1import{j as n}from"./vendor-query-De67fZpb.js";import{r as m}from"./vendor-react-DmHq5u7o.js";const g=`# HECVAT Lite Self-Assessment â Schoolpilot\r 2\r 3**Vendor:** Schoolpilot LLC\r 4**Product:** Schoolpilot (ClassPilot, PassPilot, GoPilot)\r 5**Website:** https://school-pilot.net\r 6**Assessment Date:** September 28, 2026\r 7**Assessor:** Internal self-assessment\r 8**Contact:** [email protected]\r 9\r 10---\r 11\r 12## How to Use This Document\r 13\r 14This is a completed HECVAT Lite (Higher Education Community Vendor Assessment Toolkit) self-assessment provided to school districts and higher-ed institutions to support procurement and security review.\r 15\r 16The HECVAT Lite is a subset of the full HECVAT created by EDUCAUSE and the REN-ISAC. It is the industry-standard security questionnaire for EdTech vendors. Schoolpilot provides this self-assessment to streamline procurement â contact [email protected] if you require the full HECVAT or additional documentation under NDA.\r 17\r 18The current version is published at https://school-pilot.net/security/hecvat-lite, alongside a one-page summary at https://school-pilot.net/security/summary.\r 19\r 20**Response legend:**\r 21- **Yes** â Requirement is fully met\r 22- **No** â Requirement is not currently met\r 23- **N/A** â Not applicable to the product\r 24- **Partial** â Partially met with explanatory note\r 25\r 26---\r 27\r 28## Section 1 â General / Company Profile\r 29\r 30| # | Question | Response |\r 31|---|----------|----------|\r 32| 1.1 | Company legal name | Schoolpilot LLC (Ohio) |\r 33| 1.2 | Year company founded | 2024 |\r 34| 1.3 | Number of employees with access to production systems | 1-5 |\r 35| 1.4 | Does the company maintain cyber liability insurance? | In progress |\r 36| 1.5 | Will the product be used by end users under the age of 13? | Yes â COPPA "school consent" exception applies |\r 37| 1.6 | Does the company have a designated privacy or security officer? | Yes â [email protected] |\r 38\r 39---\r 40\r 41## Section 2 â Policies and Program\r 42\r 43| # | Question | Response | Notes |\r 44|---|----------|----------|-------|\r 45| 2.1 | Written Information Security Program (WISP) in place? | **Yes** | See \`docs/WISP.md\` â reviewed annually and after material changes |\r 46| 2.2 | Privacy Policy published publicly? | **Yes** | https://school-pilot.net/privacy |\r 47| 2.3 | Acceptable Use Policy for employees? | **Yes** | Part of WISP Section 4.2 |\r 48| 2.4 | Access control / least privilege policy? | **Yes** | RBAC enforced at application layer; WISP Section 4.1 |\r 49| 2.5 | Data classification policy? | **Yes** | WISP Section 3: Restricted / Confidential / Public |\r
50| 2.6 | Background checks on staff with data access? | **Yes** | Required before production access |\r 51| 2.7 | Annual security training for staff? | **Yes** | WISP Section 11; completion attestations are human-signed and stored privately |\r 52\r 53---\r 54\r 55## Section 3 â Data Protection\r 56\r 57| # | Question | Response | Notes |\r 58|---|----------|----------|-------|\r 59| 3.1 | Data encrypted in transit? | **Yes** | TLS 1.2+, HSTS enforced (\`max-age=31536000\`) via Helmet |\r 60| 3.2 | Data encrypted at rest? | **Yes** | AWS RDS encryption enabled, S3 SSE |\r 61| 3.3 | Encryption algorithm(s) used? | **Yes** | AES-256 at rest (AWS), TLS 1.2+ ECDHE in transit |\r 62| 3.4 | Key management process documented? | **Yes** | AWS KMS managed keys; rotation per AWS default |\r 63| 3.5 | Role-based access control (RBAC)? | **Yes** | admin / school_admin / teacher / office_staff / parent / super_admin |\r 64| 3.6 | Multi-factor authentication for privileged accounts? | **Partial** | Production AWS access uses MFA where available. In-app MFA for super_admin and school admin accounts is deferred and tracked in the SOC 2 remediation register. |\r 65| 3.7 | Password complexity enforced? | **Yes** | 10+ characters, uppercase, lowercase, digit required |\r 66| 3.8 | Account lockout after failed attempts? | **Yes** | 10 failures in 15 min â 30 min lockout (per-account, distributed-IP resistant) |\r 67| 3.9 | Session management (secure cookies, expiry)? | **Yes** | httpOnly + secure + SameSite cookies; 7-day rolling for teachers/parents; 1-hour idle timeout for admin roles |\r 68| 3.10 | Session fixation / CSRF protection? | **Yes** | CSRF tokens on state-changing requests |\r 69| 3.11 | Data retention policy documented? | **Yes** | Privacy Policy Section 4 + WISP Section 9 |\r 70| 3.12 | Data return/destruction on contract termination? | **Yes** | 30-day turnaround, returned in export format or permanently destroyed per school's written direction |\r 71\r 72---\r 73\r 74## Section 4 â Data Storage and Location\r 75\r 76| # | Question | Response | Notes |\r 77|---|----------|----------|-------|\r 78| 4.1 | Where is production data stored? | **Yes** | Amazon Web Services, us-east-1 (United States) |\r 79| 4.2 | Is data stored outside the United States? | **No** | All production data stays in us-east-1 |\r 80| 4.3 | Is data segregated from other customers? | **Yes** | Multi-tenant database; every tenant row is scoped by \`school_id\` in the application and by PostgreSQL row-level security (RLS) on tenant tables in production |\r 81| 4.4 | Is customer data commingled with other customers? | **Partial** | Multi-tenant schema; physical database shared, rows isolated per school by application scoping and PostgreSQL RLS |\r 82| 4.5 | Backups encrypted? | **Yes** | RDS automated backups inherit encryption-at-rest |\r 83| 4.6 | Backup retention period? | **Yes** | 7-day automated snapshots + on-demand manual snapshots |\r 84| 4.7 | Data center certifications (SOC, ISO)? | **Yes** | AWS maintains SOC 1/2/3 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP Moderate |\r 85\r 86---\r 87\r 88## Section 5 â Student Data and FERPA/COPPA\r 89\r 90| # | Question | Response | Notes |\r 91|---|----------|----------|-------|\r 92| 5.1 | Is the vendor a "school official" under FERPA? | **Yes** | Privacy Policy Section 5 |\r 93| 5.2 | Under direct control of the school regarding data use? | **Yes** | Privacy Policy Section 5 |\r 94| 5.3 | Student data used only for educational purposes? | **Yes** | Privacy Policy Section 4.2 â explicit no-data-mining clause |\r 95| 5.4 | Student data used for advertising? | **No** | Explicitly prohibited in Privacy Policy Section 4.2 |\r 96| 5.5 | Student data sold to third parties? | **No** | Explicitly prohibited in Privacy Policy Section 8 |\r 97| 5.6 | Student data used to train AI/ML models? | **No** | Prohibited per Privacy Policy Section 4.2. ClassPilot uses Gemini API paid-tier processing for URL/title classification; MailPilot and the optional assistant use Anthropic under their respective customer-data terms. |\r 98| 5.7 | COPPA compliance mechanism? | **Yes** | Relies on school consent exception (34 CFR § 99.31(a)(1)) |\r 99| 5.8 | Parent right of access to student records? | **Yes** | 45-day response commitment in Privacy Policy Section 10 |\r 100| 5.9 | Parent right to amend / correct records? | **Yes** | 15 business-day response in Privacy Policy Section 10.2 |\r 101| 5.10 | Signed DPA / SDPA / NDPA available? | **Yes** | Terms Section 7 â incorporated by reference upon execution |\r 102| 5.11 | Customer (school) owns all student data? | **Yes** | Explicit in Terms Section 7 |\r 103\r 104---\r 105\r 106## Section 6 â Authentication and SSO\r 107\r 108| # | Question | Response | Notes |\r 109|---|----------|----------|-------|\r 110| 6.1 | Does the product support SSO? | **Partial** | Google OAuth supported for teacher/admin login. Microsoft Entra ID sign-in and SAML 2.0 are on the roadmap. |\r 111| 6.2 | Does the product support SAML 2.0? | **No** | Roadmap item â contact for ETA |\r 112| 6.3 | Does the product support OAuth / OIDC? | **Yes** | Google OAuth for authentication |\r 113| 6.4 | Does the product support ADFS? | **No** | SAML (future) will enable ADFS compatibility |\r 114| 6.5 | Does the product support local authentication (username/password)? | **Yes** | bcrypt (12 rounds), complexity-enforced |\r 115| 6.6 | Can local auth be disabled in favor of SSO? | **Partial** | School admins can turn off staff email/password sign-in for the web app so staff use Google sign-in; the GoPilot staff app keeps password access while the school holds a GoPilot license |\r 116\r 117---\r 118\r 119## Section 7 â Application Security\r 120\r 121| # | Question | Response | Notes |\r 122|---|----------|----------|-------|\r 123| 7.1 | Secure development lifecycle (SDLC) documented? | **Yes** | WISP Section 5.5: PR review, CI security audit, no prod data in dev |\r 124| 7.2 | Code review on all changes? | **Partial** | Changes are normally merged through pull requests that must pass automated checks (build, tests, CodeQL, secret scanning), and production deploys require a green CI run on the exact commit; independent human review is not technically enforced |\r 125| 7.3 | Dependency vulnerability scanning? | **Yes** | Every CI build blocks high/critical production-dependency findings unless a narrowly scoped, time-bound, evidence-backed disposition passes validation; the complete production and development dependency tree is scanned, with normalized findings and dependency counts retained and reviewed |\r 126| 7.4 | Static application security testing (SAST)? | **Yes** | GitHub CodeQL runs on every push and pull request to main and weekly, and fails on any error- or warning-severity finding; Gitleaks secret scanning runs on every push and pull request |\r 127| 7.5 | Dynamic application security testing (DAST)? | **No** | Planned with third-party pentest |\r 128| 7.6 | Input validation framework? | **Partial** | Zod schema validation on many, but not yet all, API inputs; Drizzle ORM parameterized queries prevent SQL injection |\r 129| 7.7 | Content Security Policy (CSP) headers? | **Yes** | Helmet default CSP enabled |\r 130| 7.8 | Rate limiting on authentication endpoints? | **Yes** | IP-based (15 attempts / 15 min) + per-account lockout (10 attempts â 30 min) |\r
131| 7.9 | Third-party penetration test conducted? | **No** | Planned for next funding cycle |\r 132| 7.10 | Published responsible disclosure / security contact? | **Yes** | https://school-pilot.net/security |\r 133\r 134---\r 135\r 136## Section 8 â Vulnerability and Incident Management\r 137\r 138| # | Question | Response | Notes |\r 139|---|----------|----------|-------|\r 140| 8.1 | Documented incident response plan? | **Yes** | WISP Section 7 â four severity levels, defined workflow |\r 141| 8.2 | Customer breach notification timeline? | **Yes** | 72 hours from discovery (Privacy Policy Section 11) |\r 142| 8.3 | 30-day follow-up report commitment? | **Yes** | WISP Section 7.2 |\r 143| 8.4 | Regulatory notification cooperation? | **Yes** | WISP Section 7.2; assists with FERPA and state-law obligations |\r 144| 8.5 | Active security monitoring? | **Yes** | Deterministic rule-based security monitor (\`src/services/securityMonitor.ts\`) runs every 5 min; detects failed-auth spikes, bulk writes, cross-school access, off-hours admin bursts; alerts to [email protected] |\r 145| 8.6 | Audit logging of administrative actions? | **Yes** | \`audit_logs\` table captures user/role/action/entity/timestamp; 2-year retention per WISP |\r 146| 8.7 | Log review process? | **Yes** | Security monitor alerts + periodic human review of \`security_events\` table |\r 147\r 148---\r 149\r 150## Section 9 â Business Continuity and Disaster Recovery\r 151\r 152| # | Question | Response | Notes |\r 153|---|----------|----------|-------|\r 154| 9.1 | Documented business continuity plan? | **Yes** | WISP Section 8 |\r 155| 9.2 | Recovery Time Objective (RTO)? | **Yes** | 4 hours for critical services |\r 156| 9.3 | Recovery Point Objective (RPO)? | **Yes** | 24 hours (daily automated RDS snapshots) |\r 157| 9.4 | Annual DR test conducted? | **Yes** | Annual restore-from-backup drill (WISP Section 8) |\r 158| 9.5 | Geographic redundancy? | **Partial** | Primary: AWS us-east-1 with Multi-AZ RDS option. Full multi-region DR planned. |\r 159\r 160---\r 161\r 162## Section 10 â Third-Party Subprocessors\r 163\r 164| # | Question | Response | Notes |\r 165|---|----------|----------|-------|\r 166| 10.1 | Public list of subprocessors available? | **Yes** | https://school-pilot.net/subprocessors |\r 167| 10.2 | Subprocessors bound by data processing agreements? | **In review** | DPA confirmations are tracked in private vendor review evidence and require human sign-off before being treated as operating evidence. |\r 168| 10.3 | Notice period before adding new subprocessors? | **Yes** | 30 days per Subprocessors page |\r 169| 10.4 | Customer right to object to new subprocessors? | **Yes** | Customer may terminate if subprocessor creates unacceptable risk |\r 170\r 171---\r 172\r 173## Section 11 â Certifications and Attestations\r 174\r 175| # | Question | Response | Notes |\r 176|---|----------|----------|-------|\r 177| 11.1 | SOC 2 Type II? | **No** | Planned for next funding cycle (12-month observation window) |\r 178| 11.2 | ISO 27001? | **No** | AWS infrastructure certified; Schoolpilot itself not certified |\r 179| 11.3 | iKeepSafe FERPA / COPPA? | **Pending** | Documentation package prepared; submission pending |\r 180| 11.4 | 1EdTech TrustEd Apps? | **Planned** | Registration in progress |\r 181| 11.5 | Common Sense Education Privacy Evaluation? | **Planned** | Submission in progress |\r 182| 11.6 | State data privacy registrations (CA, TX, IL)? | **On request** | Signed NDPAs available for state-specific requirements |\r 183\r 184---\r 185\r 186## Appendix â Documents Available on Request\r 187\r 188Under NDA, the following documents are provided to schools and qualified assessors:\r 189\r 190- Full Written Information Security Program (WISP)\r 191- Executed Data Processing Agreements with subprocessors\r 192- Incident Response Runbook\r 193- Penetration test reports (when available)\r 194- SOC 2 Type II report (not available yet; when available)\r 195\r 196**Contact:** [email protected] or [email protected]\r 197\r 198---\r 199\r 200## Known Gaps (Honest Disclosure)\r 201\r 202The following items are not yet met and are documented in our security roadmap:\r 203\r 2041. **SOC 2 Type II** â working toward readiness; audit planned post-funding (cost: ~$20K, 12-month observation)\r 2052. **Third-party penetration test** â planned post-funding (~$10-15K)\r 2063. **In-app MFA for school admins and super_admins** â deferred and tracked in the SOC 2 remediation register\r 2074. **SAML 2.0 and Microsoft Entra ID SSO** â on roadmap (Google OAuth currently supported)\r 2085. **Cyber liability insurance** â in procurement\r 2096. **AWS WAF** â deployed on the CloudFront distribution (managed rule groups plus per-IP rate limiting on device ingest and the API, with CloudWatch alarms on blocks); remaining hardening (custom rate keys per device) is tracked in the roadmap\r 210\r 211We believe transparency about roadmap gaps is more valuable to assessors than marketing claims. Updated versions of this document will be maintained as items are addressed.\r 212`,y=/^(#{1,6})\s+(.*)$/,f=/^(-{3,}|\*{3,}|_{3,})$/,u=/^([-*]|\d+\.)\s+(.*)$/,b=/^:?-{3,}:?$/,v=/(\*\*[^*]+\*\*|`[^`]+`|https?:\/\/[^\s)|]*[^\s).,;:|])/g;function P(t){return t.trim().replace(/^\|/,"").replace(/\|$/,"").split("|").map(e=>e.trim())}function x(t){return t.length>0&&t.every(e=>b.test(e))}function A(t){return y.test(t)||f.test(t)||t.startsWith("|")||u.test(t)}function w(t){const e=t.replace(/\r\n?/g,` 213`).split(` 214`),r=[];let s=0;for(;s<e.length;){const i=e[s].trim();if(i===""){s+=1;continue}const d=y.exec(i);if(d){r.push({type:"heading",level:d[1].length,text:d[2].trim()}),s+=1;continue}if(f.test(i)){r.push({type:"rule"}),s+=1;continue}if(i.startsWith("|")){const o=[];for(;s<e.length&&e[s].trim().startsWith("|");)o.push(P(e[s])),s+=1;const[l,...a]=o,S=a.length>0&&x(a[0])?a.slice(1):a;
214r.push({type:"table",header:l,rows:S});continue}const p=u.exec(i);if(p){const o=p[1]!=="-"&&p[1]!=="*",l=[];for(;s<e.length;){const a=u.exec(e[s].trim());if(!a||(a[1]!=="-"&&a[1]!=="*")!==o)break;l.push(a[2]),s+=1}r.push({type:"list",ordered:o,items:l});continue}const h=[];for(;s<e.length;){const o=e[s].trim();if(o===""||A(o))break;h.push(o),s+=1}r.push({type:"paragraph",lines:h})}return r}function I(t){const e=[];let r=0;for(const s of t.matchAll(v)){s.index>r&&e.push({type:"text",value:t.slice(r,s.index)});const i=s[0];i.startsWith("**")?e.push({type:"strong",value:i.slice(2,-2)}):i.startsWith("`")?e.push({type:"code",value:i.slice(1,-1)}):e.push({type:"link",value:i}),r=s.index+i.length}return r<t.length&&e.push({type:"text",value:t.slice(r)}),e}const C=w(g),R=` 215@page { size: letter; margin: 0.5in; } 216@media print { 217 html, body { background: #fff !important; } 218 tr { break-inside: avoid; } 219 h2 { break-after: avoid; } 220} 221`;function c({text:t}){return I(t).map((e,r)=>e.type==="strong"?n.jsx("strong",{className:"font-semibold text-slate-900",children:e.value},r):e.type==="code"?n.jsx("code",{className:"rounded bg-slate-100 px-1 py-0.5 text-[0.85em] text-slate-800",children:e.value},r):e.type==="link"?n.jsx("a",{href:e.value,className:"break-all text-amber-700 underline hover:text-amber-800",children:e.value},r):n.jsx(m.Fragment,{children:e.value},r))}function Y({block:t}){switch(t.type){case"heading":return t.level===1?n.jsx("h1",{className:"mb-4 text-3xl font-bold text-slate-900 print:text-2xl",children:n.jsx(c,{text:t.text})}):t.level===2?n.jsx("h2",{className:"mb-3 mt-8 text-xl font-semibold text-slate-900 print:mt-5",children:n.jsx(c,{text:t.text})}):n.jsx("h3",{className:"mb-2 mt-6 text-lg font-medium text-slate-800",children:n.jsx(c,{text:t.text})});case"rule":return n.jsx("hr",{className:"my-6 border-slate-200 print:my-3"});case"table":return n.jsx("div",{className:"overflow-x-auto rounded-lg border border-slate-200 print:overflow-visible",children:n.jsxs("table",{className:"min-w-full text-left text-sm print:text-[10px]",children:[n.jsx("thead",{className:"bg-slate-100",children:n.jsx("tr",{children:t.header.map((e,r)=>n.jsx("th",{className:"px-3 py-2 font-semibold text-slate-700 print:px-2 print:py-1",children:n.jsx(c,{text:e})},r))})}),n.jsx("tbody",{children:t.rows.map((e,r)=>n.jsx("tr",{className:"border-t border-slate-200 align-top",children:e.map((s,i)=>n.jsx("td",{className:"px-3 py-2 text-slate-700 print:px-2 print:py-1",children:n.jsx(c,{text:s})},i))},r))})]})});case"list":{const e=t.ordered?"ol":"ul";return n.jsx(e,{className:`${t.ordered?"list-decimal":"list-disc"} space-y-2 pl-6 text-slate-700`,children:t.items.map((r,s)=>n.jsx("li",{children:n.jsx(c,{text:r})},s))})}default:return n.jsx("p",{className:"my-3 leading-relaxed text-slate-700",children:t.lines.map((e,r)=>n.jsxs(m.Fragment,{children:[r>0&&n.jsx("br",{}),n.jsx(c,{text:e})]},r))})}}function E(){return m.useEffect(()=>{const t=document.title;return document.title="Schoolpilot HECVAT Lite Self-Assessment",()=>{document.title=t}},[]),n.jsxs("div",{className:"min-h-screen bg-slate-100 px-4 py-8 print:bg-white print:p-0",children:[n.jsx("style",{children:R}),n.jsxs("div",{className:"mx-auto mb-4 flex max-w-4xl items-center justify-between gap-4 print:hidden",children:[n.jsx("a",{href:"/security",className:"text-sm text-slate-600 hover:text-slate-900",children:"â Back to Security"}),n.jsx("button",{type:"button",onClick:()=>window.print(),className:"rounded-md bg-slate-900 px-4 py-2 text-sm font-semibold text-white hover:bg-slate-700",children:"Print or save as PDF"})]}),n.jsx("main",{className:"mx-auto max-w-4xl rounded-lg bg-white p-6 shadow-sm sm:p-10 print:max-w-none print:rounded-none print:p-0 print:shadow-none",children:C.map((t,e)=>n.jsx(Y,{block:t},e))})]})}export{E as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.