HomeCase studies › Case 08
Case 08 · FERPA · GDPR · EU AI Act

Every SaaS detector transmits student text to their servers.

The compliance wall that blocks Turnitin, GPTZero, Grammarly at K-12 and EU institutions.

The failure · on the record

Under FERPA (US education), GDPR (EU), and the EU AI Act Article 12 (August 2 2026 in force), transmitting identifiable student text to a third-party AI-detection API is a compliance event that requires DPAs, lawful basis, and tamper-resistant logs. Every SaaS detector fails at least one of those. On-prem deployment is the only clean answer. Our detector is CPU-only, air-gap-installable, and ships an Ed25519 audit log built in.

The numbers
FERPA-cleanGDPR-cleanEU AI Act Art. 12 log?Air-gap install?
TurnitinRequires DPA + parental noticeRequires DPANoNo
GPTZeroRequires DPARequires DPANoNo
Grammarly EnterpriseRequires DPARequires DPANoNo
Truth-in-AI (on-prem)Yes (never leaves VPC)YesYes (Ed25519 log)Yes
What we do differently

On-prem deployment ships as a licensed, hardware-bound container. Buyer’s text never leaves their infrastructure. Audit log is Ed25519-signed at write time — tamper-resistant per EU AI Act Article 12.

Terraform module deploys inside AWS / GCP / Azure tenancy in a day.

Proof
Request the compliance packet. Request the packet →
Try it yourself
Bounty · put money where the claim is
We refund one month of license for any documented compliance blocker we cannot resolve within 30 days.
Sources