Designing a safeguarded path from concept to pilot
The work focused on architecture, security controls, implementation guidance, and a compliance evidence framework—not on claiming regulatory certification or replacing institutional approval.
The challenge
- Keep applicable data and AI processing within approved Canadian regions
- Minimize identifiable student information during a limited classroom pilot
- Restrict service access and manage secrets appropriately
- Document privacy, security, retention, and deletion decisions
The approach
- Canadian-hosted application and data architecture
- Azure OpenAI deployment in a Canadian region
- Single authorized source IP and controlled service access
- Vault-managed credentials and deployment runbook
- Pseudonymization, retention, and end-of-pilot deletion planning
Deliverables
- Technical architecture and configuration guidance
- Security and privacy control checklist
- Implementation and cutover runbook
- Evidence areas for data residency, encryption, access, and lifecycle
- Open decisions clearly assigned to institutional stakeholders
