Compliance
Every standard below states our real relationship with it. Aligned means we run our program against the standard without holding the certificate; self-assessed means we completed the framework’s own questionnaire and will share it; applicable law binds us whether we like it or not. We would rather understate than let a badge imply an audit that hasn’t happened.
Standards and frameworks
7- ISO/IEC 27001:2022InfoSec complianceSelf-assessed64 controls
- SOC 2 (AICPA Trust Services Criteria)InfoSec complianceAligned18 controls
- HECVAT (Higher Education Community Vendor Assessment Toolkit)Higher educationSelf-assessed14 controls
- Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law10 controls
- GDPR (EU General Data Protection Regulation)PrivacyApplicable law5 controls
- FERPA (US Family Educational Rights and Privacy Act)PrivacyAligned2 controls
- WCAG 2.1 AA (VPAT 2.5, incl. Revised Section 508 and EN 301 549)AccessibilitySelf-assessed1 control
How the programme records its own failures
2Two records a vendor is not usually asked for, kept here rather than on the front page because they are about how we run the management system rather than about what the platform does for you. They are the honest test of whether any of the above is real.
- An external lead auditor decided for the first internal auditISO 27001 clause 9.2 requires that auditors do not audit their own work, and with one person there is no reading of that under which a self-audit qualifies. So the audit programme names an external lead auditor for the first review of 2027, with the options and their costs recorded rather than left vague.That audit has not happened yet, and the programme says so in those words rather than counting a founder review as an audit.
- Four times a control was not working, and we wrote each one upWhen something that was supposed to be running turns out not to have been, it gets a numbered entry with a root cause, corrective actions, and an effectiveness review dated later than the fix, because a corrective action is not proven by having been taken. Four have been raised and all four are now closed. Where a closure test was changed rather than met, the entry says so, names who decided it and when, and carries the decision to the next management review.The register is shared with procurement on request, in full. It is the most useful document we have about how this platform is actually run, and it is deliberately not a highlights reel.
We answer security questionnaires directly — HECVAT, your own template, or anything between. The completed HECVAT self-audit and the assessment reports are available on request.