Built to be bought
What procurement asks for.
This folder is the handoff surface for campus IT, procurement, counsel, and accessibility reviewers. It describes the controls implemented in this repository and identifies evidence that still requires an external audit or a customer-specific contract.
Start with:
These are operational templates, not legal advice, a completed HECVAT, a VPAT, or a certification claim. Replace organization names, contacts, response targets, subprocessors, and governing terms before sending them to a university.
- securityControls implemented, controls the operator owns, evidence to request.
- privacy FERPAHow student records are handled, and what the school stays responsible for.
- procurement evidenceWhat the repository proves and what still has to come from us or from you.
- subprocessorsEvery third party that touches data, and why.
- deploymentShared, dedicated, or self-hosted, and what each means for tenancy.
- implementation checklistFrom contract to first cleared deal.
- operations SLAAvailability, support, and what we commit to.
- incident responseWho is told what, and how fast.
- accessibilityConformance target and how we test.