HECVAT 4 response guide
This page is ValidBound LLC’s companion response guide for SpeechGradebook, aligned to HECVAT 4 (Higher Education Community Vendor Assessment Toolkit™).
:::important Completed workbook Download ValidBound’s completed HECVAT 4.1.6 workbook:
HECVAT-4.1.6-SpeechGradebook-ValidBound.xlsx
This file is the official EDUCAUSE HECVAT 4.1.6 template with SpeechGradebook / ValidBound LLC answers filled on START HERE, Organization, Product, Infrastructure, IT Accessibility, Case-Specific, AI, and Privacy.
Also see the Institutional addendum (U.S. residency, LTI 1.3, MFA, AI kill-switch).
Blank template source (EDUCAUSE): Higher Education Community Vendor Assessment Toolkit (current version 4.1.6).
HECVAT™ is a trademark of EDUCAUSE. Regenerate answers with python scripts/fill_hecvat_workbook.py after updating response content.
:::
How HECVAT 4 works
Per EDUCAUSE, HECVAT 4 rolls the former Full, Lite, and On-Prem templates into one workbook:
- Open the EDUCAUSE file and complete the Start Here / required gateway questions.
- The workbook routes you to applicable sections.
- Solution providers complete all questions that apply to their product (typically once per year) and may share the same completed file with multiple institutions.
- Institutions can evaluate with a lighter high-risk / Core view when that matches their risk process (this replaces a separate “Lite” file).
Primary HECVAT 4 sections:
| Section | SpeechGradebook applicability |
|---|---|
| Organization | Yes |
| Product | Yes |
| Infrastructure | Yes (cloud SaaS) |
| IT Accessibility | Yes |
| Case-Specific | Generally limited (no HIPAA/PCI product path for SpeechGradebook education records) |
| Artificial Intelligence | Yes |
| Privacy | Yes (FERPA-relevant education records) |
Corporate FAQ: HECVAT FAQs for Corporations.
Product identity (for Start Here)
| Field | Value |
|---|---|
| Product | SpeechGradebook |
| Vendor | ValidBound LLC |
| Assessment date | July 2026 |
| Deployment | Vendor-hosted cloud SaaS (not on-premises) |
| Audience | Higher education instructors, admins, and Practice users |
| Data types | Faculty/staff accounts; student education records (evaluations, scores, feedback, speech media for instructional hosting) |
Start Here — gateway answers
Use these when filling the official Start Here / required questions tab. Exact question IDs may vary slightly by workbook build; match by topic.
| Gateway topic | SpeechGradebook answer |
|---|---|
| Solution / service type | Web application (SaaS) for AI-assisted speech evaluation and practice; LTI 1.3 Canvas/LMS integration |
| Hosting / deployment | Cloud / vendor-hosted (not customer on-premises); U.S. residency for U.S. institutions |
| Processes student education records / FERPA data? | Yes (when institutions use cloud evaluation and storage features) |
| Processes payment card data (PCI) in the product? | No for institutional course gradebook education records. Stripe processes payments for SpeechGradebook Practice Plus and ValidBound Coaching; card data is handled by Stripe, not stored as course gradebook content. |
| Processes protected health information (HIPAA)? | No (not a HIPAA-covered product offering) |
| Includes AI / machine learning? | Yes — SpeechGradebook Model for rubric-aligned evaluation assistance |
| Accessibility documentation available? | Yes — Accessibility Statement and VPAT / ACR |
| Shared / multi-tenant service? | Yes — multi-tenant with logical isolation (roles + row-level security) |
Organization
| Theme | Response |
|---|---|
| Legal entity | ValidBound LLC |
| Product operator | ValidBound LLC operates SpeechGradebook |
| Security contact | Contact form — note Security |
| Privacy contact | Privacy Policy; info@validbound.com |
| Written security plan | Yes — Security plan |
| Incident response process | Yes — Incident response and contact |
| Operator access | Production access limited to ValidBound operations roles needed to run the service |
| Access discipline | Least-privilege access to production credentials and data platforms |
| Third-party risk | Subprocessors listed publicly — Subprocessors |
| Contracts / DPA | Institution-specific DPA or addendum available on request |
Product
| Theme | Response |
|---|---|
| Authentication | Supabase Auth for portal login; LTI 1.3 (OIDC) SSO for Canvas/LMS launch; SAML/CAS evaluable per contract |
| MFA | Available on portal login via Supabase Auth TOTP (optional today); LMS users use Canvas MFA/auth |
| Authorization | Role-based UI + PostgreSQL row-level security (RLS) by user, role, and institution |
| Sessions | Token-based sessions via Supabase over HTTPS |
| Application security | Model/proxy secrets stay server-side; protected API routes validate sessions |
| Logging | Access to student evaluation data logged (who/what/when/action/context) |
| Change management | Hosted deploys via application pipeline on Render |
| Continuity | Supabase automated backups + PITR; target RPO ≤ 24h; formal ValidBound BCP/DRP on roadmap |
| Export / deletion | Instructors/admins can export and delete per product functions; retention per agreement |
| Integrations | LTI 1.3 Advantage for Canvas/LMS (current); standalone IdP SSO per contract |
Infrastructure
| Theme | Response |
|---|---|
| Hosting | Render (app/API), Supabase (Auth, PostgreSQL, Storage), Modal (model inference); Stripe (Practice/coaching payments); optional Sentry / SMTP when configured |
| Data residency | U.S. for U.S. institution deployments (including UTK) — not transferred outside the U.S. in the standard hosted configuration |
| Encryption in transit | TLS 1.2+ |
| Encryption at rest | AES-256 via Supabase PostgreSQL and Storage |
| Network exposure | Public HTTPS app endpoint; end users access data only through Auth/RLS-enforced paths |
| Backups | Supabase automated backups + PITR; target RPO ≤ 24 hours |
| WAF | Cloudflare DNS-only today; edge WAF available for institutional deployments on request |
| Vulnerability handling | Reports via contact form; prioritized remediation and credential rotation when needed |
| Penetration testing | No third-party pen test in the last year; can schedule and share under NDA |
| Tenancy | Multi-tenant with logical isolation via RLS and institution boundaries |
IT accessibility
| Theme | Response |
|---|---|
| Target standard | WCAG 2.1 Level AA |
| Public statement | Accessibility Statement |
| VPAT / ACR | VPAT / ACR (self-assessment) |
| Assistive technology | Spot-checked with major screen readers and keyboard navigation on core flows |
| Known gaps | User-uploaded video captions; some dense analytics/chart experiences |
| Feedback | Aim to respond within 5 business days |
Artificial intelligence
| Theme | Response |
|---|---|
| AI purpose | Rubric-aligned speech evaluation feedback and scoring assistance |
| Default model path | SpeechGradebook Model (Qwen-based) on Modal, via backend proxy /qwen-api/* |
| Consumer LLM APIs (default hosted path) | Not used |
| Human oversight | Instructors remain responsible for grades and instructional decisions; AI output is assistive |
| Tenant kill-switch | Yes under contract — ValidBound will disable AI evaluation for an institutional tenant on request |
| Student media to model | Sent for job duration when an instructional evaluation runs |
| Credentials | Stored server-side; not exposed to the browser in the production proxy path |
| Training / research use | Affirmative student consent required for ValidBound LLM / R&D exports; described in the Privacy Policy; institution agreements may restrict further use |
Privacy
| Theme | Response |
|---|---|
| Privacy Policy | speechgradebook.com/privacy.html |
| FERPA orientation | Role/institution limits, instructional hosting, R&D consent gate, audit logging — FERPA and student records |
| Student consent | Affirmative consent for ValidBound product-improvement / R&D use (18+); instructional storage is not consent-gated — Consent overview |
| Data inventory | Accounts, courses/rosters, rubrics, evaluations, media (instructional hosting), audit logs, consent records |
| Retention | Per institution agreement and product recovery windows — Data handling and retention |
| Subprocessors | Subprocessors and data locations |
| International transfers | Primary hosting in the United States; discuss GDPR/other frameworks in contract if required |
| Breach notification | Incident response and contact |
Case-specific (typical)
| Domain | Typical SpeechGradebook posture |
|---|---|
| HIPAA | Not applicable — not offered as a HIPAA-covered product |
| PCI DSS (in-product education records) | Not applicable — card data not processed in the SpeechGradebook education-records path |
| On-premises appliance | Not applicable — hosted SaaS |
If your campus evaluation triggers additional case-specific rows, contact ValidBound for tailored answers.
Documentation pack
| Document | Link |
|---|---|
| Official HECVAT 4 download | EDUCAUSE toolkit |
| Security plan | Security plan |
| Security overview | Security overview |
| Privacy Policy | Privacy Policy |
| Terms of Service | Terms of Service |
| VPAT / ACR | VPAT |
| Accessibility Statement | Accessibility Statement |
| Subprocessors | Subprocessors |
| Incident response | Incident response |
| IT reviewer guide | For IT reviewers |
Request updates or a signed packet
The completed workbook is in-repo (link above). Use the contact form if you need:
- A refreshed workbook after a product/security change
- DPA / subprocessor letter
- Clarifications on specific question IDs
This markdown page summarizes the same answers for quick reading.