SecurityHECVAT Assessment

HECVAT Security Assessment

The Higher Education Community Vendor Assessment Toolkit (HECVAT) is a standardized security questionnaire used by colleges and universities to evaluate cloud services and third-party vendors.

This page provides a summary of Ledly’s HECVAT responses. For a complete HECVAT Lite or Full questionnaire, please contact [email protected].


1. Company Information

QuestionResponse
Company NameLedly
Product NameLedly Lead Management Platform
Websiteledly.io
Product DescriptionCloud-based lead management platform for higher education institutions. Captures leads from web forms, landing pages, and integrations; routes to CRMs; provides analytics and reporting.
Headquarters LocationUnited States
Year Founded2023
Primary Contact[email protected]

2. Documentation

QuestionResponse
Is product documentation publicly available?Yes
Documentation URLdocs.ledly.io
Is API documentation available?Yes - API Reference
Privacy Policy URLledly.io/privacy
Terms of Service URLledly.io/terms
Security documentation available?Yes - This document and additional materials upon request

3. IT Accessibility

QuestionResponse
Does the product conform to WCAG 2.1 Level AA?In progress - Ledly is committed to accessibility and is working toward WCAG 2.1 Level AA conformance
Is a VPAT/ACR available?Available upon request
Does the product support screen readers?Yes - Primary interfaces support screen reader navigation
Does the product support keyboard-only navigation?Yes
Can users adjust text size and contrast?Yes - Respects browser/OS accessibility settings
Are alternative text and captions provided?Yes - Images include alt text; video content includes captions

4. Data Center and Hosting

QuestionResponse
Hosting modelCloud-hosted (Platform as a Service)
Cloud providerRailway (built on AWS infrastructure)
Data center locationsUnited States (AWS us-east-1, us-west-2 regions)
Is the infrastructure multi-tenant?Yes - Logical separation between customer organizations
Physical security certificationsAWS data centers maintain SOC 2 Type II, ISO 27001, and other certifications
Geographic redundancyYes - Data replicated across availability zones
Uptime SLA99.9% availability target
Status page available?Yes - status.ledly.io

Cloud Infrastructure Details

QuestionResponse
Can data residency be restricted to specific regions?Contact us for region-specific deployment options
Does the provider have FedRAMP authorization?AWS infrastructure is FedRAMP authorized; Railway operates on AWS infrastructure
Are containers/VMs isolated between tenants?Yes - Railway provides container isolation; data separated by organization ID

5. Security Program

Policies and Governance

QuestionResponse
Do you have a formal information security program?Yes
Is there a designated security officer?Yes
Do you have documented security policies?Yes - Including acceptable use, data classification, access control, and incident response
Are policies reviewed and updated regularly?Yes - Annual review and update cycle
Do you conduct security awareness training?Yes - All employees complete annual security training
Do you have a risk management program?Yes - Regular risk assessments and mitigation tracking

Incident Response

QuestionResponse
Do you have an incident response plan?Yes
How quickly are customers notified of security incidents?Within 72 hours of confirmed breach affecting customer data
Is there a dedicated incident response team?Yes
Do you conduct incident response exercises?Yes - Annual tabletop exercises
Incident reporting contact[email protected]

Compliance and Audits

QuestionResponse
SOC 2 Type II certified?In progress
ISO 27001 certified?Planned
Do you conduct regular security assessments?Yes - Annual third-party penetration testing
Are audit reports available?Available under NDA upon request

6. Authentication and Access Control

Authentication Mechanisms

QuestionResponse
What authentication methods are supported?JWT bearer tokens, API keys, OAuth 2.0
Is multi-factor authentication (MFA) available?Yes - TOTP-based MFA available for all users
Is MFA enforced for administrative access?Can be enforced via organization policy
Is single sign-on (SSO) supported?Yes - SAML 2.0 and OAuth 2.0/OIDC
SSO providers supportedOkta, Azure AD, Google Workspace, custom SAML IdP
Is federated identity supported?Yes

Access Control

QuestionResponse
Role-based access control (RBAC) implemented?Yes
What roles are available?Owner, Admin, User, Vendor (limited API access)
Can custom roles be defined?Enterprise plans support custom role definitions
Is principle of least privilege enforced?Yes - Users receive minimum permissions needed
Can access be scoped to specific data?Yes - Organization-based data isolation
Are access logs maintained?Yes - All authentication and authorization events logged

Password Requirements

QuestionResponse
Minimum password length8 characters
Password complexity requirementsAt least one uppercase, one lowercase, one number
Password expiration policyConfigurable by organization (default: no expiration with MFA enabled)
Failed login lockoutAccount locked after 5 failed attempts for 15 minutes
Password history enforcementCannot reuse last 5 passwords

Session Management

QuestionResponse
Session timeout24-hour token expiration; configurable idle timeout
Concurrent session limitsConfigurable per organization
Session termination on password changeYes - All active sessions invalidated
Secure session tokensYes - Cryptographically signed JWTs

7. Data Protection

Encryption

QuestionResponse
Is data encrypted in transit?Yes - TLS 1.3 (TLS 1.2 minimum)
Is data encrypted at rest?Yes - AES-256 encryption
Are encryption keys managed securely?Yes - Keys managed via AWS KMS
Is key rotation performed?Yes - Annual key rotation
Is end-to-end encryption available?Not applicable for this service type

Data Handling

QuestionResponse
What types of data are collected?Lead data (names, emails, phone numbers), usage analytics, authentication credentials
Is PII collected?Yes - Lead contact information as provided by customers
How is sensitive data classified?Data classification policy with Public, Internal, Confidential, and Restricted tiers
Is data masked or tokenized?Sensitive fields can be masked in logs and exports
Can customers export their data?Yes - Full data export available in CSV and JSON formats

Backup and Recovery

QuestionResponse
Are regular backups performed?Yes - Daily automated backups
Backup frequencyDaily full backups, continuous transaction log backups
Backup retention period30 days (configurable for enterprise)
Are backups encrypted?Yes - AES-256 encryption
Are backups stored offsite?Yes - Replicated to separate AWS region
Recovery time objective (RTO)4 hours
Recovery point objective (RPO)1 hour
Is backup restoration tested?Yes - Quarterly restoration testing

Data Retention and Deletion

QuestionResponse
Default data retention periodData retained while account is active
Can retention periods be customized?Yes - Configurable per organization
What happens to data upon contract termination?Data available for export for 30 days, then securely deleted
Is secure data destruction performed?Yes - Cryptographic erasure and secure deletion procedures
Can specific records be deleted on request?Yes - Individual record deletion supported

8. Privacy

Privacy Program

QuestionResponse
Do you have a privacy policy?Yes - ledly.io/privacy
Is there a designated privacy officer?Yes
Is a Data Protection Agreement (DPA) available?Yes - Available upon request
Do you conduct privacy impact assessments?Yes - For new features and integrations

FERPA Considerations

QuestionResponse
Can the platform be used in a FERPA-compliant manner?Yes - Ledly can operate as a “school official” under FERPA when processing education records
Do you sign FERPA compliance agreements?Yes - Available as part of contract negotiations
Is access to student data restricted?Yes - Role-based access controls limit data access
Are audit logs maintained for data access?Yes - Comprehensive audit logging
Can data be deleted to comply with FERPA?Yes - Data deletion capabilities support FERPA requirements

Data Subject Rights

QuestionResponse
Do you support data access requests?Yes - Customers can export all data
Do you support data deletion requests?Yes - Individual record and full account deletion
Do you support data portability?Yes - Export in standard formats (CSV, JSON)
Do you support right to rectification?Yes - Records can be updated or corrected
GDPR complianceYes - Compliant for EU data subjects
CCPA complianceYes - Compliant for California residents

Data Sharing

QuestionResponse
Is customer data shared with third parties?Only as necessary for service delivery (see subprocessors)
Is customer data used for marketing?No
Is customer data sold?No - Never
Can data sharing be restricted?Customers control which integrations receive their data

9. Network Security

Network Architecture

QuestionResponse
Is the network segmented?Yes - Separate network segments for application, database, and management
Are firewalls in place?Yes - Network and application-layer firewalls
Is a WAF (Web Application Firewall) used?Yes
Are network access controls enforced?Yes - Principle of least privilege for network access

Intrusion Detection and Prevention

QuestionResponse
Is intrusion detection deployed?Yes - Network and host-based IDS
Is intrusion prevention deployed?Yes - Automated blocking of detected threats
Are logs monitored for security events?Yes - 24/7 automated monitoring with alerting
Is a SIEM used?Yes

DDoS Protection

QuestionResponse
Is DDoS protection in place?Yes - Via Railway/AWS infrastructure
What DDoS mitigation is available?AWS Shield Standard included; enterprise DDoS protection available
Rate limiting implemented?Yes - API rate limiting to prevent abuse

Network Monitoring

QuestionResponse
Is network traffic monitored?Yes
Are network logs retained?Yes - 90 days minimum
Is traffic encrypted between internal services?Yes - mTLS for service-to-service communication

10. Vulnerability Management

Vulnerability Scanning

QuestionResponse
Are regular vulnerability scans performed?Yes - Weekly automated scans
Is penetration testing conducted?Yes - Annual third-party penetration tests
Are scan results tracked and remediated?Yes - Findings prioritized and tracked to resolution
Remediation SLAsCritical: 24 hours, High: 7 days, Medium: 30 days, Low: 90 days

Dependency and Patch Management

QuestionResponse
Is dependency scanning performed?Yes - Automated scanning via Dependabot/Snyk
How are security patches applied?Critical patches within 24-48 hours; regular patches during maintenance windows
Are systems kept up to date?Yes - Regular update schedule for all components
Is there a patch management policy?Yes

Security Development

QuestionResponse
Is secure coding practiced?Yes - OWASP guidelines followed
Is code reviewed for security?Yes - Mandatory peer review and automated scanning
Is SAST/DAST performed?Yes - Static and dynamic analysis in CI/CD pipeline
Are third-party libraries vetted?Yes - License and security review for dependencies

11. Business Continuity

Disaster Recovery

QuestionResponse
Is there a disaster recovery plan?Yes
Is the DR plan tested?Yes - Annual DR testing
Recovery Time Objective (RTO)4 hours
Recovery Point Objective (RPO)1 hour
Geographic redundancyYes - Multi-AZ deployment with cross-region backup

Business Continuity

QuestionResponse
Is there a business continuity plan?Yes
Is the BCP tested?Yes - Annual testing and review
Key personnel redundancyYes - No single point of failure for critical functions
Communication plan during outagesStatus page updates, email notifications to administrators

Backup Procedures

QuestionResponse
Database backup frequencyDaily full backups, continuous transaction logs
Backup storage locationEncrypted, offsite in separate AWS region
Backup verificationAutomated integrity checks; quarterly restoration tests
Self-service restorationAvailable for enterprise plans

12. Third-Party Risk

Subprocessors

Ledly uses the following subprocessors to deliver services:

SubprocessorPurposeData ProcessedLocation
RailwayCloud hosting and infrastructureAll application dataUnited States
AWS (Amazon Web Services)Underlying infrastructure (via Railway)All application dataUnited States
ResendTransactional email deliveryEmail addresses, notification contentUnited States
PostgreSQL (via Railway)Primary databaseAll customer and lead dataUnited States

Subprocessor Management

QuestionResponse
Are subprocessors contractually bound?Yes - Data processing agreements in place
Are subprocessors assessed for security?Yes - Security review before onboarding
Are customers notified of subprocessor changes?Yes - 30 days advance notice
Can customers object to subprocessors?Yes - Per contract terms

CRM Integrations

When customers configure CRM integrations, data flows to customer-selected destinations:

IntegrationData SharedCustomer Controlled
SalesforceLead data as configuredYes - Customer configures field mapping
HubSpotLead data as configuredYes - Customer configures field mapping
Microsoft DynamicsLead data as configuredYes - Customer configures field mapping
Custom WebhooksLead data as configuredYes - Customer specifies endpoint and payload
⚠️

CRM integrations are configured and controlled by customers. Data shared with CRMs is subject to the customer’s agreements with those providers.


Additional Security Measures

Logging and Monitoring

CapabilityDetails
Audit loggingAll user actions, API calls, and data access logged
Log retention90 days online, 1 year archived
Log integrityLogs are immutable and tamper-evident
Customer access to logsAvailable via admin dashboard and API

API Security

CapabilityDetails
API authenticationAPI keys with scoped permissions
Rate limitingConfigurable limits to prevent abuse
IP allowlistingAvailable for API key restrictions
Request signingAvailable for enhanced security

Change Management

QuestionResponse
Is there a change management process?Yes - All changes reviewed and approved
Are changes tested before deployment?Yes - Staging environment testing required
Is rollback capability available?Yes - Automated rollback on deployment failure
Are customers notified of changes?Yes - Advance notice for breaking changes

Contact Information

For security inquiries, HECVAT requests, or to report security concerns:

PurposeContact
Security questions[email protected]
HECVAT requests[email protected]
Report a vulnerability[email protected]
General support[email protected]
Sales and contracts[email protected]

Request the Full HECVAT: This summary covers key areas of the HECVAT assessment. For a complete HECVAT Lite or HECVAT Full questionnaire with detailed responses, please contact [email protected].


Document Information

FieldValue
Last UpdatedDecember 2024
Version1.0
Review CycleAnnual
Document OwnerLedly Security Team