/ /

NovoAI Security, Privacy & Compliance

Updated 25 days ago

Updated July 24, 2026

 

NovoAI Security, Privacy & Compliance

NovoAI refers to the AI features included in NovoEd products that use Traditional Machine Learning or Generative AI. It is created with the same customer-centric approach and under the same governance, privacy and terms of service as other NovoEd features. We hold ourselves accountable to a high standard of transparency with our customers. This document outlines the set of AI models we use today, the scope of data, and your opt-in/out options. It will be updated over time as we work together with our customers to bring scale, ease, efficiency, and creativity to the creation, delivery, measurement, and tracking of high-impact learning experiences on NovoEd. 

NovoAI, as part of our product, is governed by our privacy policy, our GDPR practices outlined in our compliance center, and our company security and governance controls under our SOC 2 Type II certification. NovoAI ensures that user data is encrypted in transit and at rest, and always ensures a logical separation of customer data. 

Compliance & Subprocessors

NovoEd utilizes several AI services and large language models to deliver the capabilities provided through NovoAI. The AI services used by NovoEd are listed in our subprocessor list in our compliance center. These AI models are optional; customers opt into using them by enabling the features that the models power.

Current AI-related subprocessors include: Anthropic (via AWS Bedrock), AWS Bedrock (model hosting and inference, Cohere Embed and Anthropic models), Deepgram (speech-to-text for AI Captions, Practice Insights, and speech-to-text for Voice Roleplay), Azure Cognitive Services (translation), and Inworld (text-to-speech for Voice Roleplay).

Some models, specifically NovoEd’s semantic re-ranking model and prompt-injection security model, run entirely within NovoEd’s own infrastructure. No customer data is transmitted to external parties for these inference steps.


Customer Choice: Opt-in/Opt-out

NovoEd AI hub allows organization admins to turn off one or a collection of the platform's AI capabilities. Disabling these capabilities prevents administrators and end users from seeing them and turns them off across learning experiences. Additionally, several of the NovoAI features can be enabled or disabled at component or course level per discretion and practices of L&D teams.


Usage of AI Models in NovoAI

NovoEd’s AI team works with several AI models, analyzing different aspects of their performance, and selects the best model for the job depending on the type of predictive modeling or generative task at hand. We have outlined the set of AI models NovoAI uses for our current and near-term releases. 


Capability: Speech To Text

Usage: NovoEd uses deepgram to power AI Captions, transcripts, and Practice Insights and real-time speech recognition within Voice Roleplay sessions.

Deepgram is a subprocessor of NovoEd. It does not retain any data sent by NovoEd, does not use this data to train its models, and only accesses data if a support case is opened by NovoEd on a sample file provided with the customer’s permission. 

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Deepgram’s AI Models

AI Captions & Transcripts for Lesson Videos

Customer learning video content uploaded to NovoEd courses

Capability must be enabled for your NovoEd instance.

Deepgram’s AI Models

Practice Insights: Rate of speech, Keyword detection, Filler word detection

Learner videos and audio from the Practice feature

Capability must be enabled at the NovoEd organization level and also enabled by designers at the activity level in a course.

Deepgram’s AI Models

Voice Roleplay: learner speech recognition

Learner audio captured during a voice roleplay session

Must be enabled at the organization level and at the roleplay activity level. Voice mode only.


Capability: Text To Speech

Usage: Voice Roleplay features an AI character that speaks aloud to the learner. NovoEd sends the AI character’s text turn to Inworld to generate natural-sounding speech, which is streamed back and played in the learner’s browser. Inworld offers a set of AI voice personas that map to the characters available in Voice Roleplay (Reed, Bianca, Jake, Chloe, and others). Inworld does not retain customer data for model training..

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Inworld TTS

Voice Roleplay: AI character voice synthesis

AI character dialogue text generated during the roleplay session

Must be enabled at the organization level and at the roleplay activity level.


Capability: AI Translation

Usage: NovoEd makes API calls to Azure AI Translator for automated translation and language detection across two distinct use cases: translating learning content for multilingual courses, and enabling the AI Learning Assistant to understand and respond to learner queries in their native language.

Azure AI Translator is a subprocessor of NovoEd. It does not keep any of the data NovoEd used for translation by NovoEd. No data from NovoEd is used by Azure for developing AI models.

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Azure AI Translator

Automated translation of learning content, course communications, and user-generated content such as discussion or submission comments

  • Learning content in courses

  • Course communications

  • User-generated content such as discussion or submission comments

Shall be enabled at NovoEd instance. Once enabled, it must be enabled at course level as well.

Azure AI Translator

AI Learning Assistant: language detection and query translation for non-English learner questions

Learner query text submitted to the AI Learning Assistant

Controlled by enabling or disabling the AI Learning Assistant at the organization level.


Capability: AI Learning Assistant

Usage: The AI Learning Assistant allows learners to ask questions about course content and receive grounded, sourced answers. NovoEd uses a multi-step pipeline: learner queries are analyzed, course content is retrieved using semantic vector search, and a large language model synthesizes a final answer grounded in that content.

Semantic search is powered by Cohere Embed Multilingual v3, accessed via AWS Bedrock. Course content chunks are embedded and stored in NovoEd’s vector database; learner queries are embedded at query time for retrieval. No raw content is sent to Cohere directly-all embedding inference runs through AWS Bedrock.

Multilingual support: when a learner submits a query in a language other than English, Azure AI Translator detects the language and translates the query before retrieval, then Claude localizes the final answer back into the learner’s language.

Security: a prompt-injection detection model (Meta Llama Prompt Guard) runs entirely within NovoEd’s own infrastructure to screen learner inputs before they reach any external API. No learner data leaves NovoEd for this step.

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Anthropic Claude Models via AWS Bedrock

Query analysis, retrieval decisions, response drafting, and most pipeline steps

Learner query text and retrieved course content excerpts

Must be enabled at the NovoEd organization level. Once enabled, it can be enabled or disabled per course.

Anthropic Claude Models via AWS Bedrock

Final answer synthesis from retrieved course content

Learner query text and retrieved course content excerpts

Cohere Embed Multilingual v3 via AWS Bedrock

Embedding course content for semantic search; embedding learner queries at retrieval time

Course content chunks (at index time); learner query text (at query time)

Controlled by enabling or disabling the AI Learning Assistant at the organization level.

Azure AI Translator

Language detection and query translation for non-English queries; final answer localization

Learner query text

Controlled by enabling or disabling the AI Learning Assistant at the organization level.

Meta Llama Prompt Guard runs on NovoEd infrastructure - no external call

Prompt injection and jailbreak detection on learner inputs

Learner query text, processed entirely within NovoEd’s own servers

Always active when the AI Learning Assistant is enabled. No opt-out; this is a security control.

Capability: AI Roleplay

Usage: AI Roleplay lets learners practice conversations with an AI character in a safe, feedback-rich environment. The feature is available in two modes: text-based (typed turns) and voice-based (spoken turns). Voice Roleplay uses Inworld for both speech recognition and AI character voice synthesis, as described in the Speech To Text and Text To Speech sections.

Roleplay creation is an asynchronous process in which a learning designer provides scenario details and NovoEd generates the full roleplay structure, character brief, and evaluation criteria. Live sessions use a real-time conversational pipeline with parallel LLM calls for character responses, goal tracking, and assessment. Feedback is generated at the end of the session with a detailed evaluation against the learning objectives.

Anthropic models do not ingest NovoEd customer data for any purpose and process it realtime within the boundaries of the task. The content is always chosen with the principle of using what is minimally needed for the specific task the LLM is asked to perform.

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Anthropic Claude Models via AWS Bedrock

AI Roleplay Creation: generating scenario structure, character brief, goals, and content validation

Scenario inputs provided by learning designers; no learner data Must be enabled at the NovoEd organization level.

Once enabled, it can be used by all admins creating content.

Anthropic Claude Models via AWS Bedrock

Roleplay Learner: AI character conversation turns (normal and closing messages)

Learner conversation turns and session context

Must be enabled at the organization level and at the roleplay activity level.

Anthropic Claude Models via AWS Bedrock

Roleplay Learner: goal progress assessment, objection tracking, opening message generation, and end-of-session feedback

Learner conversation turns and session context

Deepgram STT + Inworld TTS

Voice Roleplay: learner speech recognition and AI character voice synthesis

Learner audio and AI character dialogue text during a voice roleplay session

Must be enabled at the organization level and at the activity level. Voice mode only.



Capability: Generative AI in Content Creation

Usage: NovoEd uses Anthropic models on AWS Bedrock across a broad set of content creation tools. Learning Experience Designers make selections in the NovoEd UI, and NovoEd uses professionally crafted, pedagogically sound prompts to generate or analyze content. Anthropic models do not ingest any NovoEd customer data for any purpose other than completing the API call.

Different model tiers are selected based on task complexity. Claude Sonnet handles all generative and reasoning-heavy steps. Claude Haiku handles extraction and OCR tasks where speed and cost efficiency matter. Claude Opus is used for structurally complex document outline extraction in the AI Course Creator ingestion pipeline.

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Anthropic Claude Models on AWS Bedrock

AI-Generated Summaries & Key Takeaways for Learning Experience Designers

Learning content in courses.

Shall be enabled at the NovoEd organization level. Once enabled it can be used by all admins when creating content.

Anthropic Claude Models on AWS Bedrock

AI-Generated Quiz Questions for Learning Experience Designers

Learning content in courses.

Shall be enabled at NovoEd organization level. Once enabled it can be used by all admins when creating content.

Anthropic Claude Models on AWS Bedrock

AI-Generated Discussion Prompts for Learning Experience Designers

Learning content in courses.

Shall be enabled at NovoEd organization level. Once enabled it can be used by all admins when creating content.

Anthropic Claude Models on AWS Bedrock

AI-Generated Assignments: assignment creation and evaluation criteria generation

Learning content in courses; assignment rubric inputs from designers

Must be enabled at the NovoEd organization level.

Anthropic Claude Models on AWS Bedrock

AI-Generated Surveys & Polls

Learning content in courses

Must be enabled at the NovoEd organization level.

Anthropic Claude Models on AWS Bedrock

AI Course Content: outline generation, section drafting, lecture content, course summary, learning objectives, and styling-all major generation steps

Learning content in courses and raw content files uploaded by Learning Experience Designers

Must be enabled at the NovoEd organization level. Once enabled, it can be used by all admins when creating content.

Anthropic Claude Models on AWS Bedrock

AI Course Content: text and data extraction from uploaded images, PDFs, Word documents, and PowerPoint files

Raw content files uploaded by Learning Experience Designers

Controlled by enabling or disabling the AI Course Content capability.

Anthropic Claude Models on AWS Bedrock

AI Course Content: structured outline extraction from complex uploaded documents

Raw content files uploaded by Learning Experience Designers

Controlled by enabling or disabling the AI Course Content capability.



Capability: Generative AI for Facilitation & Peer Learning

Usage: NovoEd uses AI to help learners and facilitators get more value from course discussions. Discussion content is analyzed with traditional machine learning models running on NovoEd’s own infrastructure, and a large language model is used only for the final text generation step.

Semantic similarity and diversity analysis for discussion posts uses Cohere Embed Multilingual v3 (via AWS Bedrock) to embed replies. Candidate posts are re-ranked by a model running entirely on NovoEd’s own servers - no customer data leaves NovoEd for this step.

Anthropic models do not ingest NovoEd customer data for any purpose other than completing the API call.

AI Model

NovoAI Feature

Data Scope

Opt-Out Control

Anthropic Claude Models on AWS Bedrock

AI-Generated Discussion Insights: Key Themes summarizing activity in course-wide discussions

Comments in course-wide discussions

Shall be enabled at the NovoEd organization level. Once enabled it will be displayed to all Admins and Learners.

Admins can choose to show/hide it for Learners in individual course wide discussion settings.

Cohere Embed Multilingual v3 via AWS Bedrock

Discussion similarity and diversity analysis: embedding replies for semantic retrieval

Discussion reply text

Controlled by enabling or disabling the relevant discussion AI features at the organization level.

Semantic re-ranking model: BAAI/bge-reranker-large - runs on NovoEd infrastructure

Re-ranking candidate discussion replies for similarity and diversity surfaces

Discussion reply text - processed entirely within NovoEd’s own servers

Controlled by enabling or disabling the relevant discussion AI features.

Development of AI Models by NovoEd

NovoEd is not developing a large language model, and will never use any customer data for training or developing general models. 

Several specialized models run entirely within NovoEd’s own infrastructure. These include a semantic re-ranking model (BAAI/bge-reranker-large) used for discussion and QnA retrieval, and a prompt-injection security model (Meta Llama Prompt Guard) used to screen inputs to the AI Learning Assistant. Because inference for these models happens inside NovoEd’s servers, no customer data is transmitted to any third party for these steps.

NovoEd may fine-tune or create AI models specific to a customer, their learning content, or learning data in the future. In such cases, the model will be separately fine-tuned or trained, hosted, and used for the specific customer. It will only be used to serve the specific customer or subset of learning experiences from that customer. Ensuring the logical separation of data and adhering to all of our existing security, privacy, and compliance requirements is at the core of any new AI development at NovoEd.


Was this article helpful?
Subscribe to receive updates on this article