Security
Security and data processing
CavenX protects U.S. institutional data with encryption, access controls, and international data-processing safeguards. Platform services are hosted in India, and the institutional agreement documents the applicable protections.
Last updated: June 27, 2026
Security is not a feature we bolt on — it is the foundation of deploying AI inside schools, universities, and colleges. This policy describes how we protect institutional data, student data, faculty research, and communications across the platform.
1. End-to-End Encrypted Communications
All communication between students, teachers, and non-teaching staff through CavenX channels and rooms is end-to-end encrypted by default — the same class of protection users expect from WhatsApp and Telegram.
- Default E2E: Messages, files, and media in channels and rooms are encrypted on the sender's device and decrypted only on recipients' devices.
- Institutional boundaries: Encryption keys are scoped per institution. CavenX cannot read message content in E2E channels and rooms.
- Every role covered: Students, teachers, faculty, and non-teaching staff — same default protection across all room types.
- Metadata minimization: We collect only the metadata required to deliver and secure the service — not message content from E2E communications.
2. Data Processing and Residency
CavenX is India-based, and platform services are hosted in India. International data flows, subprocessors, retention, and safeguards are addressed in CavenX’s Privacy Policy and institutional agreements.
- International processing and transfer safeguards are documented for institutional deployments
- CavenX complies with applicable FERPA and COPPA requirements for U.S. school deployments
- Institutions retain ownership of their data under the applicable agreement
3. Encryption & Infrastructure
- In transit: TLS 1.3 for all connections
- At rest: AES-256 encryption for stored institutional data outside E2E message content
- Access controls: Role-based access, SSO integration, principle of least privilege
- Network security: Firewalls, intrusion detection, DDoS protection, 24/7 monitoring
- Availability: 99.9% uptime SLA for production services
4. AI Zero-Training Guarantee
Institutional data, student inputs, faculty research, and AI outputs are never used to train public AI models — contractually guaranteed with every model provider on the CavenX platform.
- Per-institution data isolation for AI workloads
- Per-faculty research isolation on higher-ed deployments
- No sale of institutional or student data to third parties
- Institutions retain absolute ownership of their data — CavenX claims no rights
5. U.S. Privacy and Student-Data Safeguards
CavenX complies with applicable FERPA and COPPA requirements for U.S. school deployments and FERPA requirements for universities. Data roles, international processing, and safeguards are described in the Privacy Policy and institutional agreement.
6. Compliance & Operations
- SOC 2 Type II: Annual third-party audits covering security, availability, and confidentiality controls
- Penetration testing: Regular third-party assessments
- Incident response: Documented process with institutional notification for material incidents
- Employee security: Background checks, security training, least-privilege access
- Vulnerability disclosure: Report issues to security@cavenx.com
Contact
Security questions or vulnerability reports: security@cavenx.com
General inquiries: hello@cavenx.com