Trust and security

Privacy and security designed in, not added later.

What protects students, families and staff in Murshid, what we will never do with their data, and the questions any school should ask an AI vendor.

Data protection by design

Controls built into the product.

Guardian consent first

Student AI features stay blocked until a guardian's consent is recorded. Revoking it takes effect immediately.

Prior-permission records

Permissions a school obtains to process children's data are recorded with their reference, scope and expiry.

Append-only audit

The database refuses edits and deletions of audit records, and a keyed chain makes tampering detectable.

Role-based access

One capability model decides both what each role sees and what the server allows.

Each school kept apart

A school's data is isolated from every other school's, and tests check that isolation.

No training on student data

Student data is never used to train AI models, enforced in the product and covered by tests.

Safeguarding alerts

Tutor conversations are screened, and open alerts are tracked for leadership beside consent and audit.

Export on request

Leadership can export the audit log, the compliance dossier and the records held about one person.

Responsible AI

Principles the product enforces.

Teachers decide

AI proposes marks, fixes and materials. A teacher accepts, edits or discards them.

Hints, not answers

The tutor guides a student towards the answer and is built never to give it.

Evidence, not predictions

Murshid describes a student's work. It does not predict a grade or a future for a child.

No rankings of children

Students and parents see a child's own progress, never a comparison with classmates.

No manipulative mechanics

No leaderboards, badges or points. A build check fails if they appear.

Every call on the record

No AI output reaches anyone without an entry in the audit log.

See the audit trail at workTamper with a record in our interactive demo and watch the chain break, then read how consent and PDPPL evidence fit together.Open the governance page

Hosting and providers

We share hosting, data location and provider details in writing during pilot scoping, so your school can review them with its own advisers before any student data is involved.

Ask us about hosting

Accessibility

The product's design system is held to WCAG 2.2 AA by automated checks that fail the build: accessible names, contrast, target size, visible focus and reduced motion, in Arabic right to left and French left to right. Automated checks do not catch everything, and testing with disabled users is still ahead of us.

Website accessibility statement

For school leaders

Questions to ask any AI vendor

Murshid is designed to support schools' obligations under Qatar's Personal Data Privacy Protection Law (Law No. 13 of 2016). This page is general information, not legal advice.

The full checklist
  1. Is student data ever used to train AI models?
  2. Can a guardian withdraw consent, and does that stop processing for their child?
  3. Does a teacher decide what the AI can do for students?
  4. Is every AI interaction recorded, and can the school export the records?
  5. Where is student data stored and processed, and by which providers?

Reviewing Murshid for your school?

Send us your security or data protection questions. We answer in Arabic, English or French.

Contact the team