RTO Assess & Assist — Security & Data Handling Summary
One page for RTO compliance managers and auditors. Plain answers to the questions you're going to ask anyway.
Last updated: 15 July 2026 · Full detail: Privacy Policy & Terms.
Does AI make assessment decisions?
No. The Service produces an AI recommendation with confidence and evidence. A named human assessor must Accept (with a written comment) or Override (with a chosen outcome and written reason) every single assessment. There is no code path that finalises a student outcome without a human decision. Anything the AI could not confidently grade is forced to "REVIEW REQUIRED" — never silently passed or failed.
What happens to a document the system can't read?
It is never sent to the AI. A file that cannot be opened, or cannot be matched to one of your marking guides, is stamped UNREAD with the reason (e.g. "file could not be read", "no matching marking guide") — it appears in the review queue and gets its own audit log row, and like every other assessment it can only leave the queue by a named assessor's decision. Nothing is skipped silently.
The same rule applies at the answer level and the run level: answers the AI could not grade are recorded with the cause (e.g. "AI unreachable"), and if an assessor stops a run mid-flight, the stop itself is written to the audit log with the number of documents completed.
What leaves the machine when AI is used?
Only redacted answer text and the marking benchmarks. Before every AI call:
- The student's name and details are read from the assessment's own cover sheet (not the file name) so the system knows exactly who to protect.
- Names, emails, phone numbers, addresses and ID numbers in the answers are replaced with anonymous tokens before sending, and restored after the response returns — originals never leave the server.
- Cover sheets, file names, and student identities are never sent to any AI provider.
- Every run's audit log records the redaction count per student, so the protection is provable per assessment, not just promised.
What audit trail exists?
One append-only audit row per assessment: local timestamp, student, unit, the AI's recommendation and score, which AI model/provider was used, PII redaction count, the final human decision, the named assessor, decision time, and the assessor's written comment or override reason. Exportable on demand as Excel or signed-footer PDF. Audit records are never edited or purged, even after uploaded files are deleted.
Two numbers, deliberately kept separate: the AI Score on each row is what the AI concluded at marking time and is never altered afterwards — an override sitting next to an unchanged AI score is the evidence of human oversight, not an inconsistency. The overall competency percentage is calculated from final assessor decisions only (undecided assessments don't count toward it).
How is AI-written student work handled?
Flagged, never auto-failed. Suspected AI-generated content is shown to the assessor with confidence, highlighted excerpts in the marked document, and suggested verbal knowledge check questions — supporting an authenticity judgement under the rules of evidence. The decision remains the assessor's. Detection is deliberately conservative and repeatable: the same submission gets the same verdict on every run, and formal tone, correct grammar or non-native (ESL) phrasing is never treated as evidence of AI use on its own.
Authenticity and knowledge are judged separately: a flagged submission whose answers meet the benchmarks still shows "Competent (AI recommendation)" with the flag beside it — the flag informs the assessor's authenticity check, it never changes the grade recommendation.
What's in the marked document?
Every answer that received written feedback is highlighted green with the feedback attached as a comment (a blank answer box gets a green cell wash instead, so an unanswered question is visible at a glance); suspected AI-written sections are highlighted yellow. The on-screen review preview shows the same green and yellow as the downloaded Word file. Only the current marking appears: any comments already inside an uploaded file (earlier markings, previous trainers) and any earlier feedback highlighting are removed from the marked copy so old feedback can never be mistaken for this run's. The uploaded original is never altered.
If the assessor deletes a marker comment (and its highlighting) from the marked document during review, two things happen: the assessment can then only be finalised as an override (a plain approval of the AI recommendation is blocked, since the AI's feedback no longer stands on its own), and the Assessment Marking Record cover page states how many comments were removed — so a filed or printed copy never implies the AI's feedback all survived review.
Every marked document downloaded from the tool carries an Assessment Marking Record cover page — student, unit, AI recommendation and score, model used, PII redaction count, the final human decision, assessor, date and comment, plus every per-question feedback comment written into the document — so every filed or printed document carries its own audit evidence. A document downloaded before the assessor has decided states "REVIEW REQUIRED — not yet decided" in place of a result, so a mid-review printout can never pass as a finalised outcome. A Marking Summary export on the Reports page lists every finalised assessment with its result, feedback and stored filename.
Data retention
| Data | Policy |
|---|---|
| Uploaded student files | Auto-deleted after 180 days (configurable) |
| Audit & completion records | Never purged |
| Finalised marked documents | Stored in your account; downloadable any time from the Reports page (singly or "Download all") |
| Database | Backed up daily (14 rolling copies) |
Access control
Account owner + invited assessor logins only; each customer sees only their own data. Signed-in sessions expire automatically after 1 hour of inactivity. Payments processed by Stripe (PCI-DSS); we never hold card numbers.
Regulatory position
Designed to support compliance with the Standards for RTOs 2025, including the principles of assessment, rules of evidence, and ASQA's published position that AI must not make assessment decisions. ASQA does not endorse software products, and we make no "ASQA approved" claim — be wary of any vendor that does.
Questions: [SUPPORT EMAIL]