Skip to content
Invigilo

How it works

The rules are set. Invigilo enforces them. The teacher decides.

Invigilo is one application a school installs, with named modules inside it: Vigila monitors exams, LUCA is the study model. Here is the flow from the exam opening to the recording being deleted, and where data lives along the way. None of it is in production yet.

The flow

Four steps: set the policy, run the exam, review, delete.

01

Before the exam

The exam's level follows the exam regulations: at exams and the large written projects AI chatbots are prohibited, so it is level 0 or 1 of the four, which the school confirms. The exam leader sets the time and the seating chart. Nothing is collected yet; the client on the student’s computer waits for the server to open the exam.

02In closed testing

Vigila

During the exam

Vigila records only the exam window and masks the address bar and bookmarks before anything is sent. The rule engine flags what falls outside the school’s policy, and the invigilator sees the finding immediately.

03

After the exam

The teacher signs in with the school’s own staff login and downloads one summary per seat: every finding with the rule behind it. Findings are decided by the teacher, never by the system.

04

The deletion

When the appeal deadline expires, the server deletes the recording automatically. Deletion is built into the system, not a routine someone has to remember.

Launching in Q4 2026, ahead of the winter exams.

Where data lives

Three places, and only two of them exist.

The archive knows only seat numbers. The student’s name lives in the school’s own roster and never enters Invigilo: not in the exam module, not in the study model. That is why there are three possible places for data and only the first two exist.

The student’s computer: An encrypted local buffer while the exam runs. If the network is down, the buffer is the whole exam, exported as an encrypted archive at the end. Deleted once the recording is delivered to the school’s archive. Our servers in the EU: The encrypted archive, hosted with Hetzner in the EU. Only the school’s own staff have access, behind their own staff sign-in. Until the appeal deadline expires, then it is deleted automatically. Outside the EU: Nothing. No US cloud services, no sub-processors in third countries, no AI service we call out to. There is no data flow to delete.

Self-hosted AI

The models run on our own servers.

When a teacher asks for an advisory assessment of a finding, the extract goes to a language model we run ourselves on a GPU server in the EU. LUCA, the study model, is built on the same footing and is still in development. There is no API call to OpenAI, Google or any other service outside Europe.

No third party
Open weights on our own machine. Student data never reaches an external AI service, and there is no third-country transfer to assess.
Advisory, never decisive
The model’s answer is marked as advisory and attached to the finding as an aid for the teacher. No student is flagged or judged by a model.
If it fails, it does not guess
If the model does not answer, the question is noted as unanswered in the summary. The rules keep running without it, and the exam is unaffected.

Some school tools run on OpenAI's GPT-4o and GPT-5.1. Even when the archive itself is stored in the EU, the conversation with the model is sent to OpenAI's servers in the US. That does not apply to our own models.

GDPR

The rules are built in, not written on top.

01

Data minimisation

Everything outside the exam window is stripped on the student’s computer before anything is sent.

02

Purpose limitation

The recording is used for one thing: the teacher’s assessment of the exam. Not statistics, not model training.

03

Storage limitation

Automatic deletion when the appeal deadline expires. No clean-up anyone can forget.

04

No transfer out of the EU

Servers and models sit in the EU. There is no transfer to run a Schrems assessment on.

05

No automated decisions

Every finding is decided by a human. That is Article 22 to the letter.

06

Processor and rights

The school is the controller, Invigilo the processor, and the agreement is part of the subscription. Access and erasure go through the school, which is the only party that knows the names.

07

Proportionality for long assignments

The authority’s proportionality test rests on an exam being short and bounded. Fourteen days of continuous monitoring is not, so SSO and SRP-style long assignments are monitored in bounded windows instead.

See for yourself

The demo shows a whole exam room live.

Open the demo and see the room, the findings and the invigilator’s view, no login required. It is Vigila as the module looks in closed testing.