Legal
Security
Last Updated: July 6, 2026
Security is the foundation of Turnitin Connect. We understand that your source text is your most valuable asset, and we have implemented industry-leading security practices across our entire infrastructure to protect it.
1. Encryption
All data in transit between the Turnitin Connect application and our routing servers is encrypted using TLS 1.3 with strong cipher suites. Any metadata stored at rest on our servers is encrypted using AES-256 encryption.
2. Local Indexing
When utilizing the "Chat with Document" feature, the underlying semantic vectors are generated and stored exclusively on your local machine. We do not sync these vector databases to the cloud.
3. Authentication and Access Control
We use secure, modern authentication protocols powered by Supabase. Your passwords and OAuth tokens are never exposed to Turnitin Connect developers. Access to production databases is restricted to core engineering leads via secure VPNs and hardware security keys.
4. Bug Bounty Program
We maintain an active, private bug bounty program with independent security researchers to continually audit our infrastructure. If you believe you have discovered a vulnerability, please contact security@turnitinconnect.com for responsible disclosure guidelines.