Institutional addendum — U.S. residency, LTI 1.3, and MFA
Vendor: ValidBound LLC
Product: SpeechGradebook
Date: July 24, 2026
Audience: Institution IT / OIT reviewers (including University of Tennessee, Knoxville)
This addendum supplements the Security plan, Privacy Policy, and completed HECVAT 4.1.6 workbook.
1. United States data residency
ValidBound confirms that for U.S. institution deployments of the hosted SpeechGradebook product, institutional data will reside in the United States.
In the standard hosted configuration, institutional data is not transferred outside the United States for collection, processing, storage, or archiving.
Primary data stores: Supabase (Auth, PostgreSQL, Storage) in U.S. regions; application hosting on Render (U.S.); model inference on Modal (U.S.).
2. LTI 1.3 / Canvas integration
SpeechGradebook supports LTI 1.3 Advantage integration for LMS launch (including Canvas).
- LTI 1.3 uses OIDC for launch authentication, providing single sign-on for in-Canvas usage.
- Users launching from Canvas authenticate through the institution’s LMS session; they do not need a separate SpeechGradebook password for that launch path.
- Standalone portal SAML/CAS (e.g., Shibboleth) SSO may be evaluated per institution contract for non-LTI access.
3. Multifactor authentication (MFA)
For institutional deployments (including UTK):
- MFA is available for SpeechGradebook portal / non-LMS login paths using Supabase Auth TOTP. Forced enrollment is not enabled today; OAuth (Google/Microsoft) with provider MFA is planned. Password accounts can optionally enroll TOTP in Account settings.
- Users who access SpeechGradebook exclusively via Canvas LTI 1.3 launch authenticate through the institution’s Canvas authentication (including any MFA the institution requires for Canvas).
4. AI evaluation kill-switch
Upon contractual request, ValidBound will disable AI evaluation features for a specific institutional tenant (kill-switch) within a commercially reasonable time. This is available for institutional deployments such as UTK even though a self-serve per-user UI toggle is not the default today.
5. Encryption
| Layer | Control |
|---|---|
| In transit | TLS 1.2+ |
| At rest | AES-256 via Supabase PostgreSQL and Storage platform encryption |
6. Continuity references (no formal ValidBound BCP/DRP yet)
| Item | Current posture |
|---|---|
| Database backups | Supabase automated backups with point-in-time recovery (PITR) |
| Target RPO | Typically ≤ 24 hours (often minutes with PITR) |
| Target RTO | Best-effort hours for SaaS redeploy / provider recovery |
| SOC 2 | ValidBound entity: not yet; hosting subprocessors publish SOC 2 (Supabase, Render trust centers) |
| Pen test | No third-party pen test in the last year; can be scheduled and shared under NDA |
| WAF | Cloudflare DNS-only today (no proxy/WAF on app traffic); edge WAF can be enabled for institutional deployments on request |
Contact
- Security / OIT packets: speechgradebook.com/contact (note Security or HECVAT)
- Email: info@validbound.com