Inside the Platform

Every layer of Orchen, in detail.

Everything under the hood: how the AI is built to teach, what the insight layer actually computes, how six roles are scoped, and the compliance posture your security review will sign off on.

For IT directors, curriculum leads, and school heads in active evaluation.

Layer 01
The student environment A Socratic tutor, an assignment shelf, a Writing Studio, and a private space that belongs to the student alone.
Layer 02
The insight & role system Conversations become structured insight, scoped to six roles that each see only what they need.
Layer 03
The compliance foundation Row-level security, immutable audit logs, per-school retention, and source deletion within seven days.
01 The Student Experience

A chat surface, an assignment shelf, a flashcard library, and a private workspace.


Students see Orchen as a conversation. Behind it: a system that adapts to how they think, an assignment workflow their teachers configured, a flashcard library built automatically from their chats, and a private workspace that belongs to the student alone.

orchen · student chat · live capture
The conversation surface students work in every day, live.
orchen · Writing Studio
Orchen Writing Studio
The dedicated essay surface with rubric-aware feedback.
orchen · quiz
Quizzes built from the session, graded semantically, not word-matched.
The conversation

Guides through questions, not answers

The Socratic pattern is hard-coded into the system architecture, a commitment deeper than any setting. Even the most creative “just give me the answer” prompt gets a guiding question back.

Adaptive presentation

Four modes, selected in real time

Verbal exploration, structured guidance, examples-first, step-by-step, chosen in real time from the student's response patterns. A student who learns by example sees examples first.

The assignment shelf

Teacher assignments in the sidebar

When a teacher creates an assignment it appears in the student's sidebar with a Launch screen. Work, submission, and reflection all happen in-chat.

Flashcards & quizzes

Concepts extracted, graded semantically

Orchen extracts key concepts from sessions and offers to save them as flashcards, grouped by subject. Quizzes use semantic grading, not exact-word matching.

The private workspace

Goals and a journal that stay the student's alone

Students set goals, keep a private journal, and tune their own preferences. None of it is visible to teachers, advisors, or parents unless the student shares it.

Multimodal input

Images handled natively

Students upload images alongside their messages and the AI handles them natively. A student stuck on a physics diagram can photograph it and Orchen guides accordingly.

02 The Teaching Architecture
Pedagogy encoded as system behavior, not marketing language.

A set of specific rules in the AI's system prompt and the product's structure. Each is operational, not aspirational.

The Socratic posture

Asks before it answers

The AI's first move is to ask what the student has tried, understands, or is stuck on. Only after they engage does Orchen begin to guide.

The Circle Rule

Two wrong answers, then a new approach

After two consecutive wrong answers on the same concept, Orchen switches approaches, different example, framing, entry point, instead of the same dead end.

Concept vs. mechanical

Two question types, two responses

Conceptual questions ("why does this work?") get unpacked through reasoning. Mechanical questions ("how do I compute this?") get scaffolded through steps.

Partial examples

The example stops before the last step

Rather than a complete example to copy, Orchen works partial examples that stop short. The student finishes, preserving the productive struggle learning requires.

Land the plane

When the student has it, Orchen stops

Once a student reaches the answer through their own work, Orchen recognizes it and stops guiding. Recognition is part of the pedagogy.

Subject modules

The prompt extends per discipline

The system prompt extends differently for math, writing, science, and history. Writing gets prewriting scaffolds; math gets worked-example logic.

Assignment workflow

Three kinds, each carrying metadata

Each assignment carries lesson context, key concepts, vocabulary, common misconceptions, success criteria, a scenario hook, and a parent-friendly explanation.

Writing Studio

A dedicated, rubric-aware essay surface

TipTap editing, prewriting worksheets (explore → thesis → outline → ready), rubric-scored draft checks, inline comments, and configurable mechanical feedback.

03 The Insight System

Structured insight, computed nightly, surfaced where it matters.


Every conversation feeds an analysis pipeline that produces structured insight, learning profiles, concept distributions, struggle and strength tags. Source conversations are deleted within seven days; what remains is the synthesis.

orchen · teacher class view · live capture
From class distribution to a single student in two clicks.
orchen · teacher insight
Orchen teacher insight dashboard
What teachers see: synthesis, not raw transcripts.
Concept progress, a class, not a leaderboard
Demonstrated repeatedly
42%
Demonstrated once
26%
In progress
21%
Not yet touched
11%

Illustrative distribution across the four evidence levels.

Learning profiles

Pace, examples, modality, and what works

Each profile captures pace, preferred examples, modality (verbal, visual, example-based, step-by-step, conceptual), and the guidance that works. It updates continuously as the student interacts.

Concept-level progress

Four buckets, not a leaderboard

Every concept across every conversation is tracked into one of four buckets. Teachers see the class as a distribution, not a ranking of who scored what.

Struggle & strength

Tagged by subject, surfaced as chips

Topics where the student gets stuck or excels, tagged by subject and updated as patterns become clear, shown as colored chips on the advisor dashboard and in the weekly narrative.

Weekly narratives

A structured narrative per advisee

Independent effort, curiosity depth, critical-engagement signals, and any concerning patterns, generated automatically from interaction data, not surveys or self-reports.

Longitudinal profile

Years of trajectory, synthesized

A senior who has used Orchen since freshman year has a four-year trajectory captured as structured insight, a synthesis of how their thinking changed, not transcripts to scroll.

Topic re-classification

Tags update as the conversation evolves

Conversations are re-classified every five student messages, so the sidebar stays organized without the student having to maintain it.

Crisis detection

Every conversation scanned, every flag tracked

Every conversation is scanned for concerning content, self-harm indicators, distress signals, references to harm by others. Detected content is flagged automatically and routed to the school's designated counselor, carrying a 24-hour urgency indicator and moving through a full lifecycle (open, reviewing, resolved, or escalated).

04 The Role Architecture

Six roles. Each sees only what their role needs to see.


The data model is organized around six roles, each with a defined view of student data, scoped, narrative, synthesized. The boundaries are enforced architecturally, not through policy documents.

RoleWhat they seeWhere the boundary is
Student Own conversations, flashcards, assignments, goals, and private journal. Nothing about other students. The private workspace is invisible to every other role unless the student shares it.
Teacher Structured insight for their classes, profiles, concept distributions, session summaries, struggle/strength areas, assignment progress, rubric scores. No raw transcripts unless the student or school explicitly grants access.
Advisor Weekly synthesized narratives for each advisee, immediate crisis flags, and parent-note tools. Shared sessions only, students choose what to share.
Parent Weekly digests at the school's visibility level: conversation starters, techniques, subject activity, overdue assignments. Five visibility tiers; the school sets the default and the ceiling any parent can request.
School admin School-level configuration: AI identity, mechanical-feedback toggles, parent visibility, crisis routing, white-label branding. School-scoped, no access across other schools.
App admin Full user management with audit logging (Orchen team). Service-role isolated; never views conversations except documented, logged, privacy-bounded review.
05 School Configuration
You set the defaults. The defaults are yours.

Behavior is configured at the school level, what the AI looks like, what parents see, how feedback is delivered, where flags go, and how it's branded.

AI identity

A tutor that matches your voice

The system prompt defining how Orchen presents itself is configurable per school; premium schools can override the default model. Name, voice, and pedagogical defaults match your institution.

Mechanical feedback

Grammar, punctuation, style, independent

Three categories toggle independently. Flag only grammar, all three, or none, a Writing Studio with or without mechanical highlights, your call.

Parent visibility

Five tiers, a default and a ceiling

From summary-only to full transcript. The school sets the default and the maximum any parent can request, and can require student notification on an upgrade.

Crisis routing

Flags stay in your designated chain

Schools designate the counselor or safeguarding lead who receives flags. The urgency indicator and lifecycle tracking are configurable; crisis content never leaves the chain.

White-label branding

The AI presents as the school's tutor

Premium schools show their own logo and name above every Orchen message. The school's brand sits where Orchen's would, so the AI presents as the school's tutor, not a generic product.

06 Compliance & Security
The architecture your security review will pass.

Supabase Postgres with strict row-level security, immutable audit logging, per-school retention, and a service-role isolation model.

Row-level security

RLS enforced at the Postgres level

Every table has RLS policies. Role-based access is checked via SECURITY DEFINER helpers to prevent recursion; service-role operations are isolated from user-facing access and cannot accidentally cross.

Immutable audit logging

Insert-only, RPC-mediated

Every staff access is logged via log_audit_event. The audit_log table is insert-only, direct inserts blocked; all writes go through the RPC, which verifies the actor server-side.

Data retention

Per-school policy, swept nightly

Each school sets retention for messages, sessions, quiz results, and snapshot keep-counts. The pg_cron job runs nightly. Crisis flags are exempt until resolved.

Source deletion

Source deleted within seven days

Source conversations are deleted within seven days of analysis, after the nightly pipeline has distilled them into profiles, concept progress, and narratives. Long-term insight compounds from those distillations, so understanding deepens over the semester with zero need to re-read old chats. Crisis-flagged content is preserved with its context until resolved.

Consent management

Tracked, versioned, revocable

Every account has a consent_records entry. Students without one enter a non-persistent Guest Mode where conversations are not saved.

Right to be forgotten

Soft-delete, anonymize, export

Accounts can be deleted at any time: soft-delete the profile, anonymize crisis records, trigger retention compliance. A full export is offered before deletion.

FERPA & COPPA

Built around the statutory boundaries

Built around FERPA's visibility boundaries and COPPA's under-13 protections. Under-13 schools add restrictions via the role-gate; audit logs satisfy FERPA record-access documentation.

Crisis-flag anonymization

Record preserved, identifier removed

On account deletion, crisis flag history is anonymized rather than deleted, preserving the safeguarding record while removing the personal identifier.

07 Data Lifecycle

A single conversation, end to end.


The path of one student-AI conversation through Orchen, from creation, through analysis, to deletion. Every step is logged, scoped, and documented.

1
Day 0
Creation

The student opens a new chat. A session row is created; each message is stored against it with RLS scoping to the student. Visible only to the student.

2
Day 0–7
Live conversation

Messages save as they happen. Topic classification updates every five messages, concept progress increments, crisis detection scans every message. Still the student's private surface.

3
Day 1–7
Nightly analysis

The pipeline runs nightly: learning profile, concept distribution, and struggle/strength tags update; weekly narratives compile; crisis flags route to the designated counselor.

4
Day 7
Source deletion

The source conversation is deleted from the messages table. The session row remains with derived insight attached, the synthesis stays, the conversation that produced it is gone.

5
Day 7+
Derived insight persists

Learning profile, concept progress, and longitudinal trajectory remain. The student's own view shows continuing work, flashcards, assignments, goals, not the deleted sources.

6
Year-end
Retention sweep

The pg_cron job sweeps per the school's policy. Insight may persist for years if configured; source data is already gone.

7
Anytime
Account deletion

Student or admin initiates deletion. Profile soft-deletes, crisis flags anonymize, an export is offered. The audit log of the deletion itself persists.

Ready to see it in motion?

A 30-minute walkthrough is the fastest way to verify any of the architecture above against the live product.

Book a walkthrough →