Security & trust.
How Noplag protects your data, the compliance posture your IT and procurement teams need, and where every report comes from. Built to be auditable, not just asserted.
What your security review will ask for.
Each item here is something a procurement or information-security team checks off. We keep them ready so the review moves.
Apache 2.0 engine
The detection pipeline is open source — your reviewers read the data flow in code, not slideware.
GDPR + UK GDPR
Data-processor terms, EU residency, and a signable Data Processing Agreement.
FERPA
School-official terms under your institution's existing LMS agreement.
EU data residency
Default EU infrastructure; pin processing to an EU endpoint or self-host so data never leaves the EEA.
Right to erasure
Delete your account and every fingerprint, hash, and report is gone within 24 hours — verifiable.
WCAG 2.1 AA
Built to WCAG 2.1 AA, including the in-LMS report panels.
Six controls, all auditable.
Nothing here is a marketing claim you have to take on trust — each control is visible in the engine code, the DPA, or a report you can request.
Encryption everywhere
Encrypted in transit (TLS 1.3) and at rest. Keys are managed and rotated; no document sits in plaintext at rest.
Least-privilege access
Role-scoped access with full audit logging. Production access is reviewed, time-bound, and logged per action.
EU residency or self-host
Pin processing to an EU-residency endpoint, or run the Apache 2.0 engine entirely inside your own VPC.
Never trained on
Submitted documents are never used to train any model — ours or anyone else's. Contractual, restated in every DPA.
Reproducible reports
Every report stamps the engine commit and corpus snapshot, so a verdict reproduces exactly months later.
Right to erasure
Delete your account and every fingerprint, document hash, and report is gone — within 24 hours.
What happens to a document you check.
Four steps from submission to purge. Each one is constrained by the controls above.
Submit
Your text or file arrives over TLS and lands in your tenant, isolated from every other customer.
Fingerprint + match
Text is reduced to non-reversible winnowing hashes and matched against the corpus. The model never sees it as training input.
Report
You get a per-interval report stamped with the engine commit and corpus snapshot that produced it — reproducible later.
Purge
Document content is purged on your retention schedule, 30 days by default. Erasure removes the fingerprints too.
We pre-package what your reviewers ask for.
Information-security and procurement reviews ask the same questions: where does the data go, what is the matching algorithm doing, can you delete everything, and where does it live. We answer with a data-flow diagram, the current sub-processor list, and a signable DPA — and because the engine is Apache 2.0, your team verifies the data flow by reading the code rather than taking it on trust. We're a relaunching open-core company, so formal attestations like SOC 2 are on our roadmap rather than in hand; the open-source engine is the stronger answer in the meantime, and research-data offices that had refused new plagiarism vendors have cleared this one for exactly that reason.
Read the institutional-review packetWhat security and procurement teams ask.
- Can our IT audit the detection engine?
- Yes — github.com/NoplagLabs/noplag-engine, Apache 2.0. The full pipeline (winnowing fingerprints, MinHash LSH, vector reranking, Binoculars AI detection) is readable line by line, so your reviewers verify what's checked, against what corpus, at what thresholds — rather than taking it on trust.
- Are you SOC 2 certified?
- Not yet — we're relaunching as an open-core company, and SOC 2 is on the roadmap rather than in hand. We don't claim it. What we offer in its place is stronger for a review: an auditable Apache 2.0 engine your team reads directly, EU residency or full self-host, a signable DPA, and the controls documented on this page.
- Where is our data processed?
- EU by default. Paid plans can pin processing to an EU-residency endpoint so data stays in the EEA, and enterprise customers can self-host the engine entirely inside their own VPC.
- Are our documents used to train AI?
- Never. Submitted documents are not used to train detection models, language models, or anything else. It's a contractual commitment, restated in every DPA, not just a policy line.
- How fast is right-to-erasure?
- Dashboard-visible records are removed within 24 hours; the full purge across the corpus index and fingerprint store completes within 30 days. Deleting your account triggers the same cascade.
- Can we self-host the whole stack?
- Yes — the engine is Apache 2.0 + Docker and runs inside your network with no required outbound traffic beyond the corpus refresh you schedule. Pair with self-hosted Moodle for a fully on-prem deployment.
Get the security packet. Or read the code.
Request the data-flow diagram, sub-processor list, and signable DPA — or skip the packet and audit the Apache 2.0 engine yourself. Either way, the review is a verification, not a leap of faith.