Which AI model do you use?
We currently utilize Claude Sonnet, hosted securely via AWS Bedrock. We chose this infrastructure specifically because it ensures no data is shared with the third-party model provider. All data remains segregated within our secure AWS environment. While we may update models in the future to maintain state-of-the-art performance, any model we use must strictly comply with our rigorous data privacy and security requirements.
What data is sent to the AI?
To power the "Get Hints" feature, the LLM model reads the question text and the student’s current answer. This allows the AI to recognize the stage the student has reached and generate a tailored hint.
What safeguards are in place regarding AI outputs, and how is teacher oversight implemented?
Student safety and teacher autonomy are our top priorities. To prevent unpredictable outputs, students do not interface directly with the AI. All AI-generated hints are governed by a teacher-approved rubric. By allowing the educator to dictate the underlying instructions, the AI's responses are firmly restricted to the context of the practice test and learning objectives.
How is student data processed and secured?
All processing of student data occurs within our secure AWS servers. We ensure student data is secured by employing multi-layered cyber security measures and rigorous data handling practices. These include:
- Secure LLM Environment: Our LLM models are hosted on AWS Bedrock. This architecture ensures that data is processed in isolation and is never shared with the model provider for their own use.
- Data Encryption: All data is "scrambled" (encrypted) whenever it moves or is stored, making it unreadable to outsiders.
- 24/7 Protection: We use automated defense systems to block cyber attacks and monitor for suspicious activity.
- Restricted Access: Our databases are kept in a private network that is completely cut off from the public internet.
- Staff Security: Only authorized staff can access technical systems. Their access requires strict identity verification and every action they take is recorded.
Furthermore, Goodnotes is ISO-27001 and SOC 2 certified. This means our data privacy and cyber security commitments are audited on an annual basis to the highest standards by an independent and certified body.
Is student or teacher data used to train the AI models?
No. We never use any teacher or student data to train the Large Language Models (LLMs). Your data remains yours and is used solely to provide the service.