Trust center
Security and data handling that respect student data.
Prospective students trust you with their plans, documents and contact details. This page lists the controls in higheredcrm.ai, the privacy tools your team can use, the documents your procurement office will ask for, and how we behave when something goes wrong.
It's your applicants' data.
We look after it on your behalf, and only on your behalf.
Controls your IT team will recognize.
Every control listed here is available in the product today, for every institution that signs up, from a single college to a multi-campus university.
- Multi-factor authenticationAuthenticator app with backup codes. Make it optional or mandatory for your organization.
- Single sign-onStaff sign in through your OpenID Connect identity provider, so access follows your own joiner and leaver process.
- Roles and permissionsCustom roles with per-page view, create, edit, delete and export permissions, plus role templates and teams.
- Your own sessionsEach user sees where they are signed in and can end other sessions or log out of all devices. Deactivating a user signs them out everywhere.
- Audit logsChanges are recorded across the system, with a full audit history on every lead record.
- Field and credential encryptionAES-256 encryption for stored integration credentials and for any custom field you mark for encryption.
- API keys with IP allow-listsEach API key accepts calls only from the network ranges you list, with rate limiting against abuse.
- Verified inbound webhooksIncoming webhooks are checked with an HMAC signature or a secret header before anything runs.
- Scoped API keysEach API key carries its own scopes and quotas, and can be revoked, rotated or reactivated.
Security & procurement pack
Every document a review asks for, with its status today.
Your IT, data protection and procurement colleagues can check this list before the first call. Anything marked on request goes to the email below.
- Available nowOn this page
Security controls overview
Every control in the product today, feature by feature.
- Available nowOn this page
Certification status
No SOC 2, ISO 27001 or other security certification is held.
- Available nowOn this page
Incident response process
How we contain, notify, explain and improve.
- Available nowsecurity.txt
Vulnerability disclosure policy
How to report a security issue, also published as security.txt.
- Available nowPrivacy policy
Privacy policy and terms of service
Including the launch offer terms.
- Available nowDevelopers and API
API overview
Authentication, scopes, inbound webhooks and examples. The full endpoint reference comes with your account.
- On requestRequest it
Data processing agreement
We act as your processor for applicant data.
- PartialSub-processors
Sub-processor list
Published, with what each third party does. Entries marked pending are being confirmed: hosting and messaging providers are confirmed in writing before you sign.
- On requestRequest it
Security questionnaire answers
Send your institution's questionnaire, or a standard one your review team uses; we answer it in full.
- Before you signRequest it
Hosting provider, region and wider encryption details
Ask us; we answer this in writing before you sign, so your data protection officer can review it.
- Not available todayRequest it
Accessibility conformance report (VPAT or ACR)
Not published. Ask us about the accessibility questions your procurement process includes.
Requests go to security@higheredcrm.ai. Running a formal evaluation? The security review checklist in our evaluation kit follows the same order as this page.
Privacy tools
Privacy tools on the lead record.
Tools your team uses every day to respect data privacy, built into the lead record where counselors already work.
Opt-outs, masking and history, where counselors work.
In higheredcrm.ai, contact preferences, access and history sit on the lead record, and every change to the record is logged.
- Do-not-contact and per-channel opt-outs on each lead, checked automatically before every send
- Contact masking for the roles you choose: they see partial phone numbers and emails, and can still call and write
- Audit history on every lead: who changed what, and when
- Role permissions that control who can view, edit, delete or export
- Lead record export to Excel or CSV, with an export history, so you can see what left the system
Certifications
Reviewed by your team, not by a badge
Our product is new. Your reviewers get the controls on this page, complete questionnaire answers and our commitments in writing.
higheredcrm.ai does not currently hold SOC 2, ISO 27001 or any other security certification. What we offer instead:
- Complete answers to your security questionnaire
- A call with the people who build and run the platform
- Our commitments written into your contract
- An update on this page if our certification status changes
If an incident touches your data, you hear it from us first.
No system is perfect. What matters is how quickly a problem is found, how clearly it's explained and what changes afterwards. Four steps, in this order.
- 1
Contain
We investigate as soon as an issue is detected and act first to protect your data and restore service.
- 2
Tell you
If your data may be affected, we notify you without undue delay, and within any timeframe your agreement sets.
- 3
Explain
You get a written account of what happened, what it means for your applicants and what we're doing about it.
- 4
Improve
After every significant incident, we review the cause and share the changes we've made to prevent it happening again.
Responsible AI
Where AI is used, and what it can't do.
The AI Assistant, built on Anthropic's Claude, gives your team a daily briefing: who needs attention, which leads need a follow-up and your conversion rate, answered in the language you ask in. Lead scoring, routing and chatbots run on rules your team sets and can read.
A daily briefing for your team
Ask what to do today and it lists the leads that need attention, with shortcuts to open the record, schedule a follow-up or write an email.
It never saves or sends
The Assistant never saves changes or sends messages. Staff complete every action themselves, and admissions decisions stay with your people.
Rules your team can read
Scoring, routing and chatbots follow rules and flows your team builds and can inspect, so every score shows why and every route can be explained.
Supporting your obligations
Institutions recruit under GDPR, FERPA and similar laws. Your institution stays responsible for how it uses applicant data. higheredcrm.ai helps you meet those obligations through concrete features: do-not-contact and per-channel opt-outs, role permissions, contact masking, audit logs and lead record export to Excel or CSV.
We act as your processor for applicant data, and a data processing agreement is available for every customer. The third parties that process data for us are listed on our sub-processors page. Read our privacy policy and terms of service.
Responsible disclosure
If you believe you've found a security vulnerability in higheredcrm.ai, please tell us privately so we can fix it before it can be misused. Include enough detail for us to reproduce the issue, and give us reasonable time to respond before sharing it publicly.
We'll acknowledge your report, keep you updated, and won't pursue action against good-faith research that avoids harm to our customers and the people in their records. Please don't access, change or keep data that isn't yours.
Questions from IT, privacy and procurement
Do you hold SOC 2 or ISO 27001 certification?
No. We don't hold any security certifications today, and we won't imply that we do. Instead, we answer your security questionnaire in full, walk your IT team through our controls and put our commitments in writing in your contract.
Will higheredcrm.ai make our institution GDPR or FERPA compliant?
Compliance is something your institution achieves through its own policies and practices, so no software can make you compliant on its own. higheredcrm.ai helps you meet obligations under GDPR, FERPA and similar laws through concrete features: do-not-contact and per-channel opt-outs, role permissions, contact masking, audit logs and lead record export to Excel or CSV.
Where is our data hosted?
Tell us about any data-location requirements early in the conversation. We confirm hosting details for your institution in writing before you sign, so your data protection officer can review them.
Can our IT security office complete a review before signing?
Yes, and we encourage it. Send us your questionnaire or ask for a call with the people who run the platform. The security and procurement pack above lists each document and its status, and the evaluation kit includes a security review checklist mapped to this page.
Who owns the applicant data we put into higheredcrm.ai?
You do. We process applicant data on your behalf and on your instructions. You can export your lead records to Excel or CSV at any time. If you don't continue after the free period, your lead records stay exportable to Excel or CSV for 30 days, then we delete your account data. Paid contracts follow the return-and-deletion terms in your agreement.
Does the AI Assistant make decisions about applicants?
No. The AI Assistant, built on Anthropic's Claude, gives your team a daily briefing and answers questions about your CRM data, with shortcuts that open a record or a form. It never saves changes or sends messages, and admissions decisions stay with your people.
Is lead scoring done by AI?
No. Lead scoring in higheredcrm.ai is rule-based. Your team defines the parameters, weights, tiers and activity rules, and every score change is kept in the lead's score history.
Bring your toughest security questions.
Send us your security questionnaire and we'll answer it in writing, then walk your IT and data protection colleagues through each control on screen.