Security Overview

How Smart Learning System is built, hosted, and operated, for institutional reviewers.

Last updated: September 10, 2026

Authentication

Users sign in with their existing institutional account. We do not create or store separate passwords for LMS-launched users. Access is established through LTI 1.3 launch from the LMS.

LTI 1.3 / LTI Advantage

The integration is 1EdTech certified and uses LTI 1.3 with signed launches and OAuth 2.0 client credentials. Legacy LTI 1.1 shared secrets are not used.

Encryption

Data is encrypted in transit using TLS and at rest using platform-managed encryption provided by our cloud host.

Course isolation

Retrieval is scoped per course. A student's assistant draws on the material for the courses they are enrolled in, not on other institutions' or other courses' content.

Hosting

The service runs on major public cloud infrastructure in the United States, using managed services with vendor-maintained patching and platform-level network controls.

Access control

Administrative access is limited to personnel who need it to operate and support the service, protected by multi-factor authentication.

Payments

Card payments are processed by Stripe. We do not receive or store full card numbers on our systems.

Incident response

We notify affected institutions without undue delay of any confirmed breach of their student data, with the information needed for their own notification duties.

Data return and deletion

On termination or written request, institutional student data is deleted or returned within sixty (60) days, except where retention is required by law.

Requesting more detail

Institutional reviewers can request our current subprocessor list, LTI configuration details, data-flow description, and 1EdTech certification records. Write to admin@bayadataai.com and tell us what your review process needs.