Trust and diligence

Governance is part of the product story.

Privacy, access, consent and authority, audit evidence, governed AI-assisted planning, typed plans, deployment security and resilience are treated as first-class operating concerns. This page summarizes those controls at a public-safe level without exposing security-sensitive operational detail or overstating market acceptance.

First-level trust position

Evidence-based, deliberately bounded.

This public summary is not a certification or legal opinion. It distinguishes implemented architecture, configurable customer choices, deployment-specific decisions and items requiring independent review.

Current stage: Implementation-ready and available for controlled pilot validation; representative role-based UAT, paid-pilot evidence, reference customers, and market-proven outcome claims remain to be established.

Launch evidence state

PendingEvidence

Representative buyer UAT and attributed launch acceptance remain explicit IMW-07 gates.

Trust topics

What an IT, security or privacy buyer should be able to find quickly.

Privacy and data separation

The public website stays outside the learner data plane.

InsightMatrix.Web is a separately deployable public website. Its normal page rendering does not require the Adaptive Learner operational database, protected object stores or production learner records. Business-contact conversion and optional analytics use separate public provider abstractions and do not create a dependency on protected learner-support records.

Public evidence cue: Public content and commercial contact handling remain separate from protected learner-support records.

Owner
Privacy / Architecture
Source
InsightMatrix.Web Solution Architecture and Requirements v1.0
Effective version
0.7.2-imw07-media-a11y

Access control

Product access is purpose-shaped, not universal.

Adaptive Learner baseline role permissions are refined by tenant, organization, learner assignment, purpose of use, record classification, consent, minor-authority mode, archive state and other applicable policy inputs. Administrative role assignment is catalog-backed and validated server-side. Website role-family language is buyer navigation and does not define product permissions.

Public evidence cue: Menu visibility, routes, queries, commands and background work are intended to use the same canonical permission model.

Owner
Security / Product Governance
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

Consent and authority

Authority is scoped, versioned and reviewable.

Adaptive Learner treats consent and minor authority as governed records with scope, effective dates, review history and differentiated permissions. Access is not inferred from a single guardian flag or a broad role label.

Public evidence cue: Consent and authority state can change visibility and participation without collapsing restricted professional context.

Owner
Privacy / Product Governance
Source
Adaptive Learner Data Architecture v1.0
Effective version
0.7.2-imw07-media-a11y

Audit and evidence

Important actions leave attributable evidence.

Security-relevant and business-governance actions are designed to retain structured audit or provenance records, including access, disclosure, workflow approvals, AI artifacts, imports, exports, restoration and applicable administrative actions.

Public evidence cue: Public trust content describes the evidence posture without exposing internal audit records, exact topology or operational identifiers.

Owner
Governance / Platform Operations
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

AI governance

AI assists. Accountable people review.

AI may assist with drafts, summaries, transcript enrichment, recommendations, explanation, approved SOP/policy retrieval and evidence-informed plan drafting or selected-section refinement. For planning, governed context may include validated assessment results and verified professional findings. AI does not infer or create a diagnosis from test scores, and authoritative publication or high-impact access actions remain behind human review and policy-controlled application boundaries.

Public evidence cue: An approved AI planning proposal can create or amend a support plan only in Draft state; normal review, approval and publication controls still apply.

Owner
AI Governance / Product
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

Typed multi-plan support

Multiple governed plan types can coexist for the same learner.

The current planning baseline supports concurrent versioned General Learner Support, Individual Education Plan (IEP, with IPP as a controlled alias), Individual Transition Plan (ITP), Behaviour Support Plan, and Other / tenant-defined plan types. Tenant-defined plan schemas are versioned and existing plans remain pinned to the schema version under which they were created.

Public evidence cue: Typed plan capability is an implemented product capability; customer outcomes from using it remain a separate evidence question.

Owner
Product / Governance
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

Deployment and security

The production baseline uses an isolated Canadian AWS deployment posture.

The Adaptive Learner production hosting baseline uses Amazon Web Services in a Canadian AWS Region, with application workloads on Amazon EC2 inside an Amazon VPC, PostgreSQL on Amazon RDS for PostgreSQL, and documents or stored artifacts on Amazon S3 with AWS KMS-managed encryption. Customer-specific region and external-provider processing details are confirmed during diligence and contracting. InsightMatrix.Web remains a separate public runtime and does not require Adaptive Learner database credentials for ordinary page rendering.

Public evidence cue: Public material states the approved baseline without exposing credentials, exact topology, logs, vulnerability detail or customer-specific configuration.

Owner
Architecture / Security / Platform Operations
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

Resilience and recovery

Recoverability is treated as an operating discipline.

The baseline requires automated database backup, versioned object storage, protected configuration/secret recovery planning, release-package retention and documented restore procedures. Pilot and Production readiness should include a recorded backup/restore rehearsal appropriate to the deployment. The public website is intended to degrade gracefully when optional providers are unavailable.

Public evidence cue: Recovery evidence and graceful dependency failure are controls; they are not promises of uninterrupted availability.

Owner
Platform Operations / Architecture
Source
Adaptive Learner First-Level Trust FAQ v1.3
Effective version
0.7.2-imw07-media-a11y

Important boundaries

What this page does not claim.

Public trust content is deliberately narrower than an internal architecture or operations runbook. It does not expose secrets, vulnerability detail, internal account names, production identifiers or configurations that would increase attack risk.

  • No claim of achieved certification unless separately evidenced and approved.
  • No promise of uninterrupted availability or absolute security.
  • No public access to learner records, product authentication tokens or protected object storage.
  • No implication that AI can approve, publish, diagnose or grant access autonomously.

Deeper diligence

Use a public-safe contact path for the next question.

Privacy

Questions about website privacy, consent/authority framing or public information handling.

Open privacy contact

Keep the diligence path accountable

Move from public trust content to the right technical conversation.

The website explains the control posture. Detailed implementation, deployment and procurement questions should be handled through the configured diligence path rather than through exposed internal accounts or undocumented claims.