Security

Built for High-Stakes Medical Certification

EdAI's security architecture was designed from day one for the compliance, access control, and audit requirements of medical certification boards. Not bolted on. Built in.

Architecture

Air-Gapped Question Banking

The AI content generation platform and the secure question bank operate in separate environments. There is no direct API connection, no shared database, no automated transfer between them. Generated content moves to the banking environment manually and deliberately — ensuring that every item passes through human review before entering the active bank. This separation is by design, not by limitation.

Generation Platform

Where AI modules create content from board-approved sources. Accessible to content curators and administrators.

Secure Banking Environment

Where examiners review, edit, approve, and finalize items. Independent infrastructure with its own access controls and audit logs.

Manual Transfer — Human Review Required
Examination Delivery

Biometric-Proctored Examination

High-stakes certification examinations require absolute confidence in candidate identity and examination integrity. EdAI's test administration platform combines biometric identity verification with dual-layer proctoring — AI surveillance working alongside human proctors — to deliver secure remote examinations at scale.

Biometric Identity Verification

Candidates authenticate through biometric verification before and during examination. The right person takes the right exam.

AI Surveillance

Continuous AI monitoring detects anomalies — environmental changes, behavioral patterns, unauthorized materials — in real-time.

Human Proctoring

Trained proctors receive AI-flagged escalations and exercise judgment on ambiguous situations. Technology assists; humans decide.

200 Concurrent Examinations

The platform supports up to 200 simultaneous remote examinations with consistent security and performance across all sessions.

Governance

Enterprise Access Control

A 6-tier role hierarchy ensures the right people have the right access — no more, no less.

1

Super Admin

Full platform control. User management, module activation, system configuration.

2

Admin

Board-level administration. User management, content oversight, analytics access.

3

Content Curator

Content creation and curation. Module access for generating and reviewing educational materials.

4

Diplomate

Certified members. Access to CME, assessments, educational resources assigned by their board.

5

Fellow

Trainees in fellowship programs. Access to training materials and supervised educational tools.

6

Researcher

Limited access for research purposes. Read-only access to approved materials.

Permission Matrix: Every role has granular permissions across module access, content management, user administration, and system settings. Permissions are inheritable — higher roles include all permissions of lower roles.

Compliance

Full Audit Trail

Every action on the platform is logged — user, timestamp, action, context. Content changes track full version history with who changed what and why. Access logs record every login, every module interaction, every data export. This isn't just good practice — it's table stakes for medical certification boards accountable to ABMS standards.

Audit Logging

Every user action recorded with full context. Searchable, exportable, and retention-policy compliant.

Data Isolation

Multi-tenant architecture ensures complete data separation between boards. Each board's content, users, and configuration are fully isolated.

Module Activation Controls

Boards toggle modules on or off as needed. Deactivation hides the module from users but preserves all data for reactivation.

Infrastructure

EdAI runs on Google Cloud Platform with Firebase infrastructure. Data encrypted at rest and in transit. Automated backups. Role-based security rules enforced at the database level.

Google Cloud PlatformFirebase Security RulesEncryption at rest and in transitAutomated backupsMulti-region availability

Questions About Security?

Schedule a security review with Dr. Ferguson. We'll walk through the architecture, access controls, and compliance documentation specific to your board's requirements.

Schedule a Security Review

Be the First to Explore EdAI Suite

Get early access to the platform. We'll notify you when demo access opens.