TurnitinConnect Home

Legal

Security

Last Updated: July 6, 2026

Security is the foundation of Turnitin Connect. We understand that your source text is your most valuable asset, and we have implemented industry-leading security practices across our entire infrastructure to protect it.

🛡️ SOC 2 Type II Certified
🔒 GDPR Compliant
⚙️ ISO 27001 Aligned

1. Encryption

All data in transit between the Turnitin Connect application and our routing servers is encrypted using TLS 1.3 with strong cipher suites. Any metadata stored at rest on our servers is encrypted using AES-256 encryption.

2. Local Indexing

When utilizing the "Chat with Document" feature, the underlying semantic vectors are generated and stored exclusively on your local machine. We do not sync these vector databases to the cloud.

3. Authentication and Access Control

We use secure, modern authentication protocols powered by Supabase. Your passwords and OAuth tokens are never exposed to Turnitin Connect developers. Access to production databases is restricted to core engineering leads via secure VPNs and hardware security keys.

4. Bug Bounty Program

We maintain an active, private bug bounty program with independent security researchers to continually audit our infrastructure. If you believe you have discovered a vulnerability, please contact security@turnitinconnect.com for responsible disclosure guidelines.

Terms Privacy Data Security