No new passwords
Everyone signs in through your school's national login system, the one students and staff already use. Invigilo has no password of its own to forget, share or leak.
Security
Invigilo is the software a school installs. Vigila and LUCA are modules inside it, and both touch some of the most sensitive material a school has: what a student is doing while something is at stake. Here is what we do about it: without technical language, and without promises we cannot keep.
In practice
Invigilo is built to what GDPR asks of exam monitoring: collect as little as possible, keep it separated, and be able to account for every look. The points below are not intentions: they are how the platform is set up today, and they hold for every module, not only the exam one.
Everyone signs in through your school's national login system, the one students and staff already use. Invigilo has no password of its own to forget, share or leak.
A student appears as an anonymous seat, never as a name or a national ID number. The link between seat and person exists only in your own roster, including when the work happens in the study module.
One school's data is walled off from every other school's down in the database itself, not just in the software on top. And student work is not used to train a language model, not ours, not anyone else's.

Your machines. Your data. Your key.
When an exam is exported as documentation, it is locked to your school's own key. Nobody else can open it, Invigilo included.
Vigila is built and running in closed testing ahead of a Q4 2026 launch. LUCA is in development. The points above describe how the platform is built today, not a service already in production.
See what the modules doThere is a well-documented case where a European government shipped its own exam-monitoring software with a hardcoded, placeholder encryption key: the digits one through eight in order. A student took the whole thing apart in an afternoon. A placeholder is what you type while you build. No finished system should ever ship with one. That case is the standard any school is right to hold us to, and the sheet beside this is our answer on the three points it failed.
That is why we are looking for the first schools to run Vigila through closed testing with, before the module is released: the three points have to be checkable by someone outside the company, not only by us.
That includes us. Software running on the machine a student is sitting at can always, in principle, be challenged by someone persistent enough. An academic security researcher reviewing the case above said much the same at the time: this kind of software cannot be made unbeatable.
So it is worth being wary of a vendor promising the opposite. A claim of an unbreakable system is either ignorance or sales talk, and both become the school’s problem the day it stops holding.
Proportionality
Spot checks helped end the system above, and rightly so: being able to look is not the same as needing to. Invigilo does not have that capability. There is no place in the system where you can follow a student live or read a raw feed of activity.
The same principle holds for the study module: a student's conversation with the study model is the student's own, and does not become a monitoring trail a teacher can browse.
For your IT department
The same facts as above, in the form an IT lead usually expects them.