Zum Inhalt springen
Trust Center

Trust you can verify.

LAURA is a correction assistant, built to the GDPR: the AI proposes, the teacher decides, and every decision is provable. This page shows how school leadership, authorities and data protection officers can check that for themselves.

Laura liest eine Klausur

The five verification pillars

Each pillar points to its proof: an architecture decision (ADR) or verifiable code. No marketing claims without a basis.

Teacher Final Decision

LAURA never assigns an automatic grade. Every assessment is a proposal, and it only becomes final through the teacher’s explicit release. This step is enforced by the architecture, not a checkbox in the settings.

Proof: ADR-0012; deterministic, overridable grade proposal (implemented and tested).

Audit trail with hash chain

Every decision is logged append-only and cryptographically chained via SHA-256. Tampering is not quietly repaired but made visible: the history can be verified independently.

Proof: ADR-0019; verification in apps/worker/audit/verify.py (implemented and tested).

EU data residency

All metadata and processing results live in a dedicated database project in Frankfurt (eu-central-1). Row-Level Security on every table; the school is the hard tenant boundary.

Proof: DEC-019/ADR-0026, ADR-0031; row-level security on every table, enforced for new ones by the ensure_rls event trigger (deployed).

Local-first, controlled processing

Raw media (photos, scans) stay local by default or in school-controlled storage. Which stage applies is your choice: in the default local stage the server actively rejects every upload, and with the Local hosting plan Laura runs entirely on your own servers. Cloud processing happens only after explicit release (opt-in): never silently, never by default.

Proof: ADR-0013/0016/0033; documented processing_mode matrix (local is the default).

Transparency instead of hidden tracking

No advertising trackers, no hidden scanning of student devices: that is anchored in the architecture. Since 13 August 2026 the public website has collected no web analytics at all: the former Google Analytics tag was removed for good. It sat on 183 pages, cost 471 ms of load time per visit and collected zero data points, because consent could structurally never be given. The correction environment never had tracking, and student or exam data were never involved. The consent component deliberately stays in the code: if analytics ever return, they return only together with a visible banner and a dedicated section in the privacy policy.

Proof: ADR-0018 (device scanning), ADR-0022 (lead sandboxes without a backend), DEC-056/ADR-0071 (no web analytics); the coupling is enforced by the no-analytics-without-consent regression test.

Data flows made transparent

Three trust zones, clearly separated. What lives where is not a matter of trust, but of architecture.

Public zone

Vercel: only the static web frontend (apps/web)

No student data, no secrets, no backend, no workers.

Controlled zone

EU database (Frankfurt) and controlled processing

Pseudonym IDs, assessment and audit metadata, protected by auth and Row-Level Security.

Local zone

Teacher’s device / school-controlled storage

Raw media and real-name mapping. They leave the device only after explicit release.

Data classes in brief (K1-K6)

ClassContentWhere it lives
K1Raw media (scans, photos)local / school-controlled, never public
K2High PII (real names)local, encrypted mapping, never in the cloud
K3Metadata + pseudonymsEU database, RLS-protected
K4Audit / hashesEU database, append-only
K5Synthetic / publicwebsite, demos, exclusively synthetic
K6System configuration + secretssecret store, never in the frontend, never in Git

Documents for your review

The status of each document is stated honestly. We list certifications only once they are granted: until then, none appear here.

on request

DPA template

Data processing agreement under Art. 28 GDPR for schools and authorities.

on request

TOM overview

Technical and organisational measures (Art. 32 GDPR).

on request

Processing modes documentation

Documented processing modes (local default / EU self-hosted / cloud opt-in).

in preparation

Records of processing extract

Extract from the records of processing activities (Art. 30 GDPR).

in preparation

DPIA guide

Guide to the data protection impact assessment (Art. 35 GDPR) for schools.

in preparation

Deletion concept

Implementation of the right to erasure (Art. 17 GDPR), including backup retention.

Common review questions

Does LAURA grade automatically?
No. LAURA never assigns automatic grades. Every assessment is a proposal to the teacher; it only becomes final through their explicit release. This step is enforced by the architecture (Teacher Final Decision).
Where does student data live?
Raw media (photos, scans) stay local on the device or in school-controlled storage. The EU database (Frankfurt) holds only pseudonym IDs, assessment and audit metadata, protected by Row-Level Security with the school as the hard tenant boundary. The real-name mapping stays local.
What does the cloud see?
By default: no raw media. Cloud processing is exclusively opt-in and then limited to what is necessary (for example image excerpts of disputed passages, pseudonymised). There is no silent cloud escalation: it is ruled out by the architecture.
What is the hash chain?
Every teacher decision is chained to its predecessor with a SHA-256 hash and stored append-only. Later changes break the chain visibly; the integrity of the entire history can be verified independently.
Is LAURA GDPR-compliant?
LAURA is designed to the GDPR from the ground up: privacy by design and by default (Art. 25), data minimisation (Art. 5), EU data residency, RLS tenant separation, auditable decisions and documented processing modes. We provide the DPA template and TOM overview on request; the formal assessment is made by the school or its DPO, and we supply the documents for it.

Check it yourself instead of taking our word for it

Four small hands-on demos, including: adjusting the confidence thresholds yourself, tampering with an audit log and watching the check catch it, and following how a conflict between two devices is resolved. Everything runs in your browser, with no connection to our servers.

Developer sandbox

Four interactive demos of Laura's core algorithms. Everything runs locally in your browser.

Confusion Matrix

Laura learns from your edits. Here you can see how the most frequent confusions are reduced.

  • a→o
    18.0 %
  • e→c
    14.0 %
  • n→m
    21.0 %
  • h→k
    9.0 %
  • u→v
    11.0 %

Green Word Precision

62.0 %/ target 98 %

A direct line for data protection questions

No forced form: one email is enough. We reply with the requested documents, and send nothing without your explicit confirmation (double opt-in).

datenschutz@laura.school