Vendor assessment
HECVAT
Last updated: 2026-09-03
Universities assess cloud vendors with the EDUCAUSE Higher Education Community Vendor Assessment Toolkit. This page publishes the substance of our answers so a security reviewer can qualify Eduspera before the questionnaire is ever sent — and so the answers can be checked against what the product actually does. Where we do not meet an expectation yet, we say so.
Our HECVAT status
- HECVAT Lite — completed. Available to institutional reviewers under NDA; email [email protected] from an institutional address and we will send it with the security one-pager.
- HECVAT Full — completed on request for a formal procurement.
- Cloud Broker Index — not listed yet; we will submit after the first institutional assessment.
- Contracting entity — Design Excellent Group SL (NIF B02759603), Calle Blanquerna 53, 07003 Palma de Mallorca, Spain.
Summary of our answers
The areas below map to the sections a reviewer works through in HECVAT Lite. The full document adds the per-question detail and the supporting evidence.
| Area | Our answer |
|---|---|
| Hosting and data location | Application and database hosted in the EU. Primary data in Supabase (PostgreSQL) in Frankfurt, Germany; application runtime on EU infrastructure. No customer data is stored outside the EU except through the published sub-processors. |
| Multi-tenant isolation | Every table is protected by PostgreSQL Row Level Security keyed on the institution (tenant). Cross-tenant access exists only through audited, service-role administrative paths on the server. |
| Encryption | TLS 1.2+ for all traffic in transit; encryption at rest at the database and object-storage layer; secrets held in an encrypted vault outside the codebase. |
| Backups and recovery | Continuous database backups with point-in-time recovery (PITR). Target RPO ≤ 24 h and RTO ≤ 8 h for a major incident; infrastructure reproducible from version control. |
| Incident response and disclosure | Documented incident-response process; affected institutions notified without undue delay and within 72 hours of awareness for a personal-data breach. Coordinated vulnerability disclosure policy published on the Trust Center. |
| Sub-processors | Published list with purpose, region and safeguard for each provider; updated before a new sub-processor handles personal data. |
| Authentication and SSO | SAML 2.0 single sign-on with your IdP (Shibboleth, Entra ID, Okta, Google Workspace), just-in-time provisioning by email domain, InCommon metadata supported. SCIM 2.0 provisioning and de-provisioning. Email-based 2FA with device trust on the administrative zone. |
| Audit logging | Append-only audit log of sensitive actions (sign-in, role changes, enrolment, grading, content publish, exports) per institution, viewable by your administrators and exportable as CSV. |
| Data export and erasure | Full tenant export (courses, learners, enrolments, progress, certificates) and per-learner personal-data export are self-service; erasure requests handled within the GDPR timelines and logged. |
| Access control | Role-based access (administrator, instructor, manager, learner) with department-level (org unit) scoping; least privilege for staff; service-role keys never reach the browser. |
| Student records (FERPA) | Our Data Processing Agreement includes a FERPA “school official” clause: student records are processed only on the institution’s documented instructions, under direct institutional control, and are not used for any other purpose. |
| Accessibility | WCAG 2.2 AA as a product requirement, not a remediation project. Accessibility Conformance Report (VPAT 2.5 INT) published and regenerated with each release; axe-core runs in the deployment pipeline; independent third-party audit in progress. |
| Third-party attestations | No SOC 2 report yet. We say this plainly: a SOC 2 programme is planned and will be initiated on contract with the first institution that requires it. No ISO 27001 certificate. HECVAT Lite completed and available under NDA. |
Supporting documents
- Accessibility Conformance Report (VPAT / ACR) — WCAG 2.2 AA, EN 301 549 and Section 508, regenerated with each release and downloadable as a PDF.
- Sub-processor list — purpose, region and safeguard for every provider that can touch personal data.
- Data Processing Agreement — GDPR Article 28 with a FERPA “school official” clause, sub-processor list and EU Standard Contractual Clauses; on request.
- Security one-pager — hosting, encryption, tenant isolation, backups, incident response and access control on a single page; on request.
- Trust Center — the full set of security and privacy commitments, and our published policies.
- HECVAT explained — what the questionnaire covers, how reviewers read it, and what separates an answer that clears review from one that stalls.
Running a pilot
Security review and pilot setup run in parallel. The university pilot kit sets out a 12-week plan with named owners on both sides, the four metrics we report at the end, and the technical checklist your identity and data teams will work through — SAML SSO, SCIM provisioning, custom domain, institutional email sender, LTI 1.3 and data export.
Frequently asked questions
What is the HECVAT?
The Higher Education Community Vendor Assessment Toolkit is a standardised security questionnaire maintained by EDUCAUSE and REN-ISAC. Instead of every university writing its own vendor assessment, institutions send the same set of questions and compare answers consistently. It comes in three sizes: Full, Lite and On-Premise.
Which HECVAT version has Eduspera completed?
HECVAT Lite. It is available to institutional reviewers under NDA. We complete the Full HECVAT on request when an institution requires it for a formal procurement.
Is Eduspera listed in the Cloud Broker Index?
Not yet. The Cloud Broker Index publishes completed HECVATs from vendors assessed by member institutions, so listing follows a first institutional assessment rather than preceding it. We will submit ours after the first university pilot completes its review.
Do you have a SOC 2 report?
No, and we would rather say so than imply otherwise. Our security policies are published and the underlying controls are operating, but no independent auditor has attested to them yet. A SOC 2 Type I audit is commissioned on contract with the first institution that requires it, followed by Type II after the observation period.
How do you handle student records under FERPA?
Our Data Processing Agreement includes a FERPA “school official” clause. Student records are processed only on the institution’s documented instructions, remain under the institution’s direct control, and are never used for any other purpose, including model training.
How long does a security review usually take?
Most reviewers qualify us from this page in a single sitting, then request HECVAT Lite and the security one-pager to confirm. Where a full HECVAT and a DPA negotiation are needed, allow two to four weeks; that runs in parallel with weeks 1–4 of the pilot plan rather than blocking it.
Contact
Security, privacy and vendor-assessment requests: [email protected]