HECVAT Security Assessment
The Higher Education Community Vendor Assessment Toolkit (HECVAT) is a standardized security questionnaire used by colleges and universities to evaluate cloud services and third-party vendors.
This page provides a summary of Ledly’s HECVAT responses. For a complete HECVAT Lite or Full questionnaire, please contact [email protected].
1. Company Information
| Question | Response |
|---|---|
| Company Name | Ledly |
| Product Name | Ledly Lead Management Platform |
| Website | ledly.io |
| Product Description | Cloud-based lead management platform for higher education institutions. Captures leads from web forms, landing pages, and integrations; routes to CRMs; provides analytics and reporting. |
| Headquarters Location | United States |
| Year Founded | 2023 |
| Primary Contact | [email protected] |
2. Documentation
| Question | Response |
|---|---|
| Is product documentation publicly available? | Yes |
| Documentation URL | docs.ledly.io |
| Is API documentation available? | Yes - API Reference |
| Privacy Policy URL | ledly.io/privacy |
| Terms of Service URL | ledly.io/terms |
| Security documentation available? | Yes - This document and additional materials upon request |
3. IT Accessibility
| Question | Response |
|---|---|
| Does the product conform to WCAG 2.1 Level AA? | In progress - Ledly is committed to accessibility and is working toward WCAG 2.1 Level AA conformance |
| Is a VPAT/ACR available? | Available upon request |
| Does the product support screen readers? | Yes - Primary interfaces support screen reader navigation |
| Does the product support keyboard-only navigation? | Yes |
| Can users adjust text size and contrast? | Yes - Respects browser/OS accessibility settings |
| Are alternative text and captions provided? | Yes - Images include alt text; video content includes captions |
4. Data Center and Hosting
| Question | Response |
|---|---|
| Hosting model | Cloud-hosted (Platform as a Service) |
| Cloud provider | Railway (built on AWS infrastructure) |
| Data center locations | United States (AWS us-east-1, us-west-2 regions) |
| Is the infrastructure multi-tenant? | Yes - Logical separation between customer organizations |
| Physical security certifications | AWS data centers maintain SOC 2 Type II, ISO 27001, and other certifications |
| Geographic redundancy | Yes - Data replicated across availability zones |
| Uptime SLA | 99.9% availability target |
| Status page available? | Yes - status.ledly.io |
Cloud Infrastructure Details
| Question | Response |
|---|---|
| Can data residency be restricted to specific regions? | Contact us for region-specific deployment options |
| Does the provider have FedRAMP authorization? | AWS infrastructure is FedRAMP authorized; Railway operates on AWS infrastructure |
| Are containers/VMs isolated between tenants? | Yes - Railway provides container isolation; data separated by organization ID |
5. Security Program
Policies and Governance
| Question | Response |
|---|---|
| Do you have a formal information security program? | Yes |
| Is there a designated security officer? | Yes |
| Do you have documented security policies? | Yes - Including acceptable use, data classification, access control, and incident response |
| Are policies reviewed and updated regularly? | Yes - Annual review and update cycle |
| Do you conduct security awareness training? | Yes - All employees complete annual security training |
| Do you have a risk management program? | Yes - Regular risk assessments and mitigation tracking |
Incident Response
| Question | Response |
|---|---|
| Do you have an incident response plan? | Yes |
| How quickly are customers notified of security incidents? | Within 72 hours of confirmed breach affecting customer data |
| Is there a dedicated incident response team? | Yes |
| Do you conduct incident response exercises? | Yes - Annual tabletop exercises |
| Incident reporting contact | [email protected] |
Compliance and Audits
| Question | Response |
|---|---|
| SOC 2 Type II certified? | In progress |
| ISO 27001 certified? | Planned |
| Do you conduct regular security assessments? | Yes - Annual third-party penetration testing |
| Are audit reports available? | Available under NDA upon request |
6. Authentication and Access Control
Authentication Mechanisms
| Question | Response |
|---|---|
| What authentication methods are supported? | JWT bearer tokens, API keys, OAuth 2.0 |
| Is multi-factor authentication (MFA) available? | Yes - TOTP-based MFA available for all users |
| Is MFA enforced for administrative access? | Can be enforced via organization policy |
| Is single sign-on (SSO) supported? | Yes - SAML 2.0 and OAuth 2.0/OIDC |
| SSO providers supported | Okta, Azure AD, Google Workspace, custom SAML IdP |
| Is federated identity supported? | Yes |
Access Control
| Question | Response |
|---|---|
| Role-based access control (RBAC) implemented? | Yes |
| What roles are available? | Owner, Admin, User, Vendor (limited API access) |
| Can custom roles be defined? | Enterprise plans support custom role definitions |
| Is principle of least privilege enforced? | Yes - Users receive minimum permissions needed |
| Can access be scoped to specific data? | Yes - Organization-based data isolation |
| Are access logs maintained? | Yes - All authentication and authorization events logged |
Password Requirements
| Question | Response |
|---|---|
| Minimum password length | 8 characters |
| Password complexity requirements | At least one uppercase, one lowercase, one number |
| Password expiration policy | Configurable by organization (default: no expiration with MFA enabled) |
| Failed login lockout | Account locked after 5 failed attempts for 15 minutes |
| Password history enforcement | Cannot reuse last 5 passwords |
Session Management
| Question | Response |
|---|---|
| Session timeout | 24-hour token expiration; configurable idle timeout |
| Concurrent session limits | Configurable per organization |
| Session termination on password change | Yes - All active sessions invalidated |
| Secure session tokens | Yes - Cryptographically signed JWTs |
7. Data Protection
Encryption
| Question | Response |
|---|---|
| Is data encrypted in transit? | Yes - TLS 1.3 (TLS 1.2 minimum) |
| Is data encrypted at rest? | Yes - AES-256 encryption |
| Are encryption keys managed securely? | Yes - Keys managed via AWS KMS |
| Is key rotation performed? | Yes - Annual key rotation |
| Is end-to-end encryption available? | Not applicable for this service type |
Data Handling
| Question | Response |
|---|---|
| What types of data are collected? | Lead data (names, emails, phone numbers), usage analytics, authentication credentials |
| Is PII collected? | Yes - Lead contact information as provided by customers |
| How is sensitive data classified? | Data classification policy with Public, Internal, Confidential, and Restricted tiers |
| Is data masked or tokenized? | Sensitive fields can be masked in logs and exports |
| Can customers export their data? | Yes - Full data export available in CSV and JSON formats |
Backup and Recovery
| Question | Response |
|---|---|
| Are regular backups performed? | Yes - Daily automated backups |
| Backup frequency | Daily full backups, continuous transaction log backups |
| Backup retention period | 30 days (configurable for enterprise) |
| Are backups encrypted? | Yes - AES-256 encryption |
| Are backups stored offsite? | Yes - Replicated to separate AWS region |
| Recovery time objective (RTO) | 4 hours |
| Recovery point objective (RPO) | 1 hour |
| Is backup restoration tested? | Yes - Quarterly restoration testing |
Data Retention and Deletion
| Question | Response |
|---|---|
| Default data retention period | Data retained while account is active |
| Can retention periods be customized? | Yes - Configurable per organization |
| What happens to data upon contract termination? | Data available for export for 30 days, then securely deleted |
| Is secure data destruction performed? | Yes - Cryptographic erasure and secure deletion procedures |
| Can specific records be deleted on request? | Yes - Individual record deletion supported |
8. Privacy
Privacy Program
| Question | Response |
|---|---|
| Do you have a privacy policy? | Yes - ledly.io/privacy |
| Is there a designated privacy officer? | Yes |
| Is a Data Protection Agreement (DPA) available? | Yes - Available upon request |
| Do you conduct privacy impact assessments? | Yes - For new features and integrations |
FERPA Considerations
| Question | Response |
|---|---|
| Can the platform be used in a FERPA-compliant manner? | Yes - Ledly can operate as a “school official” under FERPA when processing education records |
| Do you sign FERPA compliance agreements? | Yes - Available as part of contract negotiations |
| Is access to student data restricted? | Yes - Role-based access controls limit data access |
| Are audit logs maintained for data access? | Yes - Comprehensive audit logging |
| Can data be deleted to comply with FERPA? | Yes - Data deletion capabilities support FERPA requirements |
Data Subject Rights
| Question | Response |
|---|---|
| Do you support data access requests? | Yes - Customers can export all data |
| Do you support data deletion requests? | Yes - Individual record and full account deletion |
| Do you support data portability? | Yes - Export in standard formats (CSV, JSON) |
| Do you support right to rectification? | Yes - Records can be updated or corrected |
| GDPR compliance | Yes - Compliant for EU data subjects |
| CCPA compliance | Yes - Compliant for California residents |
Data Sharing
| Question | Response |
|---|---|
| Is customer data shared with third parties? | Only as necessary for service delivery (see subprocessors) |
| Is customer data used for marketing? | No |
| Is customer data sold? | No - Never |
| Can data sharing be restricted? | Customers control which integrations receive their data |
9. Network Security
Network Architecture
| Question | Response |
|---|---|
| Is the network segmented? | Yes - Separate network segments for application, database, and management |
| Are firewalls in place? | Yes - Network and application-layer firewalls |
| Is a WAF (Web Application Firewall) used? | Yes |
| Are network access controls enforced? | Yes - Principle of least privilege for network access |
Intrusion Detection and Prevention
| Question | Response |
|---|---|
| Is intrusion detection deployed? | Yes - Network and host-based IDS |
| Is intrusion prevention deployed? | Yes - Automated blocking of detected threats |
| Are logs monitored for security events? | Yes - 24/7 automated monitoring with alerting |
| Is a SIEM used? | Yes |
DDoS Protection
| Question | Response |
|---|---|
| Is DDoS protection in place? | Yes - Via Railway/AWS infrastructure |
| What DDoS mitigation is available? | AWS Shield Standard included; enterprise DDoS protection available |
| Rate limiting implemented? | Yes - API rate limiting to prevent abuse |
Network Monitoring
| Question | Response |
|---|---|
| Is network traffic monitored? | Yes |
| Are network logs retained? | Yes - 90 days minimum |
| Is traffic encrypted between internal services? | Yes - mTLS for service-to-service communication |
10. Vulnerability Management
Vulnerability Scanning
| Question | Response |
|---|---|
| Are regular vulnerability scans performed? | Yes - Weekly automated scans |
| Is penetration testing conducted? | Yes - Annual third-party penetration tests |
| Are scan results tracked and remediated? | Yes - Findings prioritized and tracked to resolution |
| Remediation SLAs | Critical: 24 hours, High: 7 days, Medium: 30 days, Low: 90 days |
Dependency and Patch Management
| Question | Response |
|---|---|
| Is dependency scanning performed? | Yes - Automated scanning via Dependabot/Snyk |
| How are security patches applied? | Critical patches within 24-48 hours; regular patches during maintenance windows |
| Are systems kept up to date? | Yes - Regular update schedule for all components |
| Is there a patch management policy? | Yes |
Security Development
| Question | Response |
|---|---|
| Is secure coding practiced? | Yes - OWASP guidelines followed |
| Is code reviewed for security? | Yes - Mandatory peer review and automated scanning |
| Is SAST/DAST performed? | Yes - Static and dynamic analysis in CI/CD pipeline |
| Are third-party libraries vetted? | Yes - License and security review for dependencies |
11. Business Continuity
Disaster Recovery
| Question | Response |
|---|---|
| Is there a disaster recovery plan? | Yes |
| Is the DR plan tested? | Yes - Annual DR testing |
| Recovery Time Objective (RTO) | 4 hours |
| Recovery Point Objective (RPO) | 1 hour |
| Geographic redundancy | Yes - Multi-AZ deployment with cross-region backup |
Business Continuity
| Question | Response |
|---|---|
| Is there a business continuity plan? | Yes |
| Is the BCP tested? | Yes - Annual testing and review |
| Key personnel redundancy | Yes - No single point of failure for critical functions |
| Communication plan during outages | Status page updates, email notifications to administrators |
Backup Procedures
| Question | Response |
|---|---|
| Database backup frequency | Daily full backups, continuous transaction logs |
| Backup storage location | Encrypted, offsite in separate AWS region |
| Backup verification | Automated integrity checks; quarterly restoration tests |
| Self-service restoration | Available for enterprise plans |
12. Third-Party Risk
Subprocessors
Ledly uses the following subprocessors to deliver services:
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Railway | Cloud hosting and infrastructure | All application data | United States |
| AWS (Amazon Web Services) | Underlying infrastructure (via Railway) | All application data | United States |
| Resend | Transactional email delivery | Email addresses, notification content | United States |
| PostgreSQL (via Railway) | Primary database | All customer and lead data | United States |
Subprocessor Management
| Question | Response |
|---|---|
| Are subprocessors contractually bound? | Yes - Data processing agreements in place |
| Are subprocessors assessed for security? | Yes - Security review before onboarding |
| Are customers notified of subprocessor changes? | Yes - 30 days advance notice |
| Can customers object to subprocessors? | Yes - Per contract terms |
CRM Integrations
When customers configure CRM integrations, data flows to customer-selected destinations:
| Integration | Data Shared | Customer Controlled |
|---|---|---|
| Salesforce | Lead data as configured | Yes - Customer configures field mapping |
| HubSpot | Lead data as configured | Yes - Customer configures field mapping |
| Microsoft Dynamics | Lead data as configured | Yes - Customer configures field mapping |
| Custom Webhooks | Lead data as configured | Yes - Customer specifies endpoint and payload |
CRM integrations are configured and controlled by customers. Data shared with CRMs is subject to the customer’s agreements with those providers.
Additional Security Measures
Logging and Monitoring
| Capability | Details |
|---|---|
| Audit logging | All user actions, API calls, and data access logged |
| Log retention | 90 days online, 1 year archived |
| Log integrity | Logs are immutable and tamper-evident |
| Customer access to logs | Available via admin dashboard and API |
API Security
| Capability | Details |
|---|---|
| API authentication | API keys with scoped permissions |
| Rate limiting | Configurable limits to prevent abuse |
| IP allowlisting | Available for API key restrictions |
| Request signing | Available for enhanced security |
Change Management
| Question | Response |
|---|---|
| Is there a change management process? | Yes - All changes reviewed and approved |
| Are changes tested before deployment? | Yes - Staging environment testing required |
| Is rollback capability available? | Yes - Automated rollback on deployment failure |
| Are customers notified of changes? | Yes - Advance notice for breaking changes |
Contact Information
For security inquiries, HECVAT requests, or to report security concerns:
| Purpose | Contact |
|---|---|
| Security questions | [email protected] |
| HECVAT requests | [email protected] |
| Report a vulnerability | [email protected] |
| General support | [email protected] |
| Sales and contracts | [email protected] |
Request the Full HECVAT: This summary covers key areas of the HECVAT assessment. For a complete HECVAT Lite or HECVAT Full questionnaire with detailed responses, please contact [email protected].
Document Information
| Field | Value |
|---|---|
| Last Updated | December 2024 |
| Version | 1.0 |
| Review Cycle | Annual |
| Document Owner | Ledly Security Team |