NextPass
Privacy, IP, and data — plainly

Two things we protect like the business depends on it. Because it does.

01Your learners' privacy

Practice is private. That's why it works.

Transcripts are never shown to employers

Not to HR, not to program managers, not to facilitators. Organizations see scores, trends, and proficiency signals — never a learner's words, and never anything traceable to a person.

Privileged reads are logged

A facilitator opening a learner's record writes an audit row. The boundary itself is enforced in the database — not a paragraph in a policy.

Learners see everything about themselves

Their scores, their evidence, their trajectory. It's their development.

02Your curriculum's IP

Your method stays yours. There is no ours.

Your materials stay yours

Encoded scenarios, rubrics, and coach language are scoped to your organization and the clients you designate.

We don't train AI models on your data

Not on your curriculum, not on your learners' conversations. Processing runs your sessions and scores them — that's it.

No house curriculum

We're not accumulating your method into ours. NextPass ships empty on purpose.

03Data posture

We store the minimum, on serious infrastructure.

Development data, not personnel records

Scores against your rubrics, session metadata, and the feedback shown to the learner. NextPass makes no hiring, promotion, or termination decisions — and isn't built to.

Established providers

Voice, hosting, database, and scoring run on established infrastructure providers whose platforms carry SOC 2 / HIPAA compliance attestations. (Their attestations — we don't claim our own certification.)

Enterprise SSO

Available for enterprise rollouts, so access rides on your identity provider.

The questions your security team will ask anyway.

Data flows, subprocessors, retention, deletion, model inventory, AI guardrails — all of it is written down, with every claim labelled by how it’s verified.