New: Original View reports — findings directly on the original document See what's new
Security & trust

How we protect your institution's work

Student submissions are confidential academic records. This page explains exactly how iOriginally handles them — the encryption, the isolation, the controls you hold, and the claims we deliberately don't make.

Encrypted in transit and at restNever used to train modelsSelf-hosted option available
Security practices

Protection as a practice, not a badge

Six practices apply to every document you submit — on every plan, in every deployment, from the first evaluation upload onwards.

Encryption in transit and at rest

Every connection to the platform runs over TLS, and documents, reports and repository entries are encrypted where they are stored. There is no plain-text path for student work.

Tenant isolation

Each institution runs in its own isolated workspace. Your submissions, repository and settings are never visible to another tenant, and your documents never enter another institution's matching pool.

Role-based access and audit log

Integrity office, instructors, students and administrators each see exactly what their role permits — and every sensitive action is recorded in an audit log your administrators can review.

Retention, export and deletion

Your institution decides how long submissions are kept. Export reports, certificates and repository contents at any time — and when you delete, deletion is honoured, repository entries included.

GDPR-ready processes

Data-minimising defaults, documented processing purposes, and workflows built to support access, export and erasure requests — so your data-protection office isn't improvising.

Signed webhooks and API keys

Every webhook delivery is signed so your systems can verify it really came from us. API keys are scoped to your institution and can be rotated or revoked at any time.

GDPR-readyNo model training on your workInstitution-controlled retentionSelf-host option
Data ownership

Your data stays yours

We process documents to produce your reports. That's the whole arrangement — there is no second use hiding in the terms.

  • Never trains models. Student work is never used to train or tune detection models — ours or anyone else's.
  • Never shared by default. Submissions match against the web, open scholarly sources and your own repository. They reach other institutions only if you explicitly opt into a shared repository.
  • Processed for one purpose. Documents exist in the platform to generate your reports and certificates — not analytics products, not advertising, nothing else.
  • Exportable at any time. Reports, certificates, repository contents and CSV data export on demand — leaving is always technically possible, so staying is a choice.
Read the privacy policy
Senior professor working on a laptop in a lecture theatre
University campus building
Self-hosted option

Run it entirely inside your network

For institutions whose policies — or regulators — require that student work never leaves campus infrastructure, iOriginally deploys fully on your own servers.

  • Documents never leave. Submissions, reports and the repository live on hardware you control, inside your own network perimeter.
  • Full feature parity. Similarity, AI-writing analysis, Original View reports and verifiable certificates work the same as in managed cloud.
  • Same license price. Self-hosting costs exactly what managed cloud costs — deployment is a choice, not an upsell.
  • Your policies apply. Retention, access and backup follow your institution's own rules, because it's your infrastructure end to end.
See pricing for both deployments
Operational transparency

Trust is easier when you can see what's happening

Security is only half of trust. The other half is operational: knowing where your submissions are, what you're paying for, and what a claim on this site is actually worth.

Live status, not silence

Every submission shows its live pipeline status in the student portal, with a receipt when it completes. If something fails on our side, you see that too — we don't hide failures behind a spinner.

Honest metering

Only completed reports count against your plan. Failed uploads, cancelled scans and re-runs caused by our side are never billed — on the evaluation, the annual license or credit packs.

No borrowed badges

You won't find certification logos on this page that we can't stand behind. We describe what we actually do — and when your IT or legal team needs more depth, we walk through it with them live.

On detection claims: similarity and AI-writing signals are aids for human judgment, not proof of misconduct. Every report and PDF carries that note — because trust includes being honest about what a score can and cannot tell you.
Accessibility

Built to WCAG 2.1 AA

Integrity tools are used by every student and every instructor — including those using screen readers, keyboards, magnification or reduced motion. We design and test toward WCAG 2.1 AA across the product and this site.

Contrast and focus

Text and interface states are designed against AA contrast ratios, and every interactive element has a visible focus outline — including on the navy bands of this site.

Keyboard and screen readers

Portals and report viewers are built for full keyboard navigation, with semantic landmarks, labelled controls and alt text — not mouse-only workflows.

Motion and readability

Animation respects prefers-reduced-motion, layouts hold together at 200% zoom, and meaning is never conveyed by colour alone — match categories carry labels, not just highlights.

Found a barrier?

If anything blocks you or your students — in a report, a portal or on this site — tell us. We treat accessibility gaps as bugs to fix, not feature requests to consider.

Accessibility statement: we work to conform to WCAG 2.1 AA and review new interfaces against it before release. If you encounter a barrier anywhere in iOriginally, contact us and we will prioritise a fix and suggest a workaround in the meantime.

Put your security questions to us directly

Book a demo and bring your IT, legal and integrity teams — we'll walk through data handling, retention and deployment live, and follow up in writing.