/ /

AI Roleplay Security Review Summary

For internal security & compliance review
Updated 29 days ago

Updated August 20, 2026

A structured overview for security, privacy, legal, procurement, and AI governance reviewers

About this document

This document summarizes key information about AI Roleplay for use in internal security, privacy, procurement, or AI governance review. It covers the AI model and infrastructure, data handling practices, security controls, and access management. Use the table below to respond to vendor assessment questions or to brief a review committee. For detailed Q&A, refer to the companion Knowledge Base article: AI Roleplay Security, Privacy & Compliance FAQ.

Topic

Key Points

Purpose & scope

AI Roleplay provides simulated conversational practice within a learning experience. Learners interact with an AI-powered character and receive performance feedback tied to defined scenario objectives.

It is not a general-purpose AI tool. The AI operates within the boundaries of the configured learning scenario and course content.

AI provider & infrastructure

Anthropic Claude models through AWS Bedrock and Inworld AI STT and TTS models when voice or dictation are used.

Customer data is processed within this environment — not through any consumer-facing AI service.

Data processed

During roleplay creation: scenario inputs provided by the Learning Experience Designer and the learning content in the course. No learner data is involved in this step.

During a learner session: learner conversation turns, including speech-to-text if learner is using voice dictation, and the course content needed to conduct and evaluate the session. 

Voice Roleplay additionally: learner audio (speech-to-text) and AI character dialogue (text-to-speech).

NovoEd applies the principle of using only the data minimally necessary for each task.

Model training

No. Neither NovoEd nor any of its AI subprocessors use customer data to train or develop AI models. This applies across all subprocessors. Data is processed in real time, for the specific task only. NovoEd is not developing its own large language model.

Data retention

Roleplay conversations and feedback are retained for the duration of the customer's active contract and deleted upon a submitted deletion request.

Security controls

  • SOC 2 Type II certified

  • Data encrypted in transit and at rest

  • Logical separation of customer data

  • GDPR-compliant privacy practices

  • Established AI governance program

  • AI subprocessors documented, reviewed, and listed in the NovoEd Compliance Center

Model evaluation & drift

NovoEd conducts programmatic evaluations of AI model behavior both before software releases and on an ongoing basis in production. These evaluations follow the same security and privacy principles that govern the platform and are designed to detect model drift, ensuring that AI responses remain consistent with defined quality and behavioral standards.

Governance

AI Roleplay access is managed through AI Roleplay Usage Management, a dedicated control available to Organization Administrators. It offers two modes:

  • All Courses (default): roleplay is available across all courses

  • Require approval per course: each course must be explicitly approved before learners can access roleplay activities

Approved modality types (Text, Audio, Avatar) are also configurable per course. This supports phased and controlled-audience deployments.

Sensitive & regulated data

Scenarios should be designed so that learners do not enter real personal, confidential, or regulated information, such as actual patient names, account numbers, or genuine PII. Fictional or simulated information, such as made-up patient details in a healthcare training scenario, is fine to use.

Organizations with specific regulatory requirements (healthcare, financial services) should engage NovoEd's compliance team before deployment.

Subprocessors

AI subprocessors — including Anthropic and Inworld AI — are documented in NovoEd's Compliance Center and subprocessor list.

Additional documentation available upon request

Your NovoEd Customer Success Manager can provide:

  • Data Processing Agreement (DPA)

  • Subprocessor list and agreements

  • Security questionnaire responses

  • SOC 2 Type II report

  • NovoEd Compliance Center documentation

  • NovoEd compliance team engagement for regulated-industry use cases

Was this article helpful?
Subscribe to receive updates on this article