Updated August 20, 2026
A structured overview for security, privacy, legal, procurement, and AI governance reviewers
This document summarizes key information about AI Roleplay for use in internal security, privacy, procurement, or AI governance review. It covers the AI model and infrastructure, data handling practices, security controls, and access management. Use the table below to respond to vendor assessment questions or to brief a review committee. For detailed Q&A, refer to the companion Knowledge Base article: AI Roleplay Security, Privacy & Compliance FAQ.
Topic | Key Points |
Purpose & scope | AI Roleplay provides simulated conversational practice within a learning experience. Learners interact with an AI-powered character and receive performance feedback tied to defined scenario objectives. It is not a general-purpose AI tool. The AI operates within the boundaries of the configured learning scenario and course content. |
AI provider & infrastructure | Anthropic Claude models through AWS Bedrock and Inworld AI STT and TTS models when voice or dictation are used. Customer data is processed within this environment — not through any consumer-facing AI service. |
Data processed | During roleplay creation: scenario inputs provided by the Learning Experience Designer and the learning content in the course. No learner data is involved in this step. During a learner session: learner conversation turns, including speech-to-text if learner is using voice dictation, and the course content needed to conduct and evaluate the session. Voice Roleplay additionally: learner audio (speech-to-text) and AI character dialogue (text-to-speech). NovoEd applies the principle of using only the data minimally necessary for each task. |
Model training | No. Neither NovoEd nor any of its AI subprocessors use customer data to train or develop AI models. This applies across all subprocessors. Data is processed in real time, for the specific task only. NovoEd is not developing its own large language model. |
Data retention | Roleplay conversations and feedback are retained for the duration of the customer's active contract and deleted upon a submitted deletion request. |
Security controls |
|
Model evaluation & drift | NovoEd conducts programmatic evaluations of AI model behavior both before software releases and on an ongoing basis in production. These evaluations follow the same security and privacy principles that govern the platform and are designed to detect model drift, ensuring that AI responses remain consistent with defined quality and behavioral standards. |
Governance | AI Roleplay access is managed through AI Roleplay Usage Management, a dedicated control available to Organization Administrators. It offers two modes:
Approved modality types (Text, Audio, Avatar) are also configurable per course. This supports phased and controlled-audience deployments. |
Sensitive & regulated data | Scenarios should be designed so that learners do not enter real personal, confidential, or regulated information, such as actual patient names, account numbers, or genuine PII. Fictional or simulated information, such as made-up patient details in a healthcare training scenario, is fine to use. Organizations with specific regulatory requirements (healthcare, financial services) should engage NovoEd's compliance team before deployment. |
Subprocessors | AI subprocessors — including Anthropic and Inworld AI — are documented in NovoEd's Compliance Center and subprocessor list. |
Your NovoEd Customer Success Manager can provide:
Data Processing Agreement (DPA)
Subprocessor list and agreements
Security questionnaire responses
SOC 2 Type II report
NovoEd Compliance Center documentation
NovoEd compliance team engagement for regulated-industry use cases