Procurement evidence index
| Review area | Repository evidence | External/customer-specific evidence still required |
|---|---|---|
| Architecture and tenancy | prisma/schema.prisma, src/lib/tenant-guard.ts, src/lib/actor.ts, deployment guide | Approved diagram, deployed inventory, independent isolation test |
| Identity and access | src/lib/platform-admin.ts, invitation service, RBAC map, workspace switcher | Customer IdP credentials, SSO runtime integration test, access-review records |
| Data protection | Private storage adapter, retention script, audit events | KMS/bucket policy, backup encryption, restore evidence, legal-hold process |
| Secure configuration | .env.example, readiness route, Docker package | Secret-manager screenshots/config exports, production scan |
| Incident response | Security summary and checklist | Named contacts, approved plan, tabletop and notification commitments |
| Privacy/FERPA | Privacy schedule template, consent/publication gates | Signed agreement/DPA, counsel approval, student-record request procedure |
| Accessibility | Accessibility test plan and UI semantics | Current manual audit and VPAT/ACR |
| Business continuity | Health checks and deployment rollback guide | Contracted RTO/RPO, redundancy design, restore drill |
| Subprocessors | Current package/provider inventory | Approved subprocessor list with locations and notice terms |
Complete the institution's requested HECVAT version from verified evidence. Do not answer “implemented” based on source code where the control depends on production operations.
Primary references
- U.S. Department of Education, FERPA and virtual learning vendor responsibilities
- EDUCAUSE, Higher Education Community Vendor Assessment Toolkit
- U.S. Department of Justice, Accessibility of web content and mobile apps provided by state and local governments
Next: subprocessors