Last updated: March 2026

Built for institutional deployment.

UK data residency. GDPR aligned. DPIA ready. Every AI action auditable.

Trust Pack

Everything your DPO needs to evaluate Oralio

DPIA Template
DPA Template
Data Flow Diagram
Compliance Summary
Infrastructure Overview
Data Governance

Data Residency & Sovereignty

Your data stays in the UK.

All data is stored exclusively on Azure UK South. Each institution receives logically isolated storage. Azure infrastructure holds ISO 27001, 27017, and 27018 certifications. No data is transferred outside the UK.

GDPR & Data Protection

Oralio acts as a Data Processor for your institution.

  • Data Processing Agreement (DPA) template provided immediately.
  • Student data processed only for assessment purposes.
  • No profiling for marketing, advertising, or third-party use.
  • Full support for student rights: deletion and DSAR workflows.
  • DPIA-ready documentation included in the Trust Pack.

AI Transparency & Auditability

No black-box decisions. Every AI action is auditable.

Every AI action is logged and fully auditable.
Transcripts show exactly what was asked and answered.
AI confidence scoring flags uncertain results for review.
No black-box decisions — full reasoning chain visible to educators.
System Architecture

Human in the Loop

AI informs. Humans decide.

  • AI never makes the final call. Educators do.
  • Final assessment decisions are always made by a human educator.
  • Educators see AI reasoning before making judgements.
  • Uncertain cases are automatically flagged for additional review.

LTI 1.3 Compliance

Seamless, secure integration with your existing LMS.

Grade passback via AGS (Assessment Grade Services)
Secure user provisioning via NRPS
Tool launched from within LMS — no cross-domain tracking
OAuth 2.0 and JSON Web Tokens for all communication

Compliance & Data Questions

Clear answers to common questions about data governance, GDPR, and security.

All data is stored exclusively on Azure UK South. Each institution receives logically isolated storage. No data is transferred outside the UK. Azure infrastructure holds ISO 27001, 27017, and 27018 certifications.

Never. The AI conducts the conversation and produces evidence. Every final assessment decision is made by a human educator. The AI flags uncertain cases for additional review.

AI detection tools have documented 61% false positive rates for non-native speakers. Oralio does not assess language quality — it assesses understanding of subject matter only.

Reasonable adjustments are built in: extra time, pause and resume, text mode, no camera requirement, multilingual support. Adjustments can be configured per-student or per-assignment.

Moodle, Canvas, and Blackboard via LTI 1.3. The tool works inside your existing LMS — no separate login required.

Turnitin catches copying. It does not catch understanding. A student can use ChatGPT to produce original text that passes Turnitin cleanly. Oralio asks them to explain what they wrote. The two tools are complementary.

Every transcript and evidence pack is exportable in standard formats at any time. Nothing is locked in. Your data is always yours.

ChatGPT can have a conversation. It cannot read a student's specific submission, align questions to your rubric, produce a compliant audit trail, sync grades to your LMS, or apply reasonable adjustments securely.