Compliance proof / HECVAT 4.1.6
Every question. Every posture. Verifiable.
332 questions across 35 categories and 8 evaluation tabs. AegisGrid's alignment posture for each item is shown below — sourced directly from the EDUCAUSE HECVAT 4.1.6 workbook.
HECVAT 4.1.6 catalog: 332 question records, 35 question categories, 32 AI-prefixed questions (AIQU=2, AIGN=5, AIPL=5, AISC=5, AIML=8, AILM=7) plus the REQU-04 gate question that triggers the AI section. Counted directly from the published Questions sheet; the EDUCAUSE marketing page references 321 / 7 sections but the actual workbook contains 332 / 8 tabs / 35 categories.
332
Total questions
Reproduced verbatim from the EDUCAUSE HECVAT 4.1.6 workbook
35
Question categories
From GNRL General Information to AILM AI Large Language Model
32
AI subsection questions
Conditional AIQU=2 / AIGN=5 / AIPL=5 / AISC=5 / AIML=8 / AILM=7 categories (plus the REQU-04 gate question that activates the AI section)
§ 01 — Interactive catalog
Search, filter, inspect.
Filter by sheet, category, importance, or AegisGrid posture. Hover any row to see the full question text. Every posture is sourced from AegisGrid's documented workflow and requires institutional validation.
| ID | Question | Category | Sheet | Importance | Weight | AegisGrid posture |
|---|---|---|---|---|---|---|
| GNRL-01 | Solution Provider Name | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-02 | Solution Name | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-03 | Solution Description | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-04 | Solution Provider Contact Name | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-05 | Solution Provider Contact Title | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-06 | Solution Provider Contact Email | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-07 | Solution Provider Contact Phone Number | GNRLGeneral Information | Not Scored | Not Scored | — | Automated extraction |
| GNRL-08 | Country of Company Headquarters | GNRLGeneral Information | Not Scored | Not Scored | — | Out of scope |
| GNRL-09 | Employee Work Locations (all) | GNRLGeneral Information | Not Scored | Not Scored | — | Out of scope |
| COMP-01 | Do you have a dedicated software and system development team(s) (e.g., customer support, implementation, product management, etc.)?* | COMPCompany Information | Start Here | Standard Importance | 10 | Analyst review |
| COMP-02 | Describe your organization’s business background and ownership structure, including all parent and subsidiary relationships. | COMPCompany Information | Not Scored | Not Scored | — | Analyst review |
| COMP-03 | Have you operated without unplanned disruptions to this solution in the past 12 months? | COMPCompany Information | Start Here | Minor Importance | 5 | Analyst review |
| COMP-04 | Do you have a dedicated information security staff or office? | COMPCompany Information | Start Here | Minor Importance | 5 | Analyst review |
| COMP-05 | Use this area to share information about your environment that will assist those who are assessing your company's data security program. | COMPCompany Information | Not Scored | Not Scored | — | Analyst review |
| REQU-01gate | Are you offering a cloud-based product? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-02gate | Does your product or service have an interface? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-03gate | Are you providing consulting services? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-04gate | Does your solution have AI features, or are there plans to implement AI features in the next 12 months? | REQURequired Questions | Not Scored | Not Scored | — | Architecture-enforced |
| REQU-05gate | Does your solution process protected health information (PHI) or any data covered by the Health Insurance Portability and Accountability Act (HIPAA)? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-06gate | Is the solution designed to process, store, or transmit credit card information? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-07gate | Does operating your solution require the institution to operate a physical or virtual appliance in their own environment or to provide inbound firewall exceptions to allow your... | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| REQU-08gate | Does your solution have access to personal or institutional data? | REQURequired Questions | Not Scored | Not Scored | — | Analyst review |
| DOCU-01 | Do you have a well-documented business continuity plan (BCP), with a clear owner, that is tested annually?* | DOCUDocumentation | Organization | Critical Importance | 20 | Architecture-enforced |
| DOCU-02 | Do you have a well-documented disaster recovery plan (DRP), with a clear owner, that is tested annually?* | DOCUDocumentation | Organization | Critical Importance | 20 | Architecture-enforced |
| DOCU-03 | Have you undergone a SSAE 18/SOC 2 audit? | DOCUDocumentation | Organization | Standard Importance | 10 | Analyst review |
| DOCU-04 | Do you conform with a specific industry standard security framework (e.g., NIST Cybersecurity Framework, CIS Controls, ISO 27001, etc.)? | DOCUDocumentation | Organization | Standard Importance | 10 | Automated extraction |
| DOCU-05 | Can you provide overall system and/or application architecture diagrams, including a full description of the data flow for all components of the system? | DOCUDocumentation | Organization | Standard Importance | 10 | Analyst review |
| DOCU-06 | Does your organization have a data privacy policy? | DOCUDocumentation | Organization | Standard Importance | 10 | Automated extraction |
| DOCU-07 | Do you have a documented, and currently implemented, employee onboarding and offboarding policy? | DOCUDocumentation | Organization | Standard Importance | 10 | Automated extraction |
| ITAC-01 | Solution Provider Accessibility Contact Name | ITACIT Accessibility | Not Scored | Not Scored | — | Analyst review |
| ITAC-02 | Solution Provider Accessibility Contact Title | ITACIT Accessibility | Not Scored | Not Scored | — | Analyst review |
| ITAC-03 | Solution Provider Accessibility Contact Email | ITACIT Accessibility | Not Scored | Not Scored | — | Analyst review |
| ITAC-04 | Solution Provider Accessibility Contact Phone Number | ITACIT Accessibility | Not Scored | Not Scored | — | Analyst review |
| ITAC-05 | Web Link to Accessibility Statement or VPAT | ITACIT Accessibility | Not Scored | Not Scored | — | Analyst review |
| ITAC-06 | Has a VPAT or ACR been created or updated for the solution and version under consideration within the past 12 months?* | ITACIT Accessibility | IT Accessibility | Critical Importance | 20 | Analyst review |
| ITAC-07 | Will your company agree to meet your stated accessibility standard or WCAG 2.1 AA as part of your contractual agreement for the solution?* | ITACIT Accessibility | IT Accessibility | Critical Importance | 20 | Analyst review |
| ITAC-08 | Does the solution substantially conform to WCAG 2.1 AA?* | ITACIT Accessibility | IT Accessibility | Critical Importance | 20 | Analyst review |
| ITAC-09 | Do you have a documented and implemented process for reporting and tracking accessibility issues?* | ITACIT Accessibility | IT Accessibility | Critical Importance | 20 | Analyst review |
| ITAC-10 | Do you have documentation to support the accessibility features of your solution? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-11 | Has a third-party expert conducted an audit of the most recent version of your solution? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-12 | Do you have a documented and implemented process for verifying accessibility conformance? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-13 | Have you adopted a technical or legal standard of conformance for the solution? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-14 | Can you provide a current, detailed accessibility roadmap with delivery timelines? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-15 | Do you expect your staff to maintain a current skill set in IT accessibility? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-16 | Do you have documented processes and procedures for implementing accessibility into your development lifecycle? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-17 | Can all functions of the application or service be performed using only the keyboard? | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| ITAC-18 | Does your product rely on activating a special "accessibility mode," a "lite version," or using an alternate interface (including “overlay” or AI-based alternates) for accessib... | ITACIT Accessibility | IT Accessibility | Standard Importance | 10 | Analyst review |
| THRD-01 | Do you perform security assessments of third-party companies with which you share data (e.g., hosting providers, cloud services, PaaS, IaaS, SaaS)?* | THRDAssessment of Third Parties | Organization | Critical Importance | 20 | Analyst review |
| THRD-02 | Do you have contractual language in place with third parties governing access to institutional data?* | THRDAssessment of Third Parties | Organization | Critical Importance | 20 | Analyst review |
| THRD-03 | Do the contracts in place with these third parties address liability in the event of a data breach?* | THRDAssessment of Third Parties | Organization | Critical Importance | 20 | Analyst review |
Source & validation
Provenance matters as much as the data.
Every question, category label, weight, and importance value on this page is reproduced from the EDUCAUSE HECVAT 4.1.6 workbook. AegisGrid annotates each row with an honest posture annotation (automated extraction, analyst review, architecture-enforced, out of scope, or unmapped). Posture annotations are AegisGrid's assessment and are not an institutional attestation.
Workbook version: 4.1.6 · Last modified: 2026-06-03 · Creator: BJ Hollowell (EDUCAUSE)
Adjacent evidence
From catalog to attestation.
The question catalog is the map. The control lineage and audit-log evidence are the proof. Move from one to the next in any order.
Question catalog derived from HECVAT 4.1.6 © 2025 EDUCAUSE. Downloaded from educause.edu/HECVAT. Posture annotations are AegisGrid's honest assessment and require institutional validation.