AEGISGRID

Compliance proof / HECVAT 4.1.6

Every question. Every posture. Verifiable.

332 questions across 35 categories and 8 evaluation tabs. AegisGrid's alignment posture for each item is shown below — sourced directly from the EDUCAUSE HECVAT 4.1.6 workbook.

HECVAT 4.1.6 catalog: 332 question records, 35 question categories, 32 AI-prefixed questions (AIQU=2, AIGN=5, AIPL=5, AISC=5, AIML=8, AILM=7) plus the REQU-04 gate question that triggers the AI section. Counted directly from the published Questions sheet; the EDUCAUSE marketing page references 321 / 7 sections but the actual workbook contains 332 / 8 tabs / 35 categories.

332

Total questions

Reproduced verbatim from the EDUCAUSE HECVAT 4.1.6 workbook

35

Question categories

From GNRL General Information to AILM AI Large Language Model

32

AI subsection questions

Conditional AIQU=2 / AIGN=5 / AIPL=5 / AISC=5 / AIML=8 / AILM=7 categories (plus the REQU-04 gate question that activates the AI section)

§ 01 — Interactive catalog

Search, filter, inspect.

Filter by sheet, category, importance, or AegisGrid posture. Hover any row to see the full question text. Every posture is sourced from AegisGrid's documented workflow and requires institutional validation.

Honesty note: Posture annotations reflect AegisGrid's documented workflow design. Every "analyst-review" and "unmapped" label is work-in-progress, not a capability gap. Final posture validation requires institutional assessment by the institution's qualified individual. The catalog itself is complete and verified against the EDUCAUSE workbook (332 of 332 entries).
Showing 50 of 332 questions
IDQuestionAegisGrid posture
GNRL-01Solution Provider NameAutomated extraction
GNRL-02Solution NameAutomated extraction
GNRL-03Solution DescriptionAutomated extraction
GNRL-04Solution Provider Contact NameAutomated extraction
GNRL-05Solution Provider Contact TitleAutomated extraction
GNRL-06Solution Provider Contact EmailAutomated extraction
GNRL-07Solution Provider Contact Phone NumberAutomated extraction
GNRL-08Country of Company HeadquartersOut of scope
GNRL-09Employee Work Locations (all)Out of scope
COMP-01Do you have a dedicated software and system development team(s) (e.g., customer support, implementation, product management, etc.)?*Analyst review
COMP-02Describe your organization’s business background and ownership structure, including all parent and subsidiary relationships.Analyst review
COMP-03Have you operated without unplanned disruptions to this solution in the past 12 months?Analyst review
COMP-04Do you have a dedicated information security staff or office?Analyst review
COMP-05Use this area to share information about your environment that will assist those who are assessing your company's data security program.Analyst review
REQU-01gateAre you offering a cloud-based product?Analyst review
REQU-02gateDoes your product or service have an interface?Analyst review
REQU-03gateAre you providing consulting services?Analyst review
REQU-04gateDoes your solution have AI features, or are there plans to implement AI features in the next 12 months?Architecture-enforced
REQU-05gateDoes your solution process protected health information (PHI) or any data covered by the Health Insurance Portability and Accountability Act (HIPAA)?Analyst review
REQU-06gateIs the solution designed to process, store, or transmit credit card information?Analyst review
REQU-07gateDoes operating your solution require the institution to operate a physical or virtual appliance in their own environment or to provide inbound firewall exceptions to allow your...Analyst review
REQU-08gateDoes your solution have access to personal or institutional data?Analyst review
DOCU-01Do you have a well-documented business continuity plan (BCP), with a clear owner, that is tested annually?*Architecture-enforced
DOCU-02Do you have a well-documented disaster recovery plan (DRP), with a clear owner, that is tested annually?*Architecture-enforced
DOCU-03Have you undergone a SSAE 18/SOC 2 audit?Analyst review
DOCU-04Do you conform with a specific industry standard security framework (e.g., NIST Cybersecurity Framework, CIS Controls, ISO 27001, etc.)?Automated extraction
DOCU-05Can you provide overall system and/or application architecture diagrams, including a full description of the data flow for all components of the system?Analyst review
DOCU-06Does your organization have a data privacy policy?Automated extraction
DOCU-07Do you have a documented, and currently implemented, employee onboarding and offboarding policy?Automated extraction
ITAC-01Solution Provider Accessibility Contact NameAnalyst review
ITAC-02Solution Provider Accessibility Contact TitleAnalyst review
ITAC-03Solution Provider Accessibility Contact EmailAnalyst review
ITAC-04Solution Provider Accessibility Contact Phone NumberAnalyst review
ITAC-05Web Link to Accessibility Statement or VPATAnalyst review
ITAC-06Has a VPAT or ACR been created or updated for the solution and version under consideration within the past 12 months?*Analyst review
ITAC-07Will your company agree to meet your stated accessibility standard or WCAG 2.1 AA as part of your contractual agreement for the solution?*Analyst review
ITAC-08Does the solution substantially conform to WCAG 2.1 AA?*Analyst review
ITAC-09Do you have a documented and implemented process for reporting and tracking accessibility issues?*Analyst review
ITAC-10Do you have documentation to support the accessibility features of your solution?Analyst review
ITAC-11Has a third-party expert conducted an audit of the most recent version of your solution?Analyst review
ITAC-12Do you have a documented and implemented process for verifying accessibility conformance?Analyst review
ITAC-13Have you adopted a technical or legal standard of conformance for the solution?Analyst review
ITAC-14Can you provide a current, detailed accessibility roadmap with delivery timelines?Analyst review
ITAC-15Do you expect your staff to maintain a current skill set in IT accessibility?Analyst review
ITAC-16Do you have documented processes and procedures for implementing accessibility into your development lifecycle?Analyst review
ITAC-17Can all functions of the application or service be performed using only the keyboard?Analyst review
ITAC-18Does your product rely on activating a special "accessibility mode," a "lite version," or using an alternate interface (including “overlay” or AI-based alternates) for accessib...Analyst review
THRD-01Do you perform security assessments of third-party companies with which you share data (e.g., hosting providers, cloud services, PaaS, IaaS, SaaS)?*Analyst review
THRD-02Do you have contractual language in place with third parties governing access to institutional data?*Analyst review
THRD-03Do the contracts in place with these third parties address liability in the event of a data breach?*Analyst review
Showing 50 of 332

Source & validation

Provenance matters as much as the data.

Every question, category label, weight, and importance value on this page is reproduced from the EDUCAUSE HECVAT 4.1.6 workbook. AegisGrid annotates each row with an honest posture annotation (automated extraction, analyst review, architecture-enforced, out of scope, or unmapped). Posture annotations are AegisGrid's assessment and are not an institutional attestation.

Source: EDUCAUSE HECVAT program

Workbook version: 4.1.6 · Last modified: 2026-06-03 · Creator: BJ Hollowell (EDUCAUSE)

Adjacent evidence

From catalog to attestation.

The question catalog is the map. The control lineage and audit-log evidence are the proof. Move from one to the next in any order.

Question catalog derived from HECVAT 4.1.6 © 2025 EDUCAUSE. Downloaded from educause.edu/HECVAT. Posture annotations are AegisGrid's honest assessment and require institutional validation.