UAI, in one document.
Written for the people who evaluate rather than the people who browse. Architecture, security, evidence, deployment and procurement, with the limitations stated alongside the capabilities.
Sleipnirtech Private Limited, New Delhi. Last revised September 2026. This page is written to print on A4.
What it is
UAI is a campus intelligence platform. It places a single application, a single sign in and a single AI assistant in front of everything an institute already does, and it turns the daily use of that application into records the institute can rely on.
It is not an ERP and does not replace one. Existing systems for admissions, fees and examinations continue to operate. UAI is the layer students and faculty use each day, which is why the data that comes out of it reflects what actually happened.
UAI is built for every university. IIT Delhi is the first to run it, and the platform is in production on its campus.
The problem it addresses
Institutes rarely lack systems. They lack evidence that is ready when it is asked for.
Attendance is collected on paper and cannot be verified afterwards. Course feedback is gathered near the deadline and compiled by hand. Accreditation data is reconstructed from departments under time pressure. Students resolve institutional business over WhatsApp and by walking to offices, so none of it reaches a system at all.
The common cause is that the institute’s systems are systems of record, opened when something must be filed, while the institute’s people are somewhere else.
What it does
Listed institution first, because that is the order in which it is likely to matter to whoever is reading this.
For the institute and its faculty
- Attendance, session based, one device per student, exported as a complete register
- Course feedback, with a private teaching report for each professor whose figures are computed rather than generated
- Compiled documents for AICTE, NAAC 1.4.1, NAAC 2.7.1 and NBA, produced from that same data
- Hostel complaints, with escalation when they are not attended to, and a dean’s view of what is still waiting, by hostel and by trade
- Minutes of meeting, searchable and answerable, under board level access control with a separate clearance axis for sensitive items
- Platform health and usage analytics, so the institute can see whether what it bought is being used
For the academic day
- Timetable, per student, with changes announced by official mail detected and offered to the students affected
- Courses and materials, synchronised from the institute’s learning system
- Past papers and notes, contributed and searchable
For the rest of campus life
- Institutional mail, with urgent items surfaced ahead of the rest
- Library catalogue search
- Health service information
- Clubs and campus events
Across all of it
- One assistant, answering from the institute’s own data
Architecture and data residency
The language model that answers questions is self hosted. It is not an API subscription to a model owned by another company.
The platform can be deployed two ways: on our infrastructure in India, or on hardware inside the institute’s own campus. The product is the same in both. The second option exists because the architecture was built for it, and it is not available from vendors whose AI is a call to somebody else’s model.
The practical consequence, stated plainly: no student record, no email content, no faculty document and no question anyone asks is transmitted to an external AI provider, because the architecture contains none.
This is an architectural property rather than a contractual undertaking. A policy can be revised. An architecture that has no outbound path cannot quietly acquire one.
Security and privacy posture
Identity
Authentication is against the institute’s own directory. No separate credential is issued and no roll list is migrated.
Biometrics
Attendance verification computes a face signature on the student’s own device and stores it there. No image and no template reaches a server. The server holds only the fact that verification succeeded, and a confidence figure.
Encryption
Mail content and stored credentials are encrypted individually at rest, under a key hierarchy that permits rotation without decrypting the protected data.
Access control
Sensitive material, including meeting minutes, is governed at the database level rather than in application code, so a mistake in a screen cannot widen access.
Minors
Guardian consent is collected where a student is under eighteen, which the DPDP Act requires and which a college intake routinely includes.
Deletion
A student can delete their account and have their data purged, from within the application or from the public website without installing anything.
Regulatory position, stated honestly
The DPDP Rules 2025 were notified in November 2025. The operative duties of a data fiduciary bind from approximately May 2027, with penalties to 250 crore. An institute holding student data is a data fiduciary.
What is built today: on device biometrics, envelope encryption, guardian consent for minors, self service deletion, data minimisation, and a published privacy policy with a named grievance officer.
What is scheduled before the deadline: an itemised consent ledger, a data access and export facility, automated retention and erasure, and a breach notification runbook.
We describe this as aligned to the DPDP framework and building toward the deadline. We do not describe it as compliance already achieved, and we would treat any vendor who did so in September 2026 with caution.
What the institute provides
- Directory access for authentication
- Read access to the learning system for course material, where that is wanted
- A server with a GPU, only if you want the AI running on campus. Otherwise it runs on ours, in India
- A sponsoring department and one named contact
That is the whole list. There is no migration and no data preparation phase.
Deployment
- Semester 0. One department, one semester, chosen modules. Existing systems untouched.
- Week 1. Students sign in with the institute email they already have.
- Semester end. A verifiable attendance register, or a completed feedback cycle with its compiled documents.
- Then. Widening, department by department, on the basis of measured adoption rather than on a plan agreed in advance.
Adoption figures are visible to the institute from the first week. If a department is not using it, that is a reason to stop, and the institute should have the evidence to make that call.
Current deployment
IIT Delhi is the first institute to run UAI. The platform is deployed and in production on its campus.
We would rather name the institutes we are live at than present a client list. For an institute assessing whether this will work on its own campus, one deployment running at full depth is the more informative evidence, and we are able to discuss it in detail rather than in summary.
Commercial and procurement
- Sleipnirtech Private Limited is an Indian company registered in New Delhi. CIN and GST registration are available for the file.
- DPIIT startup recognition has been applied for and is not yet granted. When granted, GFR Rule 173 relaxes prior turnover and prior experience conditions and Rule 170 exempts bid security. We state this as it stands rather than as we expect it to stand.
- Software licences are goods within GFR Rule 143, together with the installation, training and support supplied with them, so the ordinary Chapter 6 route applies.
- We will provide a functionally written specification, describing outcomes rather than naming a product, which your department can adapt for the indent.
- Contracted annually, with a genuine renewal decision at the end of each year rather than a multi year commitment taken at the start.
- Pricing is provided in the briefing, against the scope the institute actually wants.
Limitations
- IIT Delhi is our first live deployment. Depth is our evidence, not breadth.
- The DPDP work listed in section 06 is genuinely scheduled rather than complete.
- Modules vary in maturity. Attendance, timetable, mail and the assistant are in daily use. The feedback and accreditation module is built and tested but has not yet run through a complete semester cycle, because the feedback window opens at the end of term. We would rather tell you that than let you assume otherwise.
- We are a small company. That is why we start with one department, and why we would rather you widen on evidence than on a plan.
Next step
A conversation about your institute rather than a demonstration of ours. Tell us which department feels the problem most.