PII redaction
Sensitive identifiers (SSN, phone numbers, addresses) are scanned and masked before any LLM call unless role and policy explicitly allow it.
Prompt injection protection
Malicious patterns like "Ignore previous instructions" are detected, flagged, and routed through hardened safe-handling paths.
Content moderation
All AI outputs pass through moderation before display or storage. Policy outcomes are logged for audit and compliance review.
Age-appropriate safeguards
Guardrails adapt by key stage or year group. Students under 13 require verified parent linkage. FERPA and COPPA compliance built in.
Role-based AI access
Students cannot access teacher-only AI features like grading assist or answer keys. Server-side role checks enforce boundaries.
Token limits and oversight
Hard caps on input tokens prevent abuse. Oversized requests are rejected with clear feedback. All usage is logged and auditable.