Legal

Trust Center

Viva Proof, Inc. · Last updated: July 2026

법적 고지

신뢰 센터

Viva Proof, Inc. · 최종 업데이트: 2026년 7월

FERPACompliant
COPPACompliant
K-PIPAReady
GDPR
UK/EU
Ready
SOC 2In progress

At Viva, security, privacy, and responsible AI are built into the platform, not added on top. We serve educational institutions across the world, and our approach to compliance is designed to meet the highest standards in every jurisdiction we operate in.

This page explains how we protect student data, how we meet education privacy law obligations globally, and how we approach AI fairly and transparently.

Questions? Contact privacy@vivaproof.com or request our full Vendor Security Overview.

Jump to Security & Data Protection Education Privacy Compliance Data & AI Ethics

Section 1 — Security & Data Protection

How We Protect Student Data

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. This includes voice recordings, transcripts, grades, and all other student information.

Tenant Isolation

Each school's data is kept strictly separate from every other school's through row-level security in the database. A teacher or student at one school cannot access data from another.

Access Controls

Access to student data is limited to personnel who need it to operate the service. All access is logged and auditable. Admin access requires multi-factor authentication.

Vulnerability Management

We run automated dependency scanning on every code change (GitHub Dependabot). Critical vulnerabilities are patched within 7 days; high-severity issues within 30 days. We conduct security reviews at every major release, and a third-party penetration test is commissioned ahead of our SOC 2 audit.

Breach Notification

If a data breach affects student data, we notify affected schools within 72 hours of becoming aware, consistent with applicable data protection laws in each jurisdiction we serve, including GDPR Article 33 (EEA/UK), Korea PIPA Article 34, and equivalent national requirements elsewhere.

Data Deletion

Voice recordings are automatically deleted within 30 days of each session. Voiceprints (if enabled) are deleted on the first of: satisfaction of the purpose; 90 days after account closure or contract end; or three years after the student's last interaction. Video-integrity signals and any flagged still images (if that feature is enabled) are deleted on the same schedule as the associated interview record. All student data is deleted or anonymised after the contract period. We provide written deletion confirmation on request.

Optional Integrity Features

Two optional features add an identity or presence check to an interview. Both are off by default, both are limited to students aged 14 and over, and neither can be switched on until the school has obtained the separate consent that applicable biometric-privacy law requires.

A student may decline either feature, or withdraw consent, at any time, with no penalty and no effect on their grade; the school assesses them another way.

Our Subprocessors

We work with a small number of trusted technology providers to operate the platform. Subprocessors are primarily based in the United States; Supabase and PostHog each offer EU/UK data residency options. Each is bound by a written data processing agreement with terms no less protective than our own.

ProviderRoleLocationSOC 2
Anthropic (Claude)AI interviewing, question generation, and grading (inputs and outputs deleted within 30 days; not used for model training)USType II ✓
AWS (Amazon Web Services)Secondary AI evaluation and quality-assurance cross-checks (tie-breaker model)USType II ✓
CartesiaKorean voice synthesis for live interviewsUSType II ✓
Daily.coReal-time audio transport (WebRTC) for live interviewsUSType II ✓
DeepgramSpeech-to-text and English voice synthesis for live interviewsUSType II ✓
Fal.aiAI image generation for anti-cheat visual questions (prompts may be derived from student work)USType II ✓
GoogleSecondary AI evaluation and quality-assurance cross-checks; image generation for anti-cheat visual questionsUSType II ✓
MicrosoftOffice document viewer (fallback previews for legacy Office formats)USType II ✓
OpenAISecondary AI evaluation and quality-assurance cross-checksUSType II ✓
PostHogProduct analytics (consent-gated)US / EUType II ✓
RenderSpeaker-verification (voiceprint), document text extraction, OCR, and document-to-PDF conversion microserviceUSType II ✓
ResendTransactional emailUSType II ✓
SentryError monitoring (PII scrubbed before write)USType II ✓
StripeBilling (Viva does not store card data)USType II ✓
SupabaseDatabase, authentication, file storageUS / EU-UK availableType II ✓
VercelApplication hostingUSType II ✓

Slack. Viva uses Slack for internal operational alerting (system health, usage metrics, and de-identified product-feedback summaries). No Student Data or other personal data is transmitted to Slack, so Slack is not acting as a subprocessor of personal data.

SOC 2 Readiness

Viva is currently in the SOC 2 Type II readiness phase. Our controls are operating today. The formal audit period and Type II report are targeted for 2027.

Near-term milestones:

Want the full Vendor Security Overview? Contact privacy@vivaproof.com.

Deployment Options

Managed cloud (standard). Viva runs as a managed service with the safeguards described on this page: signed DPAs, the subprocessor list above, zero-retention AI processing (student data is never used to train models), encryption in transit and at rest, and regional hosting commitments available under contract.

Private deployment (enterprise, in rollout). For institutions with strict data-residency or sovereignty requirements, Viva can be deployed single-tenant inside your institution's own cloud environment and region. In this model, student submissions, voice audio, and assessment records are processed and stored on infrastructure your institution controls, and the AI runs through your institution's own AWS Bedrock service in your chosen region. Prompts and responses are not sent to Anthropic or to Viva's shared infrastructure. Several integrity checks already run on the student's own device or on Viva-owned code with no third party involved (camera-based checks in the browser; voiceprint matching on our own service). Contact us to scope a private deployment.

Fully offline (air-gapped) deployments are on our roadmap. We currently recommend private deployment, which delivers equivalent data-control guarantees without reducing assessment quality.

Section 2 — Education Privacy Compliance

Viva is designed to comply with education privacy laws across every jurisdiction we serve. Below we explain our obligations under the two primary US frameworks. If your institution is located outside the US, we work with you to put the appropriate compliance documentation in place. Contact privacy@vivaproof.com for details relevant to your country.

FERPA (United States)

What Is FERPA?

The Family Educational Rights and Privacy Act (FERPA) is a US federal law that protects the privacy of student education records. It gives parents and eligible students the right to inspect, correct, and control access to education records.

Viva's Role Under FERPA

Viva acts as a "school official" with a "legitimate educational interest" in student data, as defined under 34 CFR § 99.31(a)(1)(i)(B). This means:

What We Do Not Do

Parental and Student Rights

Students who are 18 or older (or who attend a post-secondary institution) hold their own FERPA rights. Parents hold FERPA rights for students under 18. Through their school, parents and eligible students may inspect, request correction of, and control disclosure of education records.

For questions about FERPA rights, contact your school's registrar or data protection contact, who will liaise with Viva.

COPPA (United States — Under-13 Students)

For students under age 13, Viva operates as a service provider to schools under the Children's Online Privacy Protection Act (COPPA). Schools are responsible for obtaining verifiable parental consent before enrolling students under 13. Viva does not knowingly collect data from under-13 students without school authorisation.

Other Jurisdictions

Viva maintains equivalent compliance documentation and contractual addenda for other jurisdictions, including (but not limited to):

Contact privacy@vivaproof.com for compliance documentation specific to your institution's jurisdiction.

Section 3 — Data & AI Ethics

Our Approach to AI in Education

AI should support teachers, not replace them. Viva is built on one core principle: the AI never makes the final grading decision. Here is what that means in practice.

The Teacher Always Decides

Every AI-generated grade and piece of feedback in Viva is advisory. A teacher is responsible for every grade and can override any AI suggestion at any time, for any reason, without explanation. The teacher either reviews each result before it is released or, per assignment, chooses to release results automatically once grading is complete; the AI never decides a final grade on its own. The AI is a tool; the educator is the decision-maker.

Transparency

When Viva generates a suggested grade, the AI also produces a structured rationale explaining why. Teachers can see exactly what the AI assessed, what questions it asked, and how the student responded. Students can request access to their interview recording and transcript through their school.

No "Black Box" Grading

Viva does not issue grades from an unexplained algorithm. Every assessment result is tied to a specific interview, a specific set of teacher-designed criteria, and a visible AI explanation that a teacher can read, question, and override.

Camera-Based Integrity, and the Line We Do Not Cross

Where a school enables the optional video-integrity feature, the student's camera is used to derive attention and presence signals during the interview. We hold this feature to a deliberately narrow purpose, and there is a specific line we do not cross:

Responsible Data Use

Bias and Fairness

Oral assessment is not neutral, and we take that seriously. We design Viva's interview system to:

We conduct reviews of assessment outputs for patterns that may indicate demographic bias. Our Bias & Validity Audit Methodology is available on request.

Student Voice and Agency

Students are informed about how Viva works before their first interview through the Student Privacy Notice. They consent explicitly to voice recording. The optional voiceprint and video-integrity features require their own separate consent, and a student may decline or withdraw either at any time without penalty. They can request access to their recording. They can raise concerns about their assessment with their teacher. Viva does not make educational decisions about students; schools do.

Contact Us

For questions about our security practices, compliance, or AI ethics:

privacy@vivaproof.com
Viva Proof, Inc., Boston, MA, USA
vivaproof.com/legal/trust-center

© 2026 Viva Proof, Inc. All rights reserved.
Also see our Privacy Policy · Terms of Service.

이 한국어 버전은 이해를 돕기 위한 참고용 번역이에요. 법적 효력을 가지는 것은 영문 원본입니다.

Viva에서 보안, 개인정보 보호, 책임 있는 AI는 나중에 덧붙인 것이 아니라 플랫폼에 처음부터 내장되어 있습니다. 저희는 전 세계 교육 기관을 지원하며, 저희의 준수 방식은 운영하는 모든 관할권에서 가장 높은 기준을 충족하도록 설계되었습니다.

이 페이지는 저희가 학생 데이터를 어떻게 보호하는지, 전 세계 교육 개인정보 보호법 의무를 어떻게 충족하는지, 그리고 AI를 어떻게 공정하고 투명하게 다루는지 설명합니다.

궁금한 점이 있으신가요? privacy@vivaproof.com 으로 연락하시거나 전체 공급업체 보안 개요(Vendor Security Overview)를 요청해 주세요.

바로 가기 보안 및 데이터 보호 교육 개인정보 보호 준수 데이터 및 AI 윤리

섹션 1. 보안 및 데이터 보호

학생 데이터를 보호하는 방법

암호화

모든 데이터는 전송 중 TLS 1.2+로, 저장 시 AES-256으로 암호화됩니다. 여기에는 음성 녹음, 트랜스크립트, 점수, 그 밖의 모든 학생 정보가 포함됩니다.

테넌트 격리

각 학교의 데이터는 데이터베이스의 행 수준 보안을 통해 다른 모든 학교의 데이터와 엄격히 분리됩니다. 한 학교의 교사나 학생은 다른 학교의 데이터에 접근할 수 없습니다.

접근 통제

학생 데이터 접근은 서비스 운영에 그것이 필요한 인원으로 제한됩니다. 모든 접근은 기록되고 감사 가능합니다. 관리자 접근에는 다중 인증(MFA)이 필요합니다.

취약점 관리

저희는 모든 코드 변경에 대해 자동 의존성 스캔(GitHub Dependabot)을 실행합니다. 치명적 취약점은 7일 이내, 고위험 문제는 30일 이내에 패치합니다. 주요 릴리스마다 보안 검토를 수행하고, 매년 외부 침투 테스트를 의뢰합니다.

침해 통지

데이터 침해가 학생 데이터에 영향을 미치는 경우, 저희는 인지 후 72시간 이내에 영향받는 학교에 통지하며, 이는 저희가 운영하는 각 관할권의 적용 가능한 데이터 보호법(GDPR 제33조[EEA/UK], 한국 PIPA 제34조, 그 밖의 동등한 국가별 요건 포함)을 따릅니다.

데이터 삭제

음성 녹음은 각 세션 후 30일 이내에 자동 삭제됩니다. 음성 지문(활성화된 경우)은 계정 폐쇄 후 90일 이내에 삭제됩니다. 모든 학생 데이터는 계약 기간 종료 후 삭제되거나 익명화됩니다. 요청 시 서면 삭제 확인서를 제공합니다.

하위 처리자

저희는 플랫폼 운영을 위해 소수의 신뢰할 수 있는 기술 제공업체와 협력합니다. 하위 처리자는 주로 미국에 소재하며, Supabase와 PostHog는 각각 EU/UK 데이터 레지던시 옵션을 제공합니다. 각 업체는 저희 못지않게 보호적인 조건을 담은 서면 데이터 처리 계약에 구속됩니다.

제공업체역할위치SOC 2
Anthropic (Claude)AI 인터뷰, 질문 생성, 채점(입력·출력 30일 내 삭제, 모델 학습에 미사용)USType II ✓
AWS (Amazon Web Services)AI 보조 평가 및 품질 교차 검증(최종 판정 모델)USType II ✓
Cartesia실시간 인터뷰용 한국어 음성 합성USType II ✓
Daily.co실시간 인터뷰용 오디오 전송(WebRTC)USType II ✓
Deepgram음성 인식 및 영어 음성 합성(실시간 인터뷰)USType II ✓
Fal.ai부정행위 방지 시각 문항용 AI 이미지 생성(프롬프트가 학생 과제물에서 파생될 수 있음)USType II ✓
GoogleAI 보조 평가 및 품질 교차 검증, 부정행위 방지 시각 문항용 이미지 생성USType II ✓
MicrosoftOffice 문서 뷰어(구형 Office 형식 대체 미리보기)USType II ✓
OpenAIAI 보조 평가 및 품질 교차 검증USType II ✓
PostHog제품 분석(동의 기반)US / EUType II ✓
Render화자 확인(성문), 문서 텍스트 추출, OCR, 문서-PDF 변환 마이크로서비스USType II ✓
Resend거래성 이메일USType II ✓
Sentry오류 모니터링(기록 전 PII 정제)USType II ✓
Stripe청구(Viva는 카드 데이터를 저장하지 않음)USType II ✓
Supabase데이터베이스, 인증, 파일 저장US / EU-UK 가능Type II ✓
Vercel애플리케이션 호스팅USType II ✓

Slack. Viva는 내부 운영 알림(시스템 상태, 사용 지표, 비식별 제품 피드백 요약)에 Slack을 사용합니다. 학생 데이터나 그 밖의 개인정보는 Slack에 전송되지 않으므로, Slack은 개인정보의 하위 처리자가 아닙니다.

SOC 2 준비 현황

Viva는 현재 SOC 2 Type II 준비 단계에 있습니다. 저희의 통제 장치는 현재 작동 중입니다. 공식 감사 기간과 Type II 보고서는 2027년을 목표로 하고 있습니다.

단기 마일스톤:

전체 공급업체 보안 개요가 필요하신가요? privacy@vivaproof.com 으로 연락해 주세요.

도입 방식 안내

관리형 클라우드 (기본). Viva는 이 페이지에 안내된 보호 조치와 함께 관리형 서비스로 제공돼요. DPA 체결, 위의 하위 처리자 목록 공개, AI 처리 시 무보존(학생 데이터는 모델 학습에 사용되지 않아요), 전송·저장 구간 암호화, 계약에 따른 리전 지정이 포함돼요.

프라이빗 배포 (기관 전용, 도입 진행 중). 데이터 주권이나 국내 보관 요건이 엄격한 기관을 위해, Viva를 기관이 직접 관리하는 클라우드 환경과 리전 안에 단일 테넌트로 배포할 수 있어요. 이 방식에서는 학생 제출물, 음성, 평가 기록이 기관이 통제하는 인프라에서 처리·보관되고, AI는 기관 소유의 AWS Bedrock을 통해 지정한 리전에서 실행돼요. 프롬프트와 응답은 Anthropic이나 Viva의 공용 인프라로 전송되지 않아요. 카메라 기반 검사(브라우저 내 처리), 성문 대조(Viva 자체 서비스) 등 일부 무결성 검사는 지금도 제3자 없이 동작해요. 프라이빗 배포가 필요하시면 문의해 주세요.

완전 오프라인(폐쇄망) 배포는 로드맵에 있어요. 현재는 평가 품질을 유지하면서 동등한 데이터 통제를 제공하는 프라이빗 배포를 권장해요.

섹션 2. 교육 개인정보 보호 준수

Viva는 저희가 지원하는 모든 관할권의 교육 개인정보 보호법을 준수하도록 설계되었습니다. 아래에서는 미국의 두 가지 주요 프레임워크에 따른 저희의 의무를 설명합니다. 기관이 미국 외에 있는 경우, 저희는 해당 기관과 함께 적절한 준수 문서를 마련합니다. 거주국에 맞는 자세한 내용은 privacy@vivaproof.com 으로 문의해 주세요.

FERPA (미국)

FERPA란?

가족 교육 권리 및 사생활 보호법(FERPA)은 학생 교육 기록의 사생활을 보호하는 미국 연방법입니다. 부모와 자격 있는 학생에게 교육 기록을 열람, 정정, 그리고 그에 대한 접근을 통제할 권리를 부여합니다.

FERPA에서 Viva의 역할

Viva는 34 CFR § 99.31(a)(1)(i)(B)에 정의된 바와 같이 학생 데이터에 "정당한 교육적 이해관계"를 가진 "학교 관계자(school official)"로서 행위합니다. 이는 다음을 의미합니다:

저희가 하지 않는 것

부모와 학생의 권리

만 18세 이상이거나 고등교육 기관에 재학 중인 학생은 본인의 FERPA 권리를 가집니다. 만 18세 미만 학생의 FERPA 권리는 부모가 가집니다. 부모와 자격 있는 학생은 소속 학교를 통해 교육 기록을 열람하고, 정정을 요청하며, 그 공개를 통제할 수 있습니다.

FERPA 권리에 대한 질문은 소속 학교의 학적 담당자나 데이터 보호 담당자에게 문의해 주세요. 해당 담당자가 Viva와 협의합니다.

COPPA (미국, 만 13세 미만 학생)

만 13세 미만 학생에 대해, Viva는 아동 온라인 사생활 보호법(COPPA)에 따라 학교에 대한 서비스 제공자로서 행위합니다. 학교는 만 13세 미만 학생을 등록하기 전에 검증 가능한 부모 동의를 확보할 책임이 있습니다. Viva는 학교의 승인 없이 만 13세 미만 학생의 데이터를 알면서 수집하지 않습니다.

그 밖의 관할권

Viva는 다른 관할권에 대해서도 동등한 준수 문서와 계약 부속서를 유지하며, 여기에는 다음이 포함됩니다(이에 한정되지 않음):

기관의 관할권에 맞는 준수 문서가 필요하시면 privacy@vivaproof.com 으로 문의해 주세요.

섹션 3. 데이터 및 AI 윤리

교육에서의 AI에 대한 저희의 접근

AI는 교사를 대체하는 것이 아니라 지원해야 합니다. Viva는 하나의 핵심 원칙 위에 세워져 있습니다: AI는 결코 최종 채점 결정을 내리지 않는다는 것입니다. 이것이 실제로 무엇을 의미하는지 설명합니다.

항상 교사가 결정합니다

Viva에서 AI가 생성하는 모든 점수와 피드백은 참고용입니다. 모든 점수에 대한 책임은 교사에게 있으며, 교사는 언제든, 어떤 이유로든, 설명 없이 AI 제안 점수를 재정의할 수 있습니다. 교사는 각 결과를 공개 전에 직접 검토하거나, 과제별로 채점이 끝나면 결과를 자동으로 공개하도록 설정할 수 있고, AI가 스스로 최종 점수를 결정하지는 않습니다. AI는 도구이고, 결정권자는 교육자입니다.

투명성

Viva가 점수를 제안할 때, AI는 그 이유를 설명하는 구조화된 근거도 함께 생성합니다. 교사는 AI가 무엇을 평가했는지, 어떤 질문을 했는지, 학생이 어떻게 답했는지를 정확히 볼 수 있습니다. 학생은 소속 학교를 통해 자신의 인터뷰 녹음과 트랜스크립트에 대한 접근을 요청할 수 있습니다.

"블랙박스" 채점은 없습니다

Viva는 설명되지 않는 알고리즘으로 점수를 부여하지 않습니다. 모든 평가 결과는 특정 인터뷰, 교사가 설계한 특정 기준, 그리고 교사가 읽고, 질문하고, 재정의할 수 있는 가시적인 AI 설명에 연결되어 있습니다.

책임 있는 데이터 이용

편향과 공정성

구술 평가는 중립적이지 않으며, 저희는 그 점을 진지하게 받아들입니다. 저희는 Viva의 인터뷰 시스템을 다음과 같이 설계합니다:

저희는 인구통계학적 편향을 나타낼 수 있는 패턴이 있는지 평가 결과를 검토합니다. 저희의 편향 및 타당성 감사 방법론(Bias & Validity Audit Methodology)은 요청 시 제공됩니다.

학생의 목소리와 주체성

학생은 첫 인터뷰 전에 학생용 개인정보 고지(Student Privacy Notice)를 통해 Viva가 어떻게 작동하는지 안내받습니다. 학생은 음성 녹음에 명시적으로 동의합니다. 학생은 자신의 녹음에 대한 접근을 요청할 수 있습니다. 학생은 자신의 평가에 대한 우려를 담당 교사에게 제기할 수 있습니다. Viva는 학생에 관한 교육적 결정을 내리지 않으며, 그 결정은 학교가 내립니다.

문의

저희의 보안 관행, 준수, 또는 AI 윤리에 대한 질문은:

privacy@vivaproof.com
Viva Proof, Inc., Boston, MA, USA
vivaproof.com/legal/trust-center

© 2026 Viva Proof, Inc. All rights reserved.
함께 보세요: 개인정보처리방침 · 이용약관.