Your data, treated like critical infrastructure.
Membership rolls, dues history, registrations, abstracts — this is the operational heart of your organization. PediaSphere is built on Microsoft Azure with encryption everywhere, passwordless access, role-based permissions, automated backups, a full audit trail — and AI that is scoped, filtered, and never trained on your data. Here's how it works.
Five layers between the internet and your data.
No single control is asked to do all the work. Each layer assumes the one outside it could fail.
The controls, illustrated.
Encrypted in transit
From the moment a page loads to the moment a report downloads, the connection is encrypted. Nothing travels the public internet in the clear.
- TLS on every subdomain, enforced — HTTP redirects to HTTPS
- Certificates renewed automatically before expiry
- Modern cipher suites only; legacy protocols disabled
Encrypted at rest
Data doesn't just need protecting while it moves. Databases, backups, and file storage are encrypted on disk, so even physical access to storage media yields nothing readable.
- Azure SQL transparent data encryption, always on
- Backups encrypted with the same keys as the live database
- Keys managed and rotated by the Azure platform
Passwordless sign-in
Most breaches start with a stolen or reused password. PediaSphere removes the password entirely: a one-time code or link is delivered to a channel you already control, and it expires in minutes and works only once.
- Verified email link, SMS code, or authenticator app (TOTP) — your choice
- Nothing to remember, nothing to phish, nothing in a password dump
- Short-lived, single-use tokens; sessions expire automatically and every sign-in is logged
Role-based, row-level permissions
A society has staff, officers, committee chairs, reviewers, and members — and they should not all see the same thing. Permissions are enforced on every query, not just hidden in the interface.
- Roles map to real organizational responsibilities
- Row-level filtering: a committee chair sees only their committee's data
- Administrators grant and revoke access without contacting us
Automated backups & point-in-time restore
Mistakes happen — a bulk import goes wrong, a record is deleted. Azure SQL keeps continuous backups so we can restore your database to any point in the retention window, not just last night.
- Continuous backups with point-in-time restore
- Geo-redundant copies stored in a second Azure region
- Restores are tested; recovery isn't theoretical
Audit trail on everything
Who signed in, from where, and what they changed — every significant action is recorded with a timestamp and the acting user. When a board member asks "who edited this?", you have the answer.
- Sign-ins, role changes, exports, and record edits are logged
- Logs are append-only; they can't be altered by application users
- Available to your administrators on request
AI that answers questions — without oversharing.
AI is central to how PediaSphere works, so it gets its own set of controls. The principle is simple: the AI sees only what it needs to answer the question in front of it, for the person asking it, and nothing it sees leaves your organization's boundary.
Every request passes through the same gates
Before the AI sees anything, the request is scoped and filtered. After it answers, the exchange is logged and sampled for human review. The model itself is never trained on your data.
- Scoped to you. The AI can only reach your organization's data, filtered by the asking user's own role and row-level permissions — the same rules that govern the rest of the platform.
- Sensitive fields are filtered out. Government IDs, dates of birth, and payment details are never placed in an AI prompt. Demographic and DEI fields — race, ethnicity, gender identity, disability, health, religion — are excluded at the individual level and only ever reach the AI as aggregate counts, and only for users whose role permits demographic reporting.
- No model training on customer data. Your data, questions, and answers are not used to train or fine-tune any model. Our AI providers are contractually bound to the same: no retention beyond the request, no training.
- Every exchange is logged. AI questions and answers are recorded in the audit trail with the acting user, and a sample is reviewed by our team to catch errors, drift, and anything that should have been filtered.
Security is a habit, not a feature.
Beyond the platform controls, these are the day-to-day practices we hold ourselves to.
Procurement asked for a questionnaire? Send it over.
Security questionnaires & DPAs
We complete vendor security questionnaires and sign Data Processing Agreements as part of onboarding. Our standard Data Processing Agreement is published and ready to sign. Send yours to security@pediasphere.ai and we'll return it promptly.
Responsible disclosure
Found a vulnerability? We want to know. Email security@pediasphere.ai with details. We acknowledge every report, fix confirmed issues, and credit researchers who ask to be credited.
Questions about how we'd handle your data?
We're happy to walk your IT lead or board through any of this.
Talk to Us