Trust Center

Your data. Your institution. Your rules.

This page documents what FERPA-compliant exam monitoring looks like in practice: the institution owns and controls the data, not us. Everything here exists to let your security, privacy, and procurement teams verify that.

Capture with consent, present to humans.

That sentence is the whole Nigel doctrine. Every stream of evidence exists because a student consented to it, and every conclusion drawn from that evidence is drawn by a person your institution authorized. Policy is enforced through consent and transparency, not through control of the student's machine.

No lockdown, no auto-suspension, no scoring

Nigel never takes over the browser, never ends a session on its own, and never applies behavioral scoring. These practices are rejected by design, not just left unimplemented.

Students can always disengage

A student can stop sharing, step away, or leave focus mode at any moment. The consequence is an amber flag for human review, never a block, a lockout, or an automatic penalty.

Evidence is for human reviewers

Evidence packages exist so a trained person at your institution can see what happened and decide. AI surfaces moments for review. It never renders verdicts.

Receipts, not trust-us

Every session closes with a cryptographic receipt of what was captured, what the student consented to, and what was flagged. Students and institutions share the same tamper-evident record.

Data ownership, stated plainly.

Your institution owns all assessment recordings, evidence records, flags, and review decisions processed through Nigel. We process that data solely on your behalf and under your direction, keep it only as long as you configure, and delete or return it when you say so. We claim no ownership interest in institutional data, and we never sell it or use it for any purpose beyond the service you contracted.

FERPA: School Official Model

Nigel Integrity is designed to support FERPA-compliant exam monitoring under the school official model. Your institution maintains control of all student education records. We process data on your behalf, under your direction, subject to your policies.

No secondary use

Student data is used to deliver the service you configured. Nothing else. No model training on student records, no analytics products, no exceptions.

No sale of data

We do not sell, rent, or share student education records with third parties. Full stop.

Institution-controlled retention

You set the retention schedule for exam evidence. We enforce it automatically and certify deletion.

How AI is used, and how it is not.

Nigel uses AI to surface potential integrity concerns for human review. AI analysis is provided in part through Anthropic's Claude models under contractual data protection obligations.

No training on your data

Nigel does not use institutional assessment recordings to train AI models, and our AI sub-processor is contractually restricted from doing so.

Humans decide, always

AI output is an advisory flag with visual evidence attached. No flag results in any action against a test taker without human review.

No behavioral scoring

The AI looks for objects and events in the environment. It never scores faces, emotions, keystrokes, or behavior patterns.

Screen awareness

Nigel supports screen awareness through voluntary, consent-based screen sharing using getDisplayMedia, the W3C Screen Capture API. At the start of an assessment the student explicitly chooses what to share, a screen, a window, or a tab, through the browser's own native picker, the same way they would in a video call. This is consent-based screen sharing, not full desktop recording and not lockdown. Nigel records the shared content together with tab visibility events, webcam, and 360 degree room coverage into a single evidence timeline.

The student can revoke sharing at any time. The consequence is a flag for human review, never a block. All screen-related signals are presented to authorized institutional reviewers. Nigel does not lock the browser, restrict other applications, disable system functions, auto-suspend sessions, or apply behavioral scores. The institution retains full control over interpretation and any subsequent action.

Environment and device integrity

Nigel surfaces potential integrity issues related to the testing environment so institutions can apply their own policies. All signals come from the exam browser tab and, where enabled, the room camera. Nothing else is monitored. All signals are presented with supporting evidence for human review. No automated penalties are applied.

What is monitored

  • Additional displays or devices visible during the room camera scan.

  • Whether the exam tab loses focus, and whether the active tab navigates to a known AI assistant site during the exam window.

  • Materials or objects in the room the institution has not marked as permitted.

  • People or activity in the room not present at session start.

What is not monitored

  • Keystrokes or typing patterns.

  • The content of other browser tabs, applications, or files.

  • Facial recognition, emotion scoring, or behavioral biometrics.

  • Anything outside the active exam session.

  • A student's installed browser extensions. Nigel does not, and will not, request permission to see them.

Accommodations

A second display, assistive technology, or alternate input device configured through a student's disability services office is never treated as a flag. Accommodations are set before the exam, not litigated after it.

All environment and device signals remain advisory. The institution decides how each flag is interpreted and what action, if any, is taken.

AI assistants

Nigel can flag when the active exam tab loses focus, or when a student's browser navigates to a known AI chat assistant during an assessment window. This is a tab-level signal, not a scan of installed software. Detection is limited to the assessment window and is designed to provide evidence for institutional review, not to score students or trigger automatic consequences.

Want the plain-language version? The Students page walks through exactly what is captured during an exam, step by step, and what never is.

What students see

What Nigel does not do.

No browser lockdown

No forced single-monitor or OS restriction

No automated suspension or automated academic decisions

No behavioral scoring or black-box risk scores

No continuous forced desktop access without ongoing consent

Definitions, in plain language.

When a faculty senate, student government, or review board asks what these words actually mean, this is the answer. These are commitments, and the product is built to match them.

Behavioral scoring

An algorithm grading how a person behaves: gaze, keystroke rhythm, posture, face position, converted into a suspicion score.

Nigel does not do this. Anywhere, in any tier.

Object and event detection

Computer vision identifying concrete things in the environment: a phone, a second display, an additional person, a pair of headphones.

This is what Nigel's AI does. Every detection is an advisory flag for a human reviewer.

Tab visibility signal

A log entry recording whether the exam tab is active, with a timestamp.

A fact about the session, not a judgment about the student. It is never scored.

Additional person flag

A detection that someone beyond the test taker is in frame.

Presence-based only. Nigel performs no facial recognition and no identity matching against any database.

Audio

Sound from the exam room.

Not captured and not analyzed. No voice analysis, no stress analysis, no exceptions.

Room capture

Video of the exam environment from the webcam or 360 camera.

Recorded only with the student's up-front consent under the policy tier the institution publishes, with a live indicator whenever capture is active.

Sub-processors.

We keep the list short on purpose. These are the vendors that touch service data, what they do, and where they process it. Institutional agreements include notice provisions for sub-processor changes.

VendorPurposeProcessing location
AnthropicAI analysis (Claude models)United States
VercelApplication hostingUnited States
SupabaseDatabase and storageUnited States
CloudflareDNS, content delivery, and evidence object storage (R2)United States
RailwayAPI hosting: session records, evidence processing, and review servicesUnited States (US East)
LiveKit CloudLive proctoring media relay (real-time video during a session; not the evidence store)United States
Google WorkspaceTransactional email: sign-in links and account notificationsUnited States

How your data is protected.

Encryption in Transit

All data transmitted over TLS 1.3. Video streams over encrypted WebSocket connections.

Encryption at Rest

All stored evidence encrypted using AES-256.

Access Controls

Role-based access. Only authorized reviewers at your institution can view session evidence.

Data Residency

Evidence is stored in your designated region. US institutions' data stays in the US.

You decide. We execute.

Every policy that touches student data belongs to the institution. Our job is to carry it out, reliably and provably.

Retention policies

You set how long evidence is kept. We enforce it.

Access policies

You define who can review. We enforce it.

Deletion

You request deletion. We execute within 30 days and certify it. On termination, data is returned or deleted at your direction.

Security program and procurement resources.

What your security review will ask about, answered up front. Every item below is available in more depth through security@nigelintegrity.com.

Incident response

A documented incident response plan covers detection, containment, and remediation. Affected institutions are notified without undue delay, with a target of 72 hours or sooner where law or contract requires.

Responsible disclosure

Security researchers are welcome. Report suspected vulnerabilities to security@nigelintegrity.com. We acknowledge reports promptly, do not pursue good-faith research, and credit researchers who wish to be named.

Penetration testing

Independent third-party penetration testing is scheduled alongside our SOC 2 Type II audit. Executive summaries will be available to customers under NDA.

SSO and SAML

Reviewer access supports institutional single sign-on via LTI 1.3 launch today. Direct SAML 2.0 sign-on for the review console is on the near-term roadmap.

DPA template

A standard data processing agreement, including FERPA school official terms and GDPR processor terms, is available for procurement review and counsel redline.

HECVAT

A completed HECVAT is in preparation for higher education vendor assessment. Until it ships, we answer institutional security questionnaires directly.

Compliance roadmap.

SOC 2 Type II

In Progress

FERPA

Designed to support FERPA-compliant institutional use

WCAG 2.1 AA

Product Accessibility

LTI 1.3

Integration

Security questions? Vendor assessment? DPA request?

Our team responds directly. No ticket queue for security matters.

security@nigelintegrity.comDownload the procurement one-pager (PDF)

Ready to see it in action?

Walk through the reviewer console, the evidence chain, and the institution controls with our team.