Trust Center

Security and Compliance Documentation

Version 1.0 · Effective July 27, 2026 · Re-issued at launch

Reviewing a new vendor normally means emailing for a HECVAT, waiting a week, signing an NDA, and sitting through a sales call to get documents that should have been public. This page skips all of that. Everything your information security office, accessibility coordinator and procurement office need is below, in full, at no cost, with no form.

The documents

DocumentWhat it coversStatus
HECVAT 4 responseOrganization, product, infrastructure, AI/ML governance, privacy, IT accessibilityPublished
VPAT 2.5 / ACRWCAG 2.2 AA, Revised Section 508, EN 301 549Published
DPA and FERPA addendumProcessor terms, school-official designation, GDPR clauses, SCCsPublished, ready to sign
Security overviewArchitecture, encryption, access control, audit logging, incident responsePublished
Sub-processor listEvery third party that touches data, and what they touchPublished
Privacy PolicyWhat we collect, what we never do with itPublished

Read this part first

The platform launches August 15, 2026, and capabilities roll out on a published roadmap from there. These documents describe the system as designed and as being built, not as independently audited in production. That distinction matters to a reviewer, so we are stating it at the top rather than burying it.

Every answer is either a description of an architectural decision already made and implemented, or an explicit commitment we are willing to be held to contractually. Where we do not have something, the document says so plainly instead of using language engineered to imply we do. We re-issue all of these against the running system as it ships, and the effective date on each page tells you which version you are reading.

What we do not have

Repeated here because it is the fastest way for you to decide whether to keep reading:

  • No SOC 2 Type II report. The audit costs more than this product's entire budget.

If your process makes SOC 2 a hard gate, we will not clear it today.

  • No ISO 27001 certification.
  • No independent penetration test yet. Scheduled before launch; the summary letter

will be posted here.

  • No cyber liability insurance. If your contract requires a certificate of insurance

naming your institution, we cannot currently provide one.

  • No dedicated, separately staffed security team. Security responsibilities sit with

the engineering lead who operates the platform.

Any of those may be disqualifying for you, and that is a legitimate decision. We would rather you reach it in ten minutes from a public page than in week three of a review.

What we do have

  • Multi-tenant isolation enforced at the framework level and covered by automated tests,

so an unscoped query fails rather than quietly returning another institution's records.

  • Encryption in transit (TLS 1.2+) and at rest, with sensitive fields additionally

encrypted at the application layer.

  • Append-only audit logging that institutional administrators can read for their own

institution, so a FERPA access review is answerable with evidence.

  • Optional campus SSO via SAML 2.0 and OpenID Connect, and it can be set to required.
  • All data stored in the United States.
  • An AI provider agreement that prohibits training on submitted content.
  • A written 72-hour incident notification commitment.
  • Contractual acceptance of the FERPA school-official obligations and GDPR processor

duties, pre-agreed and ready to sign.

If you need something else

Ask, and we will publish it here rather than send it privately, so the next institution does not have to ask.

That includes the official EDUCAUSE HECVAT 4.1.5 workbook: request it and we will complete and sign it, allowing about a week for the first one. A pre-completed downloadable copy is planned for this page before launch.

[email protected]