calendar
Published on August 7, 2026

How Coursebox keeps your data safe

I answer the questions enterprise buyers actually ask me about how Coursebox handles their data, in plain language.

Toni Arrebola
Toni Arrebola
Chief Technology Officer

I'm the CTO of Coursebox AI, so I sit in a lot of enterprise demos and across most of them I always get the same question: can I trust you with our data?

That's fair. When the courses you're building hold your company's proprietary knowledge, your learner records and your training IP, you should know exactly where all of it lives and who can touch it. So rather than bury the answers in a policy document, here are the questions we actually get, answered plainly.

Does Coursebox use my data to train AI models?

No, we run Microsoft Azure OpenAI and Google Gemini under enterprise agreements. Both Microsoft and Google state that customer prompts, inputs and generated outputs aren't used to retrain their public models. That's in the contract, not a footnote. Our own policy is the same: your content and learner data are not used to train or fine-tune Coursebox models, unless you explicitly agree to it in writing for a defined purpose.

For AI video generation through HeyGen, we got it in writing in February 2026 that our enterprise API account is fully opted out of every model training pipeline.

Your content generates responses for your learners. That's all it does.

Where is my data hosted?

Since May 2026, every new Coursebox portal runs on Google Cloud Platform. We're moving off our old OVH France infrastructure to give clients a stronger compliance foundation.

GCP data centres are certified to ISO 27001, ISO 27017 and ISO 27018. The default region is France, so EU clients get intra-EU storage without asking for it. If your organisation has its own geographic or data residency requirements, you can pick a different GCP region.

One thing worth saying plainly: AI processing through Azure OpenAI runs in US regions by default, under Standard Contractual Clauses and a transfer-impact assessment. EU-region AI processing is available where you need it. If you need hosting or processing in a particular country, talk to your Coursebox account manager or reach out to support@coursebox.ai

How is my data encrypted?

Data at rest is encrypted with AES-256, managed by Google Cloud. Data in transit uses TLS 1.2 or higher. Passwords are hashed with bcrypt and never stored in plain text.

Backups are encrypted too. Daily backups are retained for 14 days by default, with a recovery point objective of 24 hours and a recovery time objective of 12 hours. Enterprise accounts on a dedicated database get point-in-time recovery, retention extendable to 30 days, and tighter targets of under an hour for RPO and under four hours for RTO.

Is my organisation's data isolated from other customers?

Yes but how we do it depends on your plan.

Most accounts run on a multi-tenant architecture. Your data, your configurations and your API keys belong to your organisation alone, and the system enforces that no other tenant can see, touch or reach them. Enterprise customers who want separation at the infrastructure level rather than enforced separation within a shared system can run on a dedicated instance with its own entirely separate database.

In plain terms, think of an apartment building. Most tenants share the building, which is the infrastructure, but your apartment is yours and so is the lock. A dedicated instance is your own building.

Which AI and data providers does Coursebox use, and what do they do with my data?

Here's every AI provider in the platform and what it does.

Microsoft Azure OpenAI handles course generation, AI writing, quizzes and the AI tutor chatbots. It's processed inside Azure's enterprise infrastructure, and Microsoft doesn't use customer data for model training.

Google Gemini Pro generates the AI images in course materials. Prompts go through the API and the outputs stay in your Coursebox environment. Google doesn't use customer data for model training.

Microsoft Azure Neural Text-to-Speech turns course text into voiceovers. That audio is processed inside Azure and isn't used to retrain public models.

Mistral pulls text and embedded images out of documents you upload, PDFs and the like. What it extracts stays in our own infrastructure on Google Cloud.

HeyGen powers the AI avatar video. As above, our enterprise account is opted out of every HeyGen training pipeline, confirmed in writing in February 2026.

Plain AI, running on Anthropic Claude, powers our support chatbot for administrators. Under Plain AI's and Anthropic's enterprise terms, customer data isn't used to train public foundation models.

Is Coursebox GDPR compliant?

dev team at Coursebox AI

Yes. Coursebox Pty Ltd has been formally assessed and certified for GDPR compliance by American Quality Standards Registrars (AQSR), which is accredited by the United States Accreditation Council (USAC).

The certificate details:

  • Certificate number: 17412
  • Date of registration: 11 June 2025
  • Re-certification date: 10 June 2028

You can check it yourself at www.aqsrworld.com using certificate number 17412.

We also comply with the Australian Privacy Principles, and we hold every client to the same data protection standard wherever they are, not only in the EU.

What happens if there is a security breach?

We have a documented incident response process with four steps. Containment, impact assessment, client notification, then a post-incident review.

Timelines are set by severity. Critical incidents like unauthorised access or data loss go to affected clients within 4 hours of detection. High-priority potential compromises within 12 hours. Lower-priority vulnerabilities within 24 hours. A full written report follows within 5 business days of resolution. For enterprise clients we can commit to notification within 8 business hours as part of the enterprise agreement.

We've had no successful security incidents and no data breaches in the past 12 months.

How does Coursebox protect against AI-specific threats like prompt injection?

We run Microsoft Azure AI Content Safety, which includes Prompt Shields. Those catch prompt injection attempts and block them before they reach the model. On the way back out, Azure OpenAI and Gemini both apply content filtering that stops malicious code, hate speech and harmful content before it reaches your users.

We rate limit our login and generation endpoints so brute-force attempts don't get far, and we watch API usage at the gateway layer for unusual spikes.

Input text is validated and structured by our application back-end before any model sees it.

What about AI hallucinations?

Hallucination is built into how large language models work. We can't eliminate it. What we can do is narrow the room it has: we anchor generations tightly to the course parameters and learning objectives you give us, apply system-level constraints, and run low inference temperatures for consistency.

The bigger safeguard is human review. Every piece of AI-generated course content passes through a person before learners see it, and the course author can edit any of it. We built the platform so a human makes the final call.

Does Coursebox have an uptime guarantee?

Yes, your learners need reliable access, so we hold a 99% uptime Service Level Objective.

Coursebox runs primarily on Google Cloud Platform, with Amazon Web Services covering supporting services in EU regions. Two things about that infrastructure do most of the work.

The first is redundancy. Google spreads workloads across multiple physical data centres, so if a server or a whole data centre goes down, another picks it up and your learners don't notice.

The second is live maintenance. Google can run routine updates and hardware fixes without taking our servers offline, which removes most of the reasons for unexpected downtime.

Our disaster recovery sits on top of that. Backups run continuously and are stored across geographically separate locations. In a worst-case regional outage, we can bring up a fresh copy of our infrastructure in a different region within minutes.

Is Coursebox independently tested for security vulnerabilities?

Yes. We run third-party penetration testing annually. The most recent test finished in June 2026.

Can my organisation turn off specific AI features?

Yes. Some AI features are optional and can be configured or switched off at the enterprise level to suit your compliance requirements. Enterprise clients can also bring their own OpenAI API key and run their own model configuration.

We keep the ability to restrict or suspend any AI integration where legal, security or compliance reasons call for it.

Does Coursebox have an AI governance policy?

Yes. We assess AI features for likely harms before they ship, apply change controls to material AI updates, keep internal documentation proportionate to each feature's risk, and run channels for customers to report AI quality or safety issues. Our Responsible AI policy follows the NIST AI Risk Management Framework, the OECD Recommendation on Artificial Intelligence, UNESCO's Recommendation on the Ethics of Artificial Intelligence, and Australia's Voluntary AI Safety Standard.

The EU AI Act's transparency obligations apply from 2 August 2026. From that date we'll show a contextualised AI note wherever learners interact with an AI feature, and on AI-generated video.

I know a list of policies doesn't always feel reassuring. What I can tell you is that the decisions behind the list, moving to Azure OpenAI, choosing Google Cloud for hosting, opting out of every vendor training pipeline we could find, weren't made because a compliance checklist told us to. They were made because clients asked us hard questions and we wanted to answer them honestly.

If your question isn't here, email us at support@coursebox.ai. We'd rather you asked than wondered.

Toni Arrebola

Toni Arrebola

Chief Technology Officer

Software engineer and SaaS product builder