CopilotRNBack to site
CopilotRN private pilot

Pilot security

Current security controls, data restrictions, and instructions for reporting a security issue.

Effective August 15, 2026
The pilot accepts synthetic or deidentified course briefs only.

It does not accept course files or regulated institutional information.

Access control

Pilot access is limited to individual accounts. CopilotRN stores a one-way verifier for each password. A successful sign-in creates a secure session cookie; disabling or rotating an account ends its active sessions.

Preview data

The product stores the approved brief, planning context, model-generated draft, run status, model configuration, token use, and estimated API cost. Faculty edits, locks, and section approvals made after generation currently remain in the browser session; reloading restores the original saved model draft. Fixed-choice interaction and feedback events are also recorded for evaluation.

Network and service boundary

The pilot is served over HTTPS from a dedicated Amazon Lightsail deployment. Only the web gateway is exposed to the internet. The course-planning service sends the approved brief, graduate-nursing profile, and source descriptors to Anthropic to generate a structured draft. It does not send course files because file upload is disabled. The interest form and evaluation events send only the fields described in the privacy notice.

Not approved for regulated data

This pilot has not been approved for student records, protected health information, patient data, clinical records, or confidential institutional files. It does not claim a security certification or institutional compliance status.

Report a security concern

Send suspected security issues to security@copilotrn.com with the affected URL, a description of the issue, and steps to reproduce it. Do not access another person’s information, disrupt the service, or run automated testing without written permission.