Trust, stated as mechanisms.

Everything on this page describes something the software actually does. Where a protection does not exist, this page says so rather than leaving the gap for you to find.

What we hold about a person

One table describes every collection of records in the product — what it is for, what it holds, and what erasure does to it. Export, erasure and the retention clock all read that same table.

AI: what leaves, and what cannot

AI is off until a school turns it on, and the school brings its own provider and its own key. These are the limits that apply once it is on.

What the platform sees

Work and counts — never screens, and never one person's week.

In the classroom, a teacher's live board shows each student's own work products and how recently they changed — the same documents, submissions and attempts the teacher could already open — and a student can raise a hand on it. It does not see screens, open tabs, keystrokes or browsing, because nothing in Taonova captures them. A teacher can push a message to the class; the student dismisses it themselves, and any link in it is offered, never opened for them. A scheduled assessment session records only what the assessment already records — start and submit times, whether a start was late, and the focus-away summary the quiz already keeps — and never turns those numbers into a verdict.

For a school's leaders, Taonova counts adoption, not activity: how many people of each role, in each school, signed in or opened a module in a given week. It stores no page visits, no time spent, no order of events and no per-person history — the only per-person record is the most recent week someone was counted, kept so that nobody is counted twice. The counts are kept for 90 days and then dropped. They reach a leader only through the same small-group suppression as every other chart, so a group too small to stay anonymous is withheld, and the AI query assistant cannot read the underlying counts at all.

Getting in, and getting at

Every read and write is authorised on the server. Nothing depends on the interface hiding a button.

Where it runs

For the service we host. A school that runs Taonova itself controls all of this, and answers for it.

Two things a hosted-only product cannot offer

These are not features we added; they are consequences of how Taonova is licensed and built.

Run it yourself

A school can install Taonova on infrastructure it controls, keeping every record inside its own jurisdiction and its own network. We hold no routine access to it. That is the strongest data-residency answer any product can give, and it does not depend on our continued goodwill.

Read the source

Taonova is source-available under the Elastic License 2.0: a school, or an auditor it hires, may read and modify the code it runs and check these claims for itself rather than take them on trust. What the licence does not allow is offering Taonova to others as a hosted service.

What we do not claim

The section most vendors leave out.

We hold no ISO 27001 certification, no SOC 2 report, and no independent penetration test. Those are audits, and audits cost money we currently spend on the product. A school whose procurement requires a certificate should read this as a firm no for now, not as a soon.

What stands in their place: the security page lists what is missing beside what is in place, in the same detail, and we will answer a school's own security questionnaire honestly — including the answers that are "no".

We also do not claim to measure engagement, time on task, or how any individual uses the platform. We could not report those even if asked, because the data they would need is never collected.

The documents behind this page

This page is the short account. These are the binding ones, and they are readable without an account.

Privacy Policy · Security Practices · Subprocessors · Data Processing Agreement · Terms of Service

Privacy questions, data-subject requests and security reports: info@taonova.com