Annoto is built for institutional procurement: interoperability, privacy, and accessibility documented and ready for your security and legal review.
Bringing a new tool into teaching means bringing it through review: security questionnaires, privacy assessments, accessibility checks, and procurement policies that differ from one institution to the next. Annoto is built and operated with that reality in mind. Rather than treating compliance review as an obstacle, we treat it as part of the product — the process is smoother when a vendor arrives organized, transparent, and already speaking your reviewers' language.
Our security and privacy practices are organized around widely used industry frameworks and the expectations institutional review boards apply to education technology. Controls are documented, access is role-based and least-privilege, and changes to the platform go through defined review. Because Annoto integrates through LTI 1.3 with Canvas, Moodle, Blackboard, Brightspace, and Open edX, identity and enrollment stay governed by your LMS — Annoto inherits your roles rather than inventing a parallel account system.
Annoto processes learner data for one purpose: making video learning work. Discussions, quiz responses, notes, and attention and comprehension analytics exist to serve instructors and students in the course, and analytics export and completion and gradebook sync move data along paths your institution controls. We collect what the pedagogy requires and no more, and we are explicit with reviewers about what is stored, where, and for how long.
Security overviews, data-processing descriptions, and architecture documentation are available on request to support vendor assessments, and our technical documentation at docs.annoto.net covers integration details your IT team will want early. If your process uses a standard questionnaire, we will complete it; if it needs a call between your security team and ours, we will schedule one. Questions from review boards get direct answers, not marketing language.
Institutions worldwide have taken Annoto through procurement, security review, and privacy assessment, and each round has made our answers sharper and our documentation better. If you are starting that process now, contact us early — we can usually shorten it by giving your committee exactly what it needs in the first exchange rather than the fourth.
Most institutional reviews of Annoto follow a familiar arc: a security questionnaire, a data-flow description showing what moves between the LMS and Annoto over LTI 1.3, a privacy assessment against your local regulations, and sign-off from whoever owns LMS integrations. The useful early step is scoping. Because authentication stays with your LMS, Annoto never receives institutional passwords, and the data exchanged is limited to what the integration needs, so reviewers can concentrate on the actual surface rather than a hypothetical one. We supply the data-flow description in the first exchange so your committee scopes from evidence, not assumption.
Review boards increasingly weigh accessibility alongside security, and video tools get particular scrutiny. Annoto's interaction layer is designed to work with the assistive technologies your students already use, and captions remain a function of the underlying player — Kaltura, Panopto, YouTube, Vimeo, or Wistia — so existing captioning workflows continue unchanged. Notes and AI summaries give students additional ways into the same material beyond the video itself. Accessibility documentation is available on request in the format your review process expects, and where a committee raises a specific barrier, we treat it as a finding to address, not an objection to argue with.
Approval is a snapshot; operating responsibly is ongoing. The division of responsibility stays clean: your institution governs identity, enrollment, roles, and retention decisions, while Annoto operates the service within the boundaries your review approved. When something material changes on our side — architecture, sub-processors, data handling — we tell you rather than letting your next annual review discover it. Institutions that re-assess vendors on a yearly cycle can request refreshed documentation each round, and exports over CSV or API mean your data remains portable for the entire life of the contract, including its end.
Modern 1EdTech interoperability: secure launch, deep linking, roster services, and gradebook pass-back.
Student education records handled as protected data. Annoto acts as a school official under your direction.
EU data subject rights supported end to end. DPA available, with EU data residency options.
Keyboard-navigable, screen-reader-tested interface. VPAT / accessibility conformance report on request.
Engagement and completion events emit to your LRS and reporting pipeline in standard formats.
Learners and instructors sign in through your identity provider. No separate Annoto passwords.
Annoto holds ISO/IEC 27001 certification for its information security management system.
A completed Higher Education Community Vendor Assessment Toolkit (HECVAT) is available for review.

Clear answers to the questions your DPO will ask, before they ask them.
Practical guides to the requirements review boards ask about most — and how video courses meet them.
Request our compliance pack with DPA, VPAT, and security documentation, or put your IT team in the room with ours.