party personal data — names, emails, dates of birth — and using data to train their models. Ours can't say that, because the architecture doesn't do it.

What the policy saysSokrosTypical grading-AI tools*
Learner work used to train modelsNeverCommon — often the default
Name, email, date of birth in training dataNoDisclosed by some policies
Third-party LLM APIs in the marking pathNoneFrequently
Needs your assessment history to workNo — dozens to calibrateOften hundreds to thousands
On-premise / in-region deploymentYes — UK · EU · GulfRarely offered
Retention and deletion on centre instructionYesVaries by provider

*Based on competitors' own published privacy policies at the time of writing — for exampleGraide's policy, which describes collecting learner, tutor and third-party personal data including name, email and date of birth, and using data to improve its models. Policies change — read the current version yourself, and hold ours to the same standard.

The data questions, answered.

What data does Sokros hold about a learner?

The submitted work, the structured evidence extracted from it (with verbatim quotes), every marking decision with its reasoning, and the rendered feedback sheet — keyed by learner, cohort, unit, brief year and attempt. That record exists because quality assurance depends on it, and it is retrievable and deletable on centre instruction.

Does any learner data leave our deployment boundary?

No learner data is sent to third-party model APIs anywhere in the marking path. On sovereign deployments, nothing leaves your infrastructure at all; on Sokros-operated deployments, data stays in the region you choose.

Is our centre's data used to improve Sokros for other centres?

No. Units are isolated configuration — there are no cross-unit fallbacks, and another centre's marking never shapes yours. Behavioural changes to the engine are numbered amendments, replay-tested, never silent retraining on customer data.

How should we compare grading tools on privacy?

Read the published privacy policy and look for three things: whether learner data trains models, which personal fields are collected and why, and whether a third-party AI service sits in the marking path. Policies state these plainly — ours does, and so do our competitors'.

Read the policiesAsk for it in writing

Put it to your DPO.

We'll answer every data-protection question in writing — boundary diagrams, retention terms, deployment options and all.