Skip to main content

HECVAT 4 response guide

This page is ValidBound LLC’s companion response guide for SpeechGradebook, aligned to HECVAT 4 (Higher Education Community Vendor Assessment Toolkit™).

:::important Completed workbook Download ValidBound’s completed HECVAT 4.1.6 workbook:

HECVAT-4.1.6-SpeechGradebook-ValidBound.xlsx

This file is the official EDUCAUSE HECVAT 4.1.6 template with SpeechGradebook / ValidBound LLC answers filled on START HERE, Organization, Product, Infrastructure, IT Accessibility, Case-Specific, AI, and Privacy.

Also see the Institutional addendum (U.S. residency, LTI 1.3, MFA, AI kill-switch).

Blank template source (EDUCAUSE): Higher Education Community Vendor Assessment Toolkit (current version 4.1.6).

HECVAT™ is a trademark of EDUCAUSE. Regenerate answers with python scripts/fill_hecvat_workbook.py after updating response content. :::

How HECVAT 4 works

Per EDUCAUSE, HECVAT 4 rolls the former Full, Lite, and On-Prem templates into one workbook:

  1. Open the EDUCAUSE file and complete the Start Here / required gateway questions.
  2. The workbook routes you to applicable sections.
  3. Solution providers complete all questions that apply to their product (typically once per year) and may share the same completed file with multiple institutions.
  4. Institutions can evaluate with a lighter high-risk / Core view when that matches their risk process (this replaces a separate “Lite” file).

Primary HECVAT 4 sections:

SectionSpeechGradebook applicability
OrganizationYes
ProductYes
InfrastructureYes (cloud SaaS)
IT AccessibilityYes
Case-SpecificGenerally limited (no HIPAA/PCI product path for SpeechGradebook education records)
Artificial IntelligenceYes
PrivacyYes (FERPA-relevant education records)

Corporate FAQ: HECVAT FAQs for Corporations.

Product identity (for Start Here)

FieldValue
ProductSpeechGradebook
VendorValidBound LLC
Assessment dateJuly 2026
DeploymentVendor-hosted cloud SaaS (not on-premises)
AudienceHigher education instructors, admins, and Practice users
Data typesFaculty/staff accounts; student education records (evaluations, scores, feedback, speech media for instructional hosting)

Start Here — gateway answers

Use these when filling the official Start Here / required questions tab. Exact question IDs may vary slightly by workbook build; match by topic.

Gateway topicSpeechGradebook answer
Solution / service typeWeb application (SaaS) for AI-assisted speech evaluation and practice; LTI 1.3 Canvas/LMS integration
Hosting / deploymentCloud / vendor-hosted (not customer on-premises); U.S. residency for U.S. institutions
Processes student education records / FERPA data?Yes (when institutions use cloud evaluation and storage features)
Processes payment card data (PCI) in the product?No for institutional course gradebook education records. Stripe processes payments for SpeechGradebook Practice Plus and ValidBound Coaching; card data is handled by Stripe, not stored as course gradebook content.
Processes protected health information (HIPAA)?No (not a HIPAA-covered product offering)
Includes AI / machine learning?Yes — SpeechGradebook Model for rubric-aligned evaluation assistance
Accessibility documentation available?YesAccessibility Statement and VPAT / ACR
Shared / multi-tenant service?Yes — multi-tenant with logical isolation (roles + row-level security)

Organization

ThemeResponse
Legal entityValidBound LLC
Product operatorValidBound LLC operates SpeechGradebook
Security contactContact form — note Security
Privacy contactPrivacy Policy; info@validbound.com
Written security planYesSecurity plan
Incident response processYesIncident response and contact
Operator accessProduction access limited to ValidBound operations roles needed to run the service
Access disciplineLeast-privilege access to production credentials and data platforms
Third-party riskSubprocessors listed publicly — Subprocessors
Contracts / DPAInstitution-specific DPA or addendum available on request

Product

ThemeResponse
AuthenticationSupabase Auth for portal login; LTI 1.3 (OIDC) SSO for Canvas/LMS launch; SAML/CAS evaluable per contract
MFAAvailable on portal login via Supabase Auth TOTP (optional today); LMS users use Canvas MFA/auth
AuthorizationRole-based UI + PostgreSQL row-level security (RLS) by user, role, and institution
SessionsToken-based sessions via Supabase over HTTPS
Application securityModel/proxy secrets stay server-side; protected API routes validate sessions
LoggingAccess to student evaluation data logged (who/what/when/action/context)
Change managementHosted deploys via application pipeline on Render
ContinuitySupabase automated backups + PITR; target RPO ≤ 24h; formal ValidBound BCP/DRP on roadmap
Export / deletionInstructors/admins can export and delete per product functions; retention per agreement
IntegrationsLTI 1.3 Advantage for Canvas/LMS (current); standalone IdP SSO per contract

Infrastructure

ThemeResponse
HostingRender (app/API), Supabase (Auth, PostgreSQL, Storage), Modal (model inference); Stripe (Practice/coaching payments); optional Sentry / SMTP when configured
Data residencyU.S. for U.S. institution deployments (including UTK) — not transferred outside the U.S. in the standard hosted configuration
Encryption in transitTLS 1.2+
Encryption at restAES-256 via Supabase PostgreSQL and Storage
Network exposurePublic HTTPS app endpoint; end users access data only through Auth/RLS-enforced paths
BackupsSupabase automated backups + PITR; target RPO ≤ 24 hours
WAFCloudflare DNS-only today; edge WAF available for institutional deployments on request
Vulnerability handlingReports via contact form; prioritized remediation and credential rotation when needed
Penetration testingNo third-party pen test in the last year; can schedule and share under NDA
TenancyMulti-tenant with logical isolation via RLS and institution boundaries

IT accessibility

ThemeResponse
Target standardWCAG 2.1 Level AA
Public statementAccessibility Statement
VPAT / ACRVPAT / ACR (self-assessment)
Assistive technologySpot-checked with major screen readers and keyboard navigation on core flows
Known gapsUser-uploaded video captions; some dense analytics/chart experiences
FeedbackAim to respond within 5 business days

Artificial intelligence

ThemeResponse
AI purposeRubric-aligned speech evaluation feedback and scoring assistance
Default model pathSpeechGradebook Model (Qwen-based) on Modal, via backend proxy /qwen-api/*
Consumer LLM APIs (default hosted path)Not used
Human oversightInstructors remain responsible for grades and instructional decisions; AI output is assistive
Tenant kill-switchYes under contract — ValidBound will disable AI evaluation for an institutional tenant on request
Student media to modelSent for job duration when an instructional evaluation runs
CredentialsStored server-side; not exposed to the browser in the production proxy path
Training / research useAffirmative student consent required for ValidBound LLM / R&D exports; described in the Privacy Policy; institution agreements may restrict further use

Privacy

ThemeResponse
Privacy Policyspeechgradebook.com/privacy.html
FERPA orientationRole/institution limits, instructional hosting, R&D consent gate, audit logging — FERPA and student records
Student consentAffirmative consent for ValidBound product-improvement / R&D use (18+); instructional storage is not consent-gated — Consent overview
Data inventoryAccounts, courses/rosters, rubrics, evaluations, media (instructional hosting), audit logs, consent records
RetentionPer institution agreement and product recovery windows — Data handling and retention
SubprocessorsSubprocessors and data locations
International transfersPrimary hosting in the United States; discuss GDPR/other frameworks in contract if required
Breach notificationIncident response and contact

Case-specific (typical)

DomainTypical SpeechGradebook posture
HIPAANot applicable — not offered as a HIPAA-covered product
PCI DSS (in-product education records)Not applicable — card data not processed in the SpeechGradebook education-records path
On-premises applianceNot applicable — hosted SaaS

If your campus evaluation triggers additional case-specific rows, contact ValidBound for tailored answers.

Documentation pack

DocumentLink
Official HECVAT 4 downloadEDUCAUSE toolkit
Security planSecurity plan
Security overviewSecurity overview
Privacy PolicyPrivacy Policy
Terms of ServiceTerms of Service
VPAT / ACRVPAT
Accessibility StatementAccessibility Statement
SubprocessorsSubprocessors
Incident responseIncident response
IT reviewer guideFor IT reviewers

Request updates or a signed packet

The completed workbook is in-repo (link above). Use the contact form if you need:

  • A refreshed workbook after a product/security change
  • DPA / subprocessor letter
  • Clarifications on specific question IDs

This markdown page summarizes the same answers for quick reading.