At Viva, security, privacy, and responsible AI are built into the platform, not added on top. We serve educational institutions across the world, and our approach to compliance is designed to meet the highest standards in every jurisdiction we operate in.
Questions? Contact privacy@vivaproof.com or request our full Vendor Security Overview.
Section 1 — Security & Data Protection
How We Protect Student Data
Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. This includes voice recordings, transcripts, grades, and all other student information.
Tenant Isolation
Each institution's data is kept strictly separate from every other institution's through row-level security in the database.
Access Controls
Access to student data is limited to personnel who need it to operate the service. All access is logged and auditable. Admin access requires multi-factor authentication.
Vulnerability Management
Automated dependency scanning on every code change (GitHub Dependabot). Critical vulnerabilities patched within 7 days; high-severity within 30 days. Security reviews at every major release; a third-party penetration test is commissioned ahead of our SOC 2 audit.
Breach Notification
If a data breach affects student data, we notify affected institutions within 72 hours of becoming aware, consistent with GDPR Article 33 (EEA/UK), Korea PIPA Article 34, and equivalent national requirements elsewhere.
Data Deletion
Voice recordings are automatically deleted within 90 days of the grade being released for that interview — sooner if the student requests it once grading is complete and there is no open review — and the countdown pauses while an integrity flag or grade appeal is open on that interview, or while the institution holds a documented, time-limited retention hold on the class. Voice ID / voiceprints (if enabled) are deleted on the first of: purpose satisfied; 30 days after consent withdrawal; 90 days after account closure or contract end; or three years after the student's last interaction. Camera Check signals and any flagged still images (if enabled) are deleted on the same schedule as the associated interview record. All student data is deleted or anonymised after the contract period. Written deletion confirmation provided on request.
Optional Integrity Features
Voice ID is offered to every student during onboarding by default, for students aged 14 and over — it isn't something an institution switches on or off. A short voice sample confirms the student taking the interview is the student who submitted the work; never used for grading, only to flag possible impersonation to the instructor. Individual student consent is always required, given on Voice ID's own standalone screen, before anything is captured. Illinois is the one exception: not offered to students at an Illinois institution until that institution has signed a BIPA Rider, as Illinois law requires.
Camera Check remains institution-controlled — off by default, switched on only if the institution enables it, limited to students 14 and over, with the same standalone student consent required before anything is captured.
- Voice ID (voice identity). A short voice sample used only to confirm the student taking the interview is the student who submitted the work, and to flag possible impersonation to the instructor. Never used for grading. Voiceprint matching runs on Viva's own service; the only subprocessor that receives this data is Render.
- Camera Check (gaze and presence). The student's camera derives simple attention and presence signals. Face and gaze analysis runs locally in the student's browser; live video is never transmitted to Viva or any subprocessor. Viva keeps only derived numeric signals and a small number of flagged still images. The feature does not identify a student from their face and creates no faceprint — identity checking, where enabled, is done by Voice ID, not the camera.
A student may decline either feature, or withdraw consent, at any time, with no penalty and no effect on their grade; the institution assesses them another way, and that alternative may not be more burdensome than the declined feature would have been.
Our Subprocessors
We work with a small number of trusted technology providers to operate the platform. Subprocessors are primarily based in the United States; Supabase and PostHog each offer EU/UK data residency options. Each is bound by a written data processing agreement with terms no less protective than our own.
| Provider | Role | Location | SOC 2 |
|---|---|---|---|
| Anthropic (Claude) | AI interviewing, question generation, grading (inputs/outputs deleted within 30 days; not used for model training) | US | Type II ✓ |
| AWS | Secondary AI evaluation and QA cross-checks (tie-breaker model) | US | Type II ✓ |
| Cartesia | Korean voice synthesis for live interviews | US | Type II ✓ |
| Daily.co | Real-time audio transport (WebRTC) | US | Type II ✓ |
| Deepgram | Speech-to-text and English voice synthesis | US | Type II ✓ |
| Fal.ai | AI image generation for anti-cheat visual questions | US | Type II ✓ |
| Secondary AI evaluation; anti-cheat image generation | US | Type II ✓ | |
| Microsoft | Office document viewer (legacy format fallback) | US | Type II ✓ |
| Modal Labs | Hosting for the speech models Viva runs itself in live interviews (English voice synthesis, speech-to-text); audio is processed in transit and not stored | US | Type II ✓ |
| OpenAI | Secondary AI evaluation and QA cross-checks | US | Type II ✓ |
| PostHog | Product analytics (consent-gated) | US / EU | Type II ✓ |
| Render | Speaker-verification (Voice ID), document text extraction, OCR | US | Type II ✓ |
| Resend | Transactional email | US | Type II ✓ |
| Sentry | Error monitoring (PII scrubbed before write) | US | Type II ✓ |
| Stripe | Billing (no card data stored by Viva) | US | Type II ✓ |
| Supabase | Database, authentication, file storage | US / EU-UK available | Type II ✓ |
| Vercel | Application hosting | US | Type II ✓ |
Slack. Viva uses Slack for internal operational alerting (system health, usage metrics, and de-identified product-feedback summaries). No Student Data or other personal data is transmitted to Slack, so Slack is not acting as a subprocessor of personal data.
SOC 2 Readiness
Viva is currently in the SOC 2 Type II readiness phase. Our controls are operating today. The formal audit period and Type II report are targeted for 2027.
Deployment Options
Managed cloud (standard). Signed DPAs, the subprocessor list, zero-retention AI processing, encryption in transit and at rest, regional hosting commitments available under contract.
Private deployment (enterprise, in rollout). Single-tenant deployment inside your institution's own cloud environment and region, with AI running through your institution's own AWS Bedrock service. Prompts and responses are not sent to Anthropic or Viva's shared infrastructure. Contact us to scope a private deployment.
Section 2 — Education Privacy Compliance
Viva is designed to comply with education privacy laws across every jurisdiction we serve. Below we explain our obligations under the two primary US frameworks. If your institution is located outside the US, we work with you to put the appropriate compliance documentation in place. Contact privacy@vivaproof.com for details relevant to your country.
FERPA (United States)
What Is FERPA?
The Family Educational Rights and Privacy Act (FERPA) is a US federal law that protects the privacy of student education records. It gives parents and eligible students the right to inspect, correct, and control access to education records.
Viva's Role Under FERPA
Viva acts as a "school official" with a "legitimate educational interest" in student data, as defined under 34 CFR § 99.31(a)(1)(i)(B). This means:
- We perform a service for which the school would otherwise use its own employees, specifically, conducting oral assessments and generating AI-suggested grades
- We are under the direct control of the school with respect to the use and maintenance of student data
- We are bound by the same use-and-redisclosure restrictions that apply under 34 CFR § 99.33(a)
What We Do Not Do
- We do not share student education records with third parties except as necessary to provide the service
- We do not use student data for advertising or commercial purposes unrelated to the school's educational purpose
- We do not disclose personally identifiable information except as permitted by the school or required by law
Parental and Student Rights
Students who are 18 or older (or who attend a post-secondary institution) hold their own FERPA rights. Parents hold FERPA rights for students under 18. Through their school, parents and eligible students may inspect, request correction of, and control disclosure of education records.
For questions about FERPA rights, contact your school's registrar or data protection contact, who will liaise with Viva.
COPPA (United States — Under-13 Students)
For students under age 13, Viva operates as a service provider to schools under the Children's Online Privacy Protection Act (COPPA). Schools are responsible for obtaining verifiable parental consent before enrolling students under 13. Viva does not knowingly collect data from under-13 students without school authorisation.
Other Jurisdictions
Viva maintains equivalent compliance documentation and contractual addenda for other jurisdictions, including (but not limited to):
- Republic of Korea: Korea PIPA (Personal Information Protection Act) — cross-border transfer disclosure, voiceprint and video-integrity consent, under-14 guardian consent
- EEA / UK: EU GDPR / UK GDPR — Standard Contractual Clauses (SCCs), UK IDTA, data subject rights
- Other national laws: available on request
Contact privacy@vivaproof.com for compliance documentation specific to your institution's jurisdiction.
Section 3 — Data & AI Ethics
Our Approach to AI in Education
The Instructor Always Decides
Every AI-generated grade and piece of feedback in Viva is advisory. An instructor is responsible for every grade and can override any AI suggestion at any time, for any reason, without explanation.
Transparency
When Viva generates a suggested grade, the AI also produces a structured rationale explaining why. Students can request access to their interview recording and transcript through their institution.
Camera-Based Integrity, and the Line We Do Not Cross
- We do not infer emotion. Prohibited under Article 5(1)(f) of the EU AI Act, and we don't build or operate Camera Check to do it.
- We do not identify by face. No faceprint, no facial-recognition template.
- It never decides anything. Camera Check signals are advisory indicators surfaced to an instructor, exactly like AI-suggested grades.
- It runs on the student's device. Live video never leaves the student's own browser.
Responsible Data Use
We do not sell student data, ever. We do not use it for advertising. We do not use it to train our AI models without explicit written permission from the institution.
Student Voice and Agency
Students are informed about how Viva works before their first interview through the Privacy Policy's Students & Families section. They consent explicitly to voice recording. Voice ID and Camera Check each require their own separate, standalone consent, given at the point that feature's data is actually captured — and a student may decline or withdraw either at any time without penalty. They can request access to their recording. They can raise concerns about their assessment with their instructor. Viva does not make educational decisions about students; institutions do.
Contact Us
For questions about our security practices, compliance, or AI ethics:
privacy@vivaproof.com
Viva Proof, Inc., Boston, MA, USA
vivaproof.com/legal/trust-center
© 2026 Viva Proof, Inc. All rights reserved.
Also see our Privacy Policy · Terms of Service · Acceptable Use Policy.