Download or print this trust center for your procurement team. DPA Template Privacy Policy Security Questionnaire

Trust Center

Security, privacy, compliance, and operational controls for Procta AI exam proctoring. Updated June 2026.

1. Product Overview

Procta is an AI-proctored exam platform for educational institutions. The platform consists of:

2. Security Controls

2.1 Data in Transit

2.2 Data at Rest

2.3 Authentication

2.4 Application Security

2.5 Infrastructure Security

3. Privacy & Data Retention

Data TypeRetention PeriodDeletion Mechanism
Exam screenshots90 daysAutomatic cleanup on startup + every 6 hours
Phone camera frames24 hoursRedis TTL expiry
Violation logs1 yearAccount deletion anonymizes
Exam answers & scoresDuration of accountAccount deletion anonymizes
Audit trails1 yearAccount deletion anonymizes
Student account dataDuration of accountSelf-service export & deletion via Privacy Center
LTI learner dataLMS-managedGoverned by institution's LMS privacy policy

3.1 Data Processing

3.2 Data Subject Rights

Students and teachers can exercise rights via the Privacy Center:

3.3 Compliance Frameworks

4. Subprocessors

ProviderServiceDataLocation
SupabasePostgreSQL database, authentication, storageAll student & exam dataAWS ap-south-1 (Mumbai)
DigitalOceanApplication hostingNone (ephemeral compute)BLR1 (Mumbai)
RedisIn-memory cache, session state, frame bufferSession tokens, live frames (no persistent storage)Co-located with application
Groq / LLM providerAI grading suggestionsQuestion + answer text (zero-shot, no training)Configurable (default: US)
RazorpayPayment processing, subscriptionsBilling data onlyIndia
Email providerTransactional email (invites, notifications)Email address, nameConfigurable

5. Incident Response

  1. Detection — Automated alerts via Sentry error tracking (error rate >5%, authentication anomalies). Infrastructure monitoring via health check endpoint (30s interval).
  2. Classification — Severity levels: Critical (data breach, service outage), High (degraded performance, auth failures), Medium (non-critical bugs), Low (cosmetic issues).
  3. Response — On-call engineer notified via Sentry/PagerDuty integration. Incident reviewed within 15 minutes for critical severity.
  4. Containment — Rollback via docker compose up -d --no-deps api (previous image retained in GHCR). Database snapshots via Supabase point-in-time recovery.
  5. Recovery — Full deploy pipeline: restore from last passing CI build, run migrations, health check, smoke test. Target: 30-minute RTO.
  6. Post-mortem — Root cause analysis documented, preventive measures added to CI/test suite, deploy checklist updated.

6. Sample Scorecard

A sample exam scorecard (PDF) includes:

7. Downloads

Save these documents for your procurement and compliance teams.

Data Processing Addendum (DPA) Privacy Policy Security Questionnaire (CAIQ-Lite) Privacy Center (self-service)

Questions? Contact security@procta.net