How we use AI securely

Last updated June 2026. Questions? Contact us.

Where inference runs

All AI inference for SENguru runs on AWS Bedrock, Amazon's managed AI service, pinned to a single region, eu-west-2 (London), for UK data residency. Every model we use is invoked in-region in London; we do not route requests across regions. By default your data stays in the UK, in line with our privacy policy and UK GDPR obligations.

There is one exception, and it needs your permission. New models sometimes arrive in eu-west-1 (Dublin) months before London. We will only ever send your data to Dublin for AI processing if you have given us explicit consent, and we will ask you plainly rather than burying it in a settings page. Decline, or simply never be asked, and your AI processing stays in the UK: we would rather leave a new model unused than move your child's case data without you agreeing to it.

Sandboxing: your data goes nowhere else

The inference call has no outbound network path beyond the managed Bedrock endpoint. Your data is sent only to generate the requested output; it cannot reach any other system, third-party service, or public internet address while the model is running.

Never used for training

AWS Bedrock's standard terms, and our service agreement, prohibit using customer data to train or improve foundation models. Your child's data is never used to train any AI model. This applies to every piece of text we process on your behalf: emails, documents, chat messages, and form drafts.

The legal corpus we use

Every AI prompt we send includes a curated SEND legal corpus: the Children and Families Act 2014, the SEND Code of Practice, relevant case law, and our own annotated commentary. This grounds the model's responses in the actual law that governs your child's rights, rather than generic internet text. We review and update the corpus regularly.

Your choice: disabling AI

If you'd prefer not to have any LLM inference run over your child's data, you can turn all AI features off from Settings → AI features.

What you lose when AI is off:

  • AI summaries, key points, and action items on emails and contacts
  • AI-extracted case data and reader summaries on uploaded documents
  • Document search (RAG-powered smart chat)
  • Smart chat assistant
  • EHCP draft review and counter-proposal drafting
  • Form filler (EHCNA and other forms)
  • Automatic follow-up suggestions

Non-AI features (email forwarding, document storage, manual follow-up tracking, deadlines, case notes) keep working regardless.

We don't recommend disabling AI, because it removes most of what makes SENguru useful. But we respect that some families feel strongly about this, and we will always honour your choice.

Open questions (not yet decided)

We are considering whether to publish our system prompts and legal corpus publicly. Doing so would increase transparency but also creates a prompt-injection risk (bad actors crafting emails designed to manipulate the model's output). We are working through this trade-off. If you have a view, let us know.