Trust Center
Security and Compliance Documentation
Reviewing a new vendor normally means emailing for a HECVAT, waiting a week, signing an NDA, and sitting through a sales call to get documents that should have been public. This page skips all of that. Everything your information security office, accessibility coordinator and procurement office need is below, in full, at no cost, with no form.
The documents
| Document | What it covers | Status |
|---|---|---|
| HECVAT 4 response | Organization, product, infrastructure, AI/ML governance, privacy, IT accessibility | Published |
| VPAT 2.5 / ACR | WCAG 2.2 AA, Revised Section 508, EN 301 549 | Published |
| DPA and FERPA addendum | Processor terms, school-official designation, GDPR clauses, SCCs | Published, ready to sign |
| Security overview | Architecture, encryption, access control, audit logging, incident response | Published |
| Sub-processor list | Every third party that touches data, and what they touch | Published |
| Privacy Policy | What we collect, what we never do with it | Published |
Read this part first
The platform launches August 15, 2026, and capabilities roll out on a published roadmap from there. These documents describe the system as designed and as being built, not as independently audited in production. That distinction matters to a reviewer, so we are stating it at the top rather than burying it.
Every answer is either a description of an architectural decision already made and implemented, or an explicit commitment we are willing to be held to contractually. Where we do not have something, the document says so plainly instead of using language engineered to imply we do. We re-issue all of these against the running system as it ships, and the effective date on each page tells you which version you are reading.
What we do not have
Repeated here because it is the fastest way for you to decide whether to keep reading:
- No SOC 2 Type II report. The audit costs more than this product's entire budget.
If your process makes SOC 2 a hard gate, we will not clear it today.
- No ISO 27001 certification.
- No independent penetration test yet. Scheduled before launch; the summary letter
will be posted here.
- No cyber liability insurance. If your contract requires a certificate of insurance
naming your institution, we cannot currently provide one.
- No dedicated, separately staffed security team. Security responsibilities sit with
the engineering lead who operates the platform.
Any of those may be disqualifying for you, and that is a legitimate decision. We would rather you reach it in ten minutes from a public page than in week three of a review.
What we do have
- Multi-tenant isolation enforced at the framework level and covered by automated tests,
so an unscoped query fails rather than quietly returning another institution's records.
- Encryption in transit (TLS 1.2+) and at rest, with sensitive fields additionally
encrypted at the application layer.
- Append-only audit logging that institutional administrators can read for their own
institution, so a FERPA access review is answerable with evidence.
- Optional campus SSO via SAML 2.0 and OpenID Connect, and it can be set to required.
- All data stored in the United States.
- An AI provider agreement that prohibits training on submitted content.
- A written 72-hour incident notification commitment.
- Contractual acceptance of the FERPA school-official obligations and GDPR processor
duties, pre-agreed and ready to sign.
If you need something else
Ask, and we will publish it here rather than send it privately, so the next institution does not have to ask.
That includes the official EDUCAUSE HECVAT 4.1.5 workbook: request it and we will complete and sign it, allowing about a week for the first one. A pre-completed downloadable copy is planned for this page before launch.