For IT reviewers
This page helps security, privacy, and procurement reviewers evaluate SpeechGradebook before or during adoption. All linked articles are available without signing in.
Recommended review order
- Trust overview
- Security plan
- Security overview
- HECVAT 4 response guide
- Completed HECVAT 4.1.6 workbook
- Institutional addendum (U.S. residency / LTI 1.3 / MFA)
- VPAT / Accessibility Conformance Report
- Privacy and legal policies
- Subprocessors and data locations
- FERPA and student records
- Data handling and retention
- Student consent model
- Role permissions
- Incident response and contact
Architecture summary
| Component | Purpose |
|---|---|
| SpeechGradebook web app | User interface and API (FastAPI on Render) |
| Supabase | Authentication, database, and media storage (AES-256 at rest; U.S. residency for U.S. institutions) |
| SpeechGradebook Model (Qwen) | AI evaluation service (proxied via /qwen-api/*) |
| LTI 1.3 | Canvas/LMS launch SSO (OIDC) |
Row-level security (RLS) in Supabase restricts data access by role and institution. Audit logs record access to student evaluation data. MFA (TOTP) is available for portal logins; LMS users authenticate via Canvas/LTI (and any campus MFA required there). Instructional media uploads are authenticated; objects are currently served via public object URLs under user/institution path prefixes (private bucket + signed URLs planned).
Legal and policies
-
Completed HECVAT 4.1.6 workbook: Download Excel
-
Institutional addendum: U.S. residency / LTI / MFA
-
Blank template: EDUCAUSE HECVAT toolkit
-
For a DPA or signed security addendum, contact ValidBound.