Detected country: US
logo
Back to creating
‌
‌
‌
logo

Powered by

  • Home
  • Partners
  • AI and Data Security for Coassemble Embed Partners

AI and Data Security for Coassemble Embed Partners

4min read

Share

Overview

As an Embed partner, you need flexibility and trust. Your clients rely on your platform integrations to deliver seamless learning experiences, so data security and responsible AI use must be built in, not bolted on.

This article explains how Coassemble approaches AI capabilities and data security, and what that means for you and your end-customers.

AI innovation without compromising data control

Coassemble includes generative AI features to help you create and improve learning content faster, while keeping your data secure and under your control.

How Coassemble uses AI

Coassemble integrates directly with Google’s AI services for AI capabilities.

Models used include:

  • Gemini Flash for text generation, including course generation, document transformation, text refinement, and translation.

  • Gemini 2.5 Flash Image for AI-generated images, producing sharp, detailed visuals with strong prompt accuracy. This replaced the earlier Imagen model, which Google is retiring.

  • Chirp for AI narration voices.

Note: Specific model and feature details may change over time. Refer to the provider’s terms of service and data policies for the most current information.

Customer data is not used to train AI models

A core principle of Coassemble’s AI approach is that customer data is not used to train the underlying AI model.

  • Content you upload or generate remains yours.

  • Coassemble does not feed your documents, course content, or prompts back into the model for training.

  • When you use features such as Transform a document:

    • Your document is securely stored in object storage.

    • Relevant course context is retained in Coassemble’s database to support generation.

Content ownership

  • You own the output. Anything generated with Coassemble AI tools is fully owned by you.

  • Through your Embed integration, this ownership extends clearly to your end-customers.

  • Ownership applies whether content is:

    • AI-generated, or

    • Manually created in Coassemble.

Data storage, encryption, and trust standards

Coassemble applies the same rigorous security controls to AI features as across the entire platform.

Security controls

  • Encryption in transit and at rest

  • Strict access control

  • Alignment with industry best-practice security frameworks

Data location and default hosting

  • By default, data is stored on US-based infrastructure (currently Oregon, USA).

  • AI processing requests are also executed in the United States.

  • If you have specific data residency requirements, see Regional infrastructure for Embed partners and Server architecture for Embed partners below.

Compliance and certifications

Coassemble maintains security and compliance standards to support enterprise customers.

  • GDPR compliance (without formal GDPR certification)

  • SOC 2 Type 2 certification

Certifications and security controls are available via the Coassemble Trust Centre:

  • https://trust.coassemble.com/

AI processing pathway and subprocessor reduction

Coassemble has updated how the AI Course Creator processes data to improve:

  • Reliability and performance

  • Data governance

  • Transparency in data handling

Coassemble now integrates directly with Google’s AI services, which supports:

  • AI processing in a fixed, known region

  • Fewer subprocessors

  • Clearer data-handling pathways for compliance and audit needs

  • Expansion of regional infrastructure options for partners with specific requirements

This shift enables Coassemble to:

  • Ensure AI processing happens in a fixed, known region

  • Reduce the number of subprocessors involved

  • Improve data-handling transparency and compliance

  • Prepare for region-specific infrastructure options

AI image generation

Coassemble uses Gemini 2.5 Flash Image for AI-generated images, producing sharper, more detailed visuals with improved prompt accuracy and consistency. This replaced the earlier Imagen model. Image generation is triggered manually, so authors control when images are created and when usage is consumed.

Server architecture for Embed partners

Your server environment is chosen upfront as part of partnership setup. Configuration is set at the start of the partnership and cannot be changed after sign-up without starting a new account.

Coassemble offers five server options:

1) Standard Release server (previously Production)

  • Shared environment that receives platform updates immediately on each release.

  • For Embed customers using the Controlled Release server in production, the Standard Release server typically serves as their dev/test workspace.

2) Controlled Release server (previously Enterprise)

  • Shared environment that receives platform updates two weeks after the Standard Release server.

  • Releases are more rigorously validated, giving customers extra preparation time at each stage.

  • Designed for production stability.

3) Region-Locked Server

  • All data is processed and stored within a specified region: EU, US or APAC.

  • For partners with data residency or compliance requirements.

4) Dedicated server

  • Private, single-tenant environment.

  • Can optionally be region-locked.

5) Self-hosting

  • Available for partners with specific deployment requirements.

  • Subject to commercial approval and discussed during partnership setup.

Regional infrastructure for Embed partners

For Embed partners with data residency or compliance requirements, Coassemble offers a Region-Locked Server option in addition to our US-based infrastructure.

Available regions for region-locked servers

  • EU

  • US

  • APAC

With Region-Locked Server enabled, data is processed and stored within the selected region.

What this means for you as an Embed partner

These controls and commitments help you meet your own customer promises.

  • Confidence for your clients: Assure end-customers that your integrated offering does not introduce unexpected data-use risks.

  • Clear ownership: Content created through your Embed integration remains owned by your clients, with no hidden downstream usage.

  • Regulatory alignment: For customers with compliance requirements (for example, GDPR or SOC 2), you can reference Coassemble’s certifications and data-location transparency.

  • Scalable innovation: Benefit from Coassemble’s AI improvements without building or maintaining an AI stack, so you can focus on your Embed experience and differentiated features.

Related resources

  • Coassemble Trust Centre (security controls and certifications): https://trust.coassemble.com/

  • Google AI provider terms of service and data policies: https://ai.google.dev/gemini-api/terms#data-use-paid

Share