Data Handling Policy
Last Updated: July 8, 2026
This Data Handling Policy outlines the technical and organizational measures ScholarVault employs to secure the data submitted to our intelligence network.
1. Data Storage & Encryption
All data at rest is encrypted using AES-256 encryption. Data in transit between your browser and our servers, or between our internal microservices, is encrypted using TLS 1.3. We utilize enterprise-grade cloud infrastructure (AWS) distributed across multiple geographic zones to ensure high availability and data durability.
2. Uploaded Documents (PDFs & Images)
When you upload a conference flyer or PDF to SCVS for Document Intelligence analysis:
- The document is temporarily stored in a secure bucket for OCR processing.
- Text is extracted and analyzed against our verification checkpoints.
- By default, the original source file is permanently deleted from our servers within 24 hours of analysis completion, unless you explicitly save it to your institutional library.
3. AI Model Training
We continuously improve the SCVS accuracy using aggregated and anonymized data from user queries. We strictly strip all Personally Identifiable Information (PII) before any data is used for model tuning. We do not use proprietary research, unpublished papers, or private institutional data to train our public models.
4. Access Controls
Access to user data is strictly limited to authorized ScholarVault personnel on a principle of least privilege. All employee access is logged, monitored, and requires multi-factor authentication (MFA).
5. Data Breach Protocol
In the highly unlikely event of a data breach, ScholarVault maintains an Incident Response Plan. Affected users and institutional administrators will be notified within 72 hours of incident confirmation, detailing the scope of the breach and remediation steps taken.