Tenant exit and export
On exit — the customer's or ours — each institution receives its full machine-readable export before anything is deleted, ending with hard deletion and, on request, a certificate of destruction. This is a contractual commitment backed by the data being ordinary Postgres rows and storage objects; the tenant-teardown orchestration that would automate it is still to be built.
Standards mappings
This control maps to the following standards and frameworks. Each entry states our real relationship with the standard, and the specific requirements this control helps satisfy.
HECVAT (Higher Education Community Vendor Assessment Toolkit)Higher educationSelf-assessed
A full HECVAT answer pack is maintained and kept current for university procurement, deliberately honest about gaps (no SOC 2 or ISO attestation, no independent penetration test, PITR not enabled). It is a vendor self-assessment, not an externally validated response, backed by a full internal HECVAT-aligned self-audit.
- ExitVendor viability and data exit
Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law
The primary legal regime. APP 8 drives the residency objective and every disclosed cross-border flow, APP 11 drives retention and erasure, and the Notifiable Data Breaches scheme's assessment clock is built into the incident runbook with OAIC contacts documented. The privacy policy, terms, and DPA template are counsel-reviewed and approved.
- APP 11.2Destruction and de-identification
Policy mapping
The written standard this control enforces:
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.