Compliance

The Standards Your Review Board Asks About

Annoto is built for institutional procurement: interoperability, privacy, and accessibility documented and ready for your security and legal review.

Request DocumentationSecurity & Trust →
Learn more: A standards-driven approach for your review board
Compliance

A standards-driven approach your review board can work with

Bringing a new tool into teaching means bringing it through review: security questionnaires, privacy assessments, accessibility checks, and procurement policies that differ from one institution to the next. Annoto is built and operated with that reality in mind. Rather than treating compliance review as an obstacle, we treat it as part of the product — the process is smoother when a vendor arrives organized, transparent, and already speaking your reviewers' language.

Anchored in recognized frameworks

Our security and privacy practices are organized around widely used industry frameworks and the expectations institutional review boards apply to education technology. Controls are documented, access is role-based and least-privilege, and changes to the platform go through defined review. Because Annoto integrates through LTI 1.3 with Canvas, Moodle, Blackboard, Brightspace, and Open edX, identity and enrollment stay governed by your LMS — Annoto inherits your roles rather than inventing a parallel account system.

Privacy and data minimization

Annoto processes learner data for one purpose: making video learning work. Discussions, quiz responses, notes, and attention and comprehension analytics exist to serve instructors and students in the course, and analytics export and completion and gradebook sync move data along paths your institution controls. We collect what the pedagogy requires and no more, and we are explicit with reviewers about what is stored, where, and for how long.

Documentation for your reviewers

Security overviews, data-processing descriptions, and architecture documentation are available on request to support vendor assessments, and our technical documentation at docs.annoto.net covers integration details your IT team will want early. If your process uses a standard questionnaire, we will complete it; if it needs a call between your security team and ours, we will schedule one. Questions from review boards get direct answers, not marketing language.

Institutions worldwide have taken Annoto through procurement, security review, and privacy assessment, and each round has made our answers sharper and our documentation better. If you are starting that process now, contact us early — we can usually shorten it by giving your committee exactly what it needs in the first exchange rather than the fourth.

What a typical review actually involves

Most institutional reviews of Annoto follow a familiar arc: a security questionnaire, a data-flow description showing what moves between the LMS and Annoto over LTI 1.3, a privacy assessment against your local regulations, and sign-off from whoever owns LMS integrations. The useful early step is scoping. Because authentication stays with your LMS, Annoto never receives institutional passwords, and the data exchanged is limited to what the integration needs, so reviewers can concentrate on the actual surface rather than a hypothetical one. We supply the data-flow description in the first exchange so your committee scopes from evidence, not assumption.

Accessibility questions, answered upfront

Review boards increasingly weigh accessibility alongside security, and video tools get particular scrutiny. Annoto's interaction layer is designed to work with the assistive technologies your students already use, and captions remain a function of the underlying player — Kaltura, Panopto, YouTube, Vimeo, or Wistia — so existing captioning workflows continue unchanged. Notes and AI summaries give students additional ways into the same material beyond the video itself. Accessibility documentation is available on request in the format your review process expects, and where a committee raises a specific barrier, we treat it as a finding to address, not an objection to argue with.

Responsibilities after the approval

Approval is a snapshot; operating responsibly is ongoing. The division of responsibility stays clean: your institution governs identity, enrollment, roles, and retention decisions, while Annoto operates the service within the boundaries your review approved. When something material changes on our side — architecture, sub-processors, data handling — we tell you rather than letting your next annual review discover it. Institutions that re-assess vendors on a yearly cycle can request refreshed documentation each round, and exports over CSV or API mean your data remains portable for the entire life of the contract, including its end.

Standards & Regulations

LTI 1.3 Advantage

Modern 1EdTech interoperability: secure launch, deep linking, roster services, and gradebook pass-back.

FERPA

Student education records handled as protected data. Annoto acts as a school official under your direction.

GDPR

EU data subject rights supported end to end. DPA available, with EU data residency options.

WCAG 2.1 AA

Keyboard-navigable, screen-reader-tested interface. VPAT / accessibility conformance report on request.

SCORM / xAPI

Engagement and completion events emit to your LRS and reporting pipeline in standard formats.

SSO / SAML & OIDC

Learners and instructors sign in through your identity provider. No separate Annoto passwords.

ISO 27001 Certified

Annoto holds ISO/IEC 27001 certification for its information security management system.

HECVAT Available

A completed Higher Education Community Vendor Assessment Toolkit (HECVAT) is available for review.

Illustration representing Annoto's security certifications and compliance assessments
Data Handling

Your Learners’ Data, Treated Like It Matters

Clear answers to the questions your DPO will ask, before they ask them.

Encrypted Everywhere: TLS in transit, encryption at rest.
Data Residency Options: EU or US hosting, chosen per institution.
No Ads, No Resale: learner data is never sold or used for advertising.
Retention You Control: deletion and export on institutional request.
In-video engagement illustration
Compliance Guides

The standards, applied to course video

Practical guides to the requirements review boards ask about most — and how video courses meet them.

FAQ

Frequently Asked Questions

Which standards and regulations does Annoto support?
LTI 1.3, FERPA, GDPR (with DPA), WCAG 2.1 AA accessibility, and SCORM/xAPI compatibility.
How does Annoto support RSI (Regular & Substantive Interaction)?
Annoto adds instructor-initiated, time-stamped, substantive interaction inside course video and documents it with analytics, supporting RSI requirements for online courses.
Can we get a DPA and accessibility documentation?
Yes. A Data Processing Agreement and WCAG/VPAT accessibility documentation are available on request for your review.
Where is learner data stored?
Annoto adds an engagement layer over your existing video and supports regional data residency; request the DPA for specifics on storage and retention.
Procurement

Ready For Your Security Review

Request our compliance pack with DPA, VPAT, and security documentation, or put your IT team in the room with ours.