TrustApache 2.0 · GDPR · EU residency · Self-host

Security & trust.

How Noplag protects your data, the compliance posture your IT and procurement teams need, and where every report comes from. Built to be auditable, not just asserted.

COMPLIANCE POSTURE

What your security review will ask for.

Each item here is something a procurement or information-security team checks off. We keep them ready so the review moves.

Auditable

Apache 2.0 engine

The detection pipeline is open source — your reviewers read the data flow in code, not slideware.

DPA ready

GDPR + UK GDPR

Data-processor terms, EU residency, and a signable Data Processing Agreement.

Covered

FERPA

School-official terms under your institution's existing LMS agreement.

Available

EU data residency

Default EU infrastructure; pin processing to an EU endpoint or self-host so data never leaves the EEA.

24h

Right to erasure

Delete your account and every fingerprint, hash, and report is gone within 24 hours — verifiable.

Built to

WCAG 2.1 AA

Built to WCAG 2.1 AA, including the in-LMS report panels.

HOW WE PROTECT YOUR DATA

Six controls, all auditable.

Nothing here is a marketing claim you have to take on trust — each control is visible in the engine code, the DPA, or a report you can request.

Encryption everywhere

Encrypted in transit (TLS 1.3) and at rest. Keys are managed and rotated; no document sits in plaintext at rest.

Least-privilege access

Role-scoped access with full audit logging. Production access is reviewed, time-bound, and logged per action.

EU residency or self-host

Pin processing to an EU-residency endpoint, or run the Apache 2.0 engine entirely inside your own VPC.

Never trained on

Submitted documents are never used to train any model — ours or anyone else's. Contractual, restated in every DPA.

Reproducible reports

Every report stamps the engine commit and corpus snapshot, so a verdict reproduces exactly months later.

Right to erasure

Delete your account and every fingerprint, document hash, and report is gone — within 24 hours.

24herasure SLA
EUresidency available
Apache 2.0auditable engine
0documents trained on
30-daycontent purge
DATA FLOW

What happens to a document you check.

Four steps from submission to purge. Each one is constrained by the controls above.

01

Submit

Your text or file arrives over TLS and lands in your tenant, isolated from every other customer.

02

Fingerprint + match

Text is reduced to non-reversible winnowing hashes and matched against the corpus. The model never sees it as training input.

03

Report

You get a per-interval report stamped with the engine commit and corpus snapshot that produced it — reproducible later.

04

Purge

Document content is purged on your retention schedule, 30 days by default. Erasure removes the fingerprints too.

FOR YOUR SECURITY REVIEW

We pre-package what your reviewers ask for.

Information-security and procurement reviews ask the same questions: where does the data go, what is the matching algorithm doing, can you delete everything, and where does it live. We answer with a data-flow diagram, the current sub-processor list, and a signable DPA — and because the engine is Apache 2.0, your team verifies the data flow by reading the code rather than taking it on trust. We're a relaunching open-core company, so formal attestations like SOC 2 are on our roadmap rather than in hand; the open-source engine is the stronger answer in the meantime, and research-data offices that had refused new plagiarism vendors have cleared this one for exactly that reason.

Read the institutional-review packet
Security review packet
FLOWA diagram of exactly what crosses the boundary and what stays inside your tenant.
EUEU-residency endpoint so personal data stays in the EEA; default EU infrastructure.
ON-PREMRun the Apache 2.0 engine inside your own VPC — nothing leaves your network.
ERASURERight-to-erasure cascades to fingerprints and reports within 24 hours.
DPAGDPR-compliant Data Processing Agreement, signable.
OSSApache 2.0 engine — your IT reads the data flow in code, not slideware.
FAQ

What security and procurement teams ask.

Can our IT audit the detection engine?
Yes — github.com/NoplagLabs/noplag-engine, Apache 2.0. The full pipeline (winnowing fingerprints, MinHash LSH, vector reranking, Binoculars AI detection) is readable line by line, so your reviewers verify what's checked, against what corpus, at what thresholds — rather than taking it on trust.
Are you SOC 2 certified?
Not yet — we're relaunching as an open-core company, and SOC 2 is on the roadmap rather than in hand. We don't claim it. What we offer in its place is stronger for a review: an auditable Apache 2.0 engine your team reads directly, EU residency or full self-host, a signable DPA, and the controls documented on this page.
Where is our data processed?
EU by default. Paid plans can pin processing to an EU-residency endpoint so data stays in the EEA, and enterprise customers can self-host the engine entirely inside their own VPC.
Are our documents used to train AI?
Never. Submitted documents are not used to train detection models, language models, or anything else. It's a contractual commitment, restated in every DPA, not just a policy line.
How fast is right-to-erasure?
Dashboard-visible records are removed within 24 hours; the full purge across the corpus index and fingerprint store completes within 30 days. Deleting your account triggers the same cascade.
Can we self-host the whole stack?
Yes — the engine is Apache 2.0 + Docker and runs inside your network with no required outbound traffic beyond the corpus refresh you schedule. Pair with self-hosted Moodle for a fully on-prem deployment.

Get the security packet. Or read the code.

Request the data-flow diagram, sub-processor list, and signable DPA — or skip the packet and audit the Apache 2.0 engine yourself. Either way, the review is a verification, not a leap of faith.

Security & trust — Noplag