Last Updated: July 6, 2026
Security is the foundation of Turnitin Connect. We understand that your source text is your most valuable asset, and we have implemented industry-leading security practices across our entire infrastructure to protect it.
All data in transit between the Turnitin Connect desktop application and our routing servers is encrypted using TLS 1.3 with strong cipher suites. Any metadata stored at rest on our servers is encrypted using AES-256 encryption.
Our cloud infrastructure is hosted on AWS and GCP, utilizing their highest-tier security constructs. We employ rigorous access controls, network segregation, and automated threat detection. Our routing servers operate in stateless mode for AI requests to ensure that your text payloads are processed in volatile memory and immediately wiped.
We conduct regular dynamic and static application security testing (DAST/SAST) on our document. We also partner with independent third-party security firms to conduct comprehensive penetration testing on both the desktop Scanner client and our backend API infrastructure twice a year.
We welcome reports from security researchers. If you believe you have found a security vulnerability in Turnitin Connect or our associated web services, please report it to