Skip to content
Security & integrations

Security your review team can check.

How students sign in, how Zelvi connects to your LMS and SIS, where the walls between institutions are, and what we send your privacy and accessibility offices.

Your systems

Identity providerSAML, Google, Microsoft
LMSLTI 1.3 launch, roster, grades
SIS rosterOneRoster CSV, verified domain

Zelvi

Tutor, your material only Recovery recordUploaded material is never used for AI training.

Database, row-level security

Your institution
Another institution

Cross-institution reads are refused by the database itself.

Grounding
100%
of questions outside the course material routed to the instructor on our benchmark, not guessed.
Isolation
0
cross-institution reads allowed. The database refuses them, tested as real signed-in users.
LMS
LTI 1.3
launch, roster sync and grade passback into Canvas, Moodle, Blackboard or D2L.
Accessibility
WCAG 2.1 AA
measured criterion by criterion, with the full report sent on request.

Integrations

Fits the systems you already run.

Single sign-on and the LMS launch are switched on with your IT team during pilot setup, because their first real run needs your identity provider and your LMS.
  • Set up with your IT team

    Single sign-on

    Students and staff sign in with the account they already have. No new passwords.

    SAML 2.0 for Okta, Shibboleth / InCommon, ADFS and Entra ID, registered by metadata URL or pasted metadata XML, plus Google Workspace and Microsoft 365. An identity provider can only be attached to a domain your institution has verified.

  • Set up with your IT team

    Clever and ClassLink

    K-12 students and teachers open Zelvi from their district portal and land in the right school and class.

    Clever and ClassLink sign-in, linked to your district ID in the console. Students and teachers only: a portal never makes anyone an administrator, and parent accounts are not created.

  • Set up with your IT team

    Inside your LMS

    Students open Zelvi from their Canvas, Moodle, Blackboard or D2L course. The class list and grades flow back.

    LTI 1.3 launch, roster sync (NRPS) and grade passback (AGS), built to the standard and tested against a simulated platform. The first launch into your LMS is validated with your team during pilot setup.

  • Available

    Roster import

    Everyone lands in the right course on day one, and re-importing never creates duplicates.

    OneRoster 1.1 CSV from your SIS, a spreadsheet, a join code, or automatic join from a verified email domain. A preview shows every change before anything is written.

  • Set up with your IT team

    Google Classroom

    A teacher brings a Classroom class list into their Zelvi course in two clicks.

    Read-only roster access, a preview before anything is written, and re-imports that add nobody twice. Teachers can only add addresses at your verified domains.

  • Available

    Live help, in the same place

    Office hours and short group sessions for students stuck on the same thing, opened from the Studio.

    Private video rooms that expire after the session. Recording and transcription are off unless your institution switches them on.

  • Available

    Per-institution data isolation

    Your students, material and results are visible to your institution only.

    Enforced by the database’s row-level security, not by application code, and probed as real signed-in users across two tenants.

  • Available

    Privacy controls

    Learners can export or erase their data; under-18 accounts need guardian consent.

    Data export, account erasure and single-use guardian consent, each driven end to end through a real browser before release.

  • Available

    Accessibility review

    Your accessibility office gets a current, criterion-by-criterion report before purchase, not after.

    Measured against every Level A and AA success criterion in WCAG 2.1, the standard the ADA Title II rule sets for public colleges. Sent as an ACR / VPAT on request, with a named contact for barrier reports.

  • On request

    SCIM and live SIS sync

    Automatic joiners and leavers from your identity or SIS platform.

    Built on the same roster seam as the imports above, when a pilot needs it.

Controls

What protects your students’ data.

  • Isolation at the database

    Every learner record is scoped to its institution by row-level security. A request for another institution’s data is refused by the database, not filtered by the app.

  • Course-scoped material

    Published material is readable only by that course’s students. The tutor answers from it, cites the page, and declines what it does not cover.

  • Learner control

    Learners can clear their own conversations, typed and voice, in one action. Hand-offs to staff point at the attempt instead of copying the learner’s words.

  • Export, erasure and consent

    Data export, permanent erasure and single-use guardian consent for under-18 accounts, each tested end to end in a browser before release.

  • Student safety

    If a student types or says something that may mean they are in danger, Ava stops tutoring, says she is an AI, gives crisis resources for their country, and alerts your designated staff. The alert email never carries the student’s words.

SOC 2

The controls above are in place; the independent audit has not yet been performed.

Data region

Hosted in a US region. Another region is set up for a signed agreement that requires it.

Patient data

Zelvi does not accept real patient health information.

Send this page to your review team.

We send the accessibility report, the security overview and answers to your questionnaire before anything is signed.