Trust you can verify.
LAURA is a correction assistant, built to the GDPR: the AI proposes, the teacher decides, and every decision is provable. This page shows how school leadership, authorities and data protection officers can check that for themselves.
The five verification pillars
Each pillar points to its proof: an architecture decision (ADR) or verifiable code. No marketing claims without a basis.
Teacher Final Decision
LAURA never assigns an automatic grade. Every assessment is a proposal, and it only becomes final through the teacher’s explicit release. This step is enforced by the architecture, not a checkbox in the settings.
Proof: ADR-0012; deterministic, overridable grade proposal (implemented and tested).
Audit trail with hash chain
Every decision is logged append-only and cryptographically chained via SHA-256. Tampering is not quietly repaired but made visible: the history can be verified independently.
Proof: ADR-0019; verification in apps/worker/audit/verify.py (implemented and tested).
EU data residency
All metadata and processing results live in a dedicated database project in Frankfurt (eu-central-1). Row-Level Security on every table; the school is the hard tenant boundary.
Proof: DEC-019/ADR-0026, ADR-0031; row-level security on every table, enforced for new ones by the ensure_rls event trigger (deployed).
Local-first, controlled processing
Raw media (photos, scans) stay local by default or in school-controlled storage. Which stage applies is your choice: in the default local stage the server actively rejects every upload, and with the Local hosting plan Laura runs entirely on your own servers. Cloud processing happens only after explicit release (opt-in): never silently, never by default.
Proof: ADR-0013/0016/0033; documented processing_mode matrix (local is the default).
Transparency instead of hidden tracking
No advertising trackers, no hidden scanning of student devices: that is anchored in the architecture. Since 13 August 2026 the public website has collected no web analytics at all: the former Google Analytics tag was removed for good. It sat on 183 pages, cost 471 ms of load time per visit and collected zero data points, because consent could structurally never be given. The correction environment never had tracking, and student or exam data were never involved. The consent component deliberately stays in the code: if analytics ever return, they return only together with a visible banner and a dedicated section in the privacy policy.
Proof: ADR-0018 (device scanning), ADR-0022 (lead sandboxes without a backend), DEC-056/ADR-0071 (no web analytics); the coupling is enforced by the no-analytics-without-consent regression test.
Data flows made transparent
Three trust zones, clearly separated. What lives where is not a matter of trust, but of architecture.
Public zone
Vercel: only the static web frontend (apps/web)
No student data, no secrets, no backend, no workers.
Controlled zone
EU database (Frankfurt) and controlled processing
Pseudonym IDs, assessment and audit metadata, protected by auth and Row-Level Security.
Local zone
Teacher’s device / school-controlled storage
Raw media and real-name mapping. They leave the device only after explicit release.
Data classes in brief (K1-K6)
| Class | Content | Where it lives |
|---|---|---|
| K1 | Raw media (scans, photos) | local / school-controlled, never public |
| K2 | High PII (real names) | local, encrypted mapping, never in the cloud |
| K3 | Metadata + pseudonyms | EU database, RLS-protected |
| K4 | Audit / hashes | EU database, append-only |
| K5 | Synthetic / public | website, demos, exclusively synthetic |
| K6 | System configuration + secrets | secret store, never in the frontend, never in Git |
Documents for your review
The status of each document is stated honestly. We list certifications only once they are granted: until then, none appear here.
DPA template
Data processing agreement under Art. 28 GDPR for schools and authorities.
TOM overview
Technical and organisational measures (Art. 32 GDPR).
Processing modes documentation
Documented processing modes (local default / EU self-hosted / cloud opt-in).
Records of processing extract
Extract from the records of processing activities (Art. 30 GDPR).
DPIA guide
Guide to the data protection impact assessment (Art. 35 GDPR) for schools.
Deletion concept
Implementation of the right to erasure (Art. 17 GDPR), including backup retention.
Common review questions
- Does LAURA grade automatically?
- No. LAURA never assigns automatic grades. Every assessment is a proposal to the teacher; it only becomes final through their explicit release. This step is enforced by the architecture (Teacher Final Decision).
- Where does student data live?
- Raw media (photos, scans) stay local on the device or in school-controlled storage. The EU database (Frankfurt) holds only pseudonym IDs, assessment and audit metadata, protected by Row-Level Security with the school as the hard tenant boundary. The real-name mapping stays local.
- What does the cloud see?
- By default: no raw media. Cloud processing is exclusively opt-in and then limited to what is necessary (for example image excerpts of disputed passages, pseudonymised). There is no silent cloud escalation: it is ruled out by the architecture.
- What is the hash chain?
- Every teacher decision is chained to its predecessor with a SHA-256 hash and stored append-only. Later changes break the chain visibly; the integrity of the entire history can be verified independently.
- Is LAURA GDPR-compliant?
- LAURA is designed to the GDPR from the ground up: privacy by design and by default (Art. 25), data minimisation (Art. 5), EU data residency, RLS tenant separation, auditable decisions and documented processing modes. We provide the DPA template and TOM overview on request; the formal assessment is made by the school or its DPO, and we supply the documents for it.
Check it yourself instead of taking our word for it
Four small hands-on demos, including: adjusting the confidence thresholds yourself, tampering with an audit log and watching the check catch it, and following how a conflict between two devices is resolved. Everything runs in your browser, with no connection to our servers.
Developer sandbox
Four interactive demos of Laura's core algorithms. Everything runs locally in your browser.
Confusion Matrix
Laura learns from your edits. Here you can see how the most frequent confusions are reduced.
- a→o18.0 %
- e→c14.0 %
- n→m21.0 %
- h→k9.0 %
- u→v11.0 %
Green Word Precision
A direct line for data protection questions
No forced form: one email is enough. We reply with the requested documents, and send nothing without your explicit confirmation (double opt-in).