Skip to main content

Institutional addendum — U.S. residency, LTI 1.3, and MFA

Vendor: ValidBound LLC
Product: SpeechGradebook
Date: July 24, 2026
Audience: Institution IT / OIT reviewers (including University of Tennessee, Knoxville)

This addendum supplements the Security plan, Privacy Policy, and completed HECVAT 4.1.6 workbook.

1. United States data residency

ValidBound confirms that for U.S. institution deployments of the hosted SpeechGradebook product, institutional data will reside in the United States.

In the standard hosted configuration, institutional data is not transferred outside the United States for collection, processing, storage, or archiving.

Primary data stores: Supabase (Auth, PostgreSQL, Storage) in U.S. regions; application hosting on Render (U.S.); model inference on Modal (U.S.).

2. LTI 1.3 / Canvas integration

SpeechGradebook supports LTI 1.3 Advantage integration for LMS launch (including Canvas).

  • LTI 1.3 uses OIDC for launch authentication, providing single sign-on for in-Canvas usage.
  • Users launching from Canvas authenticate through the institution’s LMS session; they do not need a separate SpeechGradebook password for that launch path.
  • Standalone portal SAML/CAS (e.g., Shibboleth) SSO may be evaluated per institution contract for non-LTI access.

3. Multifactor authentication (MFA)

For institutional deployments (including UTK):

  • MFA is available for SpeechGradebook portal / non-LMS login paths using Supabase Auth TOTP. Forced enrollment is not enabled today; OAuth (Google/Microsoft) with provider MFA is planned. Password accounts can optionally enroll TOTP in Account settings.
  • Users who access SpeechGradebook exclusively via Canvas LTI 1.3 launch authenticate through the institution’s Canvas authentication (including any MFA the institution requires for Canvas).

4. AI evaluation kill-switch

Upon contractual request, ValidBound will disable AI evaluation features for a specific institutional tenant (kill-switch) within a commercially reasonable time. This is available for institutional deployments such as UTK even though a self-serve per-user UI toggle is not the default today.

5. Encryption

LayerControl
In transitTLS 1.2+
At restAES-256 via Supabase PostgreSQL and Storage platform encryption

6. Continuity references (no formal ValidBound BCP/DRP yet)

ItemCurrent posture
Database backupsSupabase automated backups with point-in-time recovery (PITR)
Target RPOTypically ≤ 24 hours (often minutes with PITR)
Target RTOBest-effort hours for SaaS redeploy / provider recovery
SOC 2ValidBound entity: not yet; hosting subprocessors publish SOC 2 (Supabase, Render trust centers)
Pen testNo third-party pen test in the last year; can be scheduled and shared under NDA
WAFCloudflare DNS-only today (no proxy/WAF on app traffic); edge WAF can be enabled for institutional deployments on request

Contact