AEGISGRID

Compliance crosswalk / 05

Compliance is documented, not asserted.

A framework-versioned view of the controls AegisGrid was designed to support — with the institutional assessment boundary left explicit.

AegisGrid is a software platform. AegisGrid does not hold third-party security certifications at the time of writing. What AegisGrid does is implement controls designed to align with the published frameworks below. Compliance with these frameworks in a specific institutional deployment requires a formal assessment by the institution's qualified individual.

Framework crosswalk

Specific mappings. Cautious language.

AegisGrid was designed against the frameworks on this page. We use "aligned with", "designed for", and "maps to" deliberately, because a CISSP reads the difference between an alignment claim and a certification claim. The mappings below are specific; each framework section names the clauses AegisGrid was designed to support.

HECVAT 4.1.6 is published by EDUCAUSE; 4.1.6 is the current release. AegisGrid's extraction workflow is designed to support all 35 question categories across the 8 published evaluation tabs. The conditional AI subsection (32 questions, aligned to NIST AI RMF AIPL-05) is supported as a first-class workflow with explicit citation lineage for each question.

Tab 1 — Start Here
The intake agent identifies the vendor, product boundary, service scope, and artifacts under review.
Tab 2 — Organization
The extraction agent identifies data types, classification, processing locations, and system relationships from the vendor artifacts.
Tab 3 — Product
The extraction and map agents structure control statements with source locations for analyst review.
Tab 4 — Infrastructure
The workflow extracts infrastructure, disclosure, remediation, and testing evidence into the review record.
Tab 5 — IT Accessibility
The map agent links accessibility and accommodation statements to the institution's review criteria and audit lineage.
Tab 6 — Case-Specific
The score agent records attestations, independent reports, audit periods, exceptions, and evidence gaps.
Tab 7 — Privacy
The intake and extraction agents identify subprocessors, fourth parties, hosting patterns, and related privacy dependencies.
Tab 8 — AI (conditional, 32 questions / AIPL-05)
When a vendor product includes AI or ML, the extraction agent handles the AI section and produces NIST AI RMF lineage for each question (AIQU=2, AIGN=5, AIPL=5, AISC=5, AIML=8, AILM=7) plus the REQU-04 gate question, paired with the source location in the vendor artifact.
mapping posture: designed to support · not a completed HECVAT response or certification
Source: official framework document

Institutional boundary

Your qualified individual makes the final attestation.

Compliance is documented, not asserted. AegisGrid provides architecture diagrams, control mappings, deployment guides, and immutable audit logs that an institution's qualified individual can review. Final compliance attestation is the institution's responsibility.

Next: inspect the evidence

Review the proof, not a badge.

See the redacted artifact workflow, control lineage, and audit-log evidence that an institutional team can evaluate.

Go to proof