Cutting-edge AI for your campus.
Zero risk to your data.

Deploy the power of artificial intelligence with the peace of mind that your intellectual property, student records and institutional knowledge are under lock and key.

GDPR
FERPA
SOC 2 Type II

Your knowledge is yours. Full stop.

Zero Training Guarantee: Your files, research documents, exams and student data remain hosted in a private environment exclusive to your institution. We will never use your information to train public AI models or third-party models. Your model learns only within your own boundaries.

Witty Boxes vs. cloud alternatives.

An honest comparison for technical and compliance teams evaluating options.

CriterioWitty BoxesChatGPT EduMS CopilotGemini Edu
Data never leaves the institution
GDPR compliance native by design
No training with your data
Native LMS integration (Moodle/Canvas)
Full customisation with own context
Complete audit and traceability
European provider, data in Europe
Sí, nativo
Parcial / configurable
No disponible

EU AI Act:
What it means for your institution.

Regulation (EU) 2024/1689, in force since August 2024, establishes specific obligations for high-risk AI systems — the category that covers AI used in educational environments.

What is the EU AI Act?

The world's first global AI regulatory framework. It classifies systems by risk level and establishes obligations for transparency, auditing and human oversight. AI systems applied in education and student management are explicitly classified as high-risk (Annex III).

Implementation timeline

February 2025 · Prohibited practices

Prohibited AI practices: cognitive manipulation, social scoring.

August 2025 · General obligations

Transparency and user information about AI use.

August 2026 · High-risk AI
En vigor

Education: human oversight, technical documentation, audit.

2027 · Commission Review

First European Commission audits of high-risk AI systems in production.

The 4 key obligations for educational AI

  • 1Risk management system and technical documentation
  • 2Quality and governance of training data
  • 3Transparency and effective human oversight
  • 4Robustness, security and verifiable accuracy

How Witty Boxes complies with the EU AI Act

  • On-Premise: data is never processed outside the institutional perimeter
  • RAG with source citations: human oversight of every response
  • Immutable audit logs: complete documentation for compliance
  • Multi-agent architecture: human intervention possible at any point in the flow

Legal rigour.
No surprises.

Designed from the ground up to strictly comply with the most demanding international standards for data protection and privacy in educational environments.

Global Regulatory Compliance

Institutional-level data protection under the world's most demanding regulatory frameworks.

  • GDPR: Full protection of personal data
  • FERPA: Academic records fully safeguarded
  • SOC 2 Type II: Audited security infrastructure

Access Control & Roles

Configure granular permissions so each profile can only access the information relevant to them.

  • Students: Secure environment free of data leaks
  • Faculty: Private management of materials and assessment
  • Administrators: Centralised control of usage policies

Traceability & Audit

Full visibility over every interaction. RAG always cites the sources used, preventing hallucinations or plagiarism.

  • Audit logs: Complete history for compliance reviews
  • Source citations: Responses from your official documentation
  • Leak prevention: Active IP protection filters

Review our security
architecture in full.

Request a meeting with our Privacy Officer to review your specific case or download the security white paper.

Back to home