HECVAT (Higher Education Community Vendor Assessment Toolkit)
A full HECVAT answer pack is maintained and kept current for university procurement, deliberately honest about gaps (no SOC 2 or ISO attestation, no independent penetration test, PITR not enabled). It is a vendor self-assessment, not an externally validated response, backed by a full internal HECVAT-aligned self-audit.
Controls mapped to this standard
Each control page lists the specific requirements it helps satisfy.
Data · 1
Identity and access control · 1
Monitoring · 3
Business operations · 2
Product delivery · 3
Customers · 1
Vendors · 1
Policies behind those controls
- Information security policyGovernance
- Compliance postureGovernance
- Access control policyData security and privacy
- Data retention and lifecycle policyData security and privacy
- Change management policyApplication security
- Accessibility self-assessment (WCAG 2.1 AA)Application security
- Phishing and social engineering policySecurity operations
- Logging and monitoring policySecurity operations
- Business continuity and wind-down policySecurity operations
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.