Skip to main content

Trust overview

This section helps institution reviewers — IT security, privacy officers, and procurement — evaluate SpeechGradebook.

Platform components

ComponentRole
SpeechGradebook web appUser interface and API (FastAPI, deployed on Render)
SupabaseAuthentication, PostgreSQL database, and object storage
SpeechGradebook Model (Qwen)AI evaluation; accessed via backend proxy

Key controls

  • Row-level security (RLS) — Database policies restrict rows by role and institution
  • Student consent — Cloud storage requires per-course consent
  • Audit logging — Access to evaluation data is logged for compliance review
  • Role-based UI — Admin and Super Admin functions are gated in the app and in data policies
  • LTI 1.3 — Canvas/LMS launch SSO (OIDC); AES-256 at rest; U.S. residency for U.S. institutions

Review checklist

  1. Security plan
  2. Security overview
  3. HECVAT 4 response guide + completed workbook
  4. Institutional addendum (U.S. residency / LTI / MFA)
  5. VPAT / Accessibility Conformance Report
  6. Privacy and legal policies
  7. Subprocessors and data locations
  8. FERPA and student records
  9. Data handling and retention
  10. Student consent overview
  11. Role permissions
  12. Incident response and contact

Contact

For security questionnaires, the completed HECVAT workbook, or institutional agreements, contact ValidBound.