Security / Institutional review

Security controls for institutional assessment workflows

Assessment data requires careful handling. PaperGrader documents its security and privacy controls so institutional teams can evaluate access, isolation, encryption, auditability and the data-processing context for their own deployment.

For technology, procurement and data-governance reviewers.

Use this page as a starting point for security and privacy review. Requirements vary by institution, deployment and data classification, so detailed documentation and contractual terms should be considered separately.

Answer scripts and grade records need controls across the full workflow.

A secure assessment process involves more than storing a file. Institutions need to consider role-based access, tenant isolation, encryption in transit and at rest, audit information, retention and the services involved in processing the document and rubric context.

How the evaluation workflow operates

  1. 01

    Control access

    Assign user access according to institutional roles and the tasks each role is authorised to perform.

  2. 02

    Separate institution data

    Use tenant-aware access controls so one institution's workflow does not expose another's records.

  3. 03

    Protect data in transit and at rest

    Apply transport and storage protections appropriate to the system and deployment configuration.

  4. 04

    Record privileged activity

    Keep an audit record for relevant review, approval and administrative actions.

  5. 05

    Review deployment specifics

    Evaluate retention, subprocessors, integrations and contract requirements with the institution's own governance team.

Security review remains deployment-specific.

Public documentation describes the product posture; it is not a substitute for an institution's own risk assessment. Teams should assess the data categories, hosting, retention, integrations and contractual safeguards relevant to their deployment.

Operational benefits

  • Role-based access for assessment responsibilities
  • Tenant-aware data isolation controls
  • Documented security and privacy review paths
  • Auditability for approval and administrative activity
  • Links to data-processing and disclosure information

Continue the evaluation

Discuss your institution's evaluation workflow