Sikgen AI
Security & Privacy

Your institution's data is yours — and it stays that way

Sikgen AI is built from the ground up with per-tenant isolation, encrypted transmission, and modern authentication — so you can deploy with confidence.

Security Architecture

How we protect your data

Per-tenant data isolation

Every institution's data lives in a dedicated logical store. No cross-tenant data leakage is architecturally possible.

JWT authentication + HTTPS

All sessions authenticated via JSON Web Tokens. All traffic encrypted with TLS 1.2+ enforced. Cookies are HttpOnly and SameSite=Strict.

Rate limiting & brute-force protection

All authentication endpoints rate-limited. IP-based throttling prevents credential stuffing and brute-force attacks.

PostgreSQL with encrypted backups

Transactional PostgreSQL database with daily encrypted backups and point-in-time recovery. Data retained per contractual terms.

.NET 10 hardened infrastructure

Built on the latest .NET runtime with security middleware, CORS policies, input sanitisation, and SQL injection prevention via parameterised queries.

OWASP Top 10 mitigations

Security controls mapped to OWASP Top 10: no eval(), parameterised DB queries, Content-Security-Policy headers, CSRF tokens on state-changing forms.

How AI processing handles your content

Sikgen AI is a retrieval-augmented (RAG) system, not a model trained on your material. Your documents are ingested, split into passages and indexed as embeddings scoped to your tenant. When a student asks a question, the relevant passages from your content are retrieved and passed to a language model as context for that single answer.

Two consequences worth being explicit about. First, answers cite the source passage they came from, so a teacher can verify them. Second, because retrieval is scoped to your tenant, one institution's content is never used to answer another institution's question.

We do not use institution or student data to train general models. Content is processed to serve your users and for no other purpose.

Compliance & data processing

For institutional customers operating under GDPR (EU/UK), India's Digital Personal Data Protection (DPDP) Act, or other data-protection regulations, we offer a Data Processing Agreement (DPA) as part of the Enterprise plan contract. The DPA covers processing purposes, sub-processor obligations, breach notification, and your rights as controller.

Student data is retained only as long as the contract requires. On termination, data is exported and deleted within 30 days of your written request.

Hosting region, the current sub-processor list, and incident-notification terms are confirmed in writing as part of the DPA before contract signature, so you can review them against your own obligations rather than take a marketing page's word for it. If you need them earlier — for a procurement questionnaire or a supplier-risk review — ask and we will send them ahead of any commitment.

What we don't claim

Sikgen AI is not currently SOC 2 Type II certified, ISO/IEC 27001 certified, or FedRAMP authorised. Nor is any vendor "GDPR certified" — that is not a certification that exists, whatever a supplier's website says.

The architecture described above is designed to support GDPR and DPDP obligations, and we sign a DPA that commits us to them contractually. If your procurement process requires an independent audit report as a hard gate, we would rather tell you now than three months into an evaluation.

If certification status changes, this page changes with it.

WhatsAppBook Free Demo