Security & Compliance

Enterprise-Grade Security, Built For Learning

Annoto meets the privacy, accessibility, and compliance requirements institutions and enterprises demand.

Talk To Security
A secure layer over your existing video
Learn more: How Annoto approaches protecting learner data
Security & privacy

How Annoto approaches protecting learner data

In education, trust is a precondition. Students speak candidly inside course video only when they know the conversation belongs to their class, and institutions adopt tools only when they can see how data is protected. Annoto's security posture is built for both audiences, and it is designed to meet the privacy expectations of educational institutions. The details below are the short version; the long version is written down and available to your reviewers.

Data protection as a design constraint

Learner data in Annoto exists to support learning: discussions, notes, quiz responses, and viewing analytics. It is protected in transit and at rest, and scoped to the course context it came from. Personal notes remain personal, class conversation stays inside the class, and analytics are visible to the roles with a legitimate teaching or administrative need, not to everyone with a login. Retention and deletion follow the institution's direction rather than the vendor's convenience.

Access follows institutional identity

Because Annoto deploys through LTI 1.3 inside your LMS, access control starts with your own sign-on. There are no separate passwords to leak and no self-registered accounts drifting outside your identity lifecycle. Roles map from the LMS, so a student, an instructor, and an administrator each see precisely what their role permits, and when someone leaves the institution, your LMS remains the single switch. Deprovisioning happens where it should: in your directory, once.

Controls and visibility for administrators

Institutional admins govern moderation defaults, feature availability, and data flows, and can export data by CSV or API under their own control rather than requesting it from a vendor. Documentation of the architecture and data handling practices is available for IT and privacy review teams at docs.annoto.net, written to answer the questions those teams actually ask.

This posture has carried Annoto through the scrutiny of institutions worldwide, whose security and privacy reviews are rarely gentle. If your team is evaluating Annoto right now, the fastest path is the technical documentation, followed by a working session with people who have answered these questions many times before. Both are readily available.

Data minimization starts with the architecture

Annoto runs as an interaction layer on top of the video players an institution already operates — Kaltura, Panopto, Wistia, YouTube, Vimeo — so the platform never needs to ingest or store your media library. What it holds is the interaction record: who commented at which timestamp, how a quiz was answered, where attention dipped. Keeping the media itself out of scope shrinks the attack surface and shortens every privacy conversation, because reviewers can quickly confirm that the most sensitive asset — recorded lectures, clinical scenarios, internal briefings — never changes hands.

AI features bound by the same rules

The AI capabilities in the platform — discussion summaries and the Lumo copilot, built specifically for education — operate on the same course-scoped data as every other feature and under the same role permissions. They exist so instructors and students can work with what the class has already produced, not to build behavioral profiles or feed advertising systems. Whether AI features are enabled at all is an institutional decision, made through admin settings rather than inherited from a vendor default.

What a security review looks like in practice

Most evaluations follow a familiar arc: the institution's security questionnaire, an architecture walkthrough with the people responsible for data flows, then a scoped pilot in a sandbox course before production rollout. Annoto supports each step with written answers rather than improvised ones — data-flow descriptions, retention specifics, and configuration guidance your reviewers can cite in their own reports. Running the pilot behind LTI in a test course lets IT verify role mapping, gradebook behavior, and analytics visibility exactly as students would experience them, before any real learner touches the tool.

Operating the service responsibly over time

A security posture is not a one-time claim; it is how a service is run week after week. Annoto maintains continuous monitoring, ships updates without customer-side maintenance windows, and communicates changes that affect data handling through channels administrators actually watch. When your institution revises its own policies — a new retention rule, an updated privacy notice — the admin controls described above are the mechanism for bringing the platform into line, without a support queue standing between policy and enforcement.

Illustration representing Annoto's security certifications and compliance assessments
Certifications & Assessments

Independently Certified, Ready For Review

Annoto's security and compliance posture is documented and available for your review.

ISO/IEC 27001 Certified: Annoto holds ISO/IEC 27001 certification for its information security management system.
HECVAT Available: A completed Higher Education Community Vendor Assessment Toolkit (HECVAT) is available for review.
FERPA & Student Data Privacy: purpose-built for FERPA and student data privacy.
GDPR & DPA Available On Request: GDPR-ready, with a Data Processing Agreement on request.
WCAG 2.1 AA Accessible: Accessible to WCAG 2.1 AA, verified by VPAT.
LTI 1.3 Secure Integration: Secure, standards-based LTI 1.3 install.
Data Privacy

How We Keep Learner Data Safe

SSO & MFA Access

Single sign-on with MFA and role-based access.

Data Privacy By Design

Least data collected; privacy built into every feature.

Regional Data Residency

Choose where your data is stored and processed.

Encryption Everywhere

Encrypted in transit and at rest, end to end.

Compliance documentation
Procurement-Ready

Compliance Your Procurement Team Will Approve

Everything reviewers ask for, ready to go.

FERPA & Student Data Privacy: purpose-built for FERPA and student data privacy.
GDPR & DPA Available On Request: GDPR-ready, with a Data Processing Agreement on request.
Request Documentation

Everything Your IT And Legal Teams Need

One secure layer over your existing video, wherever it lives.

Talk To Security →

LTI 1.3 Secure Integration

Secure, standards-based LTI 1.3 install.

Cloud Infrastructure Security

Hardened cloud infrastructure and monitoring.

Incident Response

A clear incident response and disclosure process.

Access Controls & Roles

Granular roles and organization-level controls.

WCAG 2.1 AA Accessibility

Accessible to WCAG 2.1 AA, verified by VPAT.

VPAT Available

VPAT documentation available for review.

FAQ

Security & Trust: Frequently Asked Questions

Is Annoto FERPA and GDPR compliant?
Yes. Annoto is built for education, with FERPA alignment, GDPR & DPA support, and regional data-residency options.
What authentication and access controls are supported?
SSO and MFA, with role-based access. Inside an LMS, access flows through the LTI 1.1 or 1.3 session. Outside one, learners authenticate against your own platform and Annoto accepts that identity over JWT or SAML, so there is no second account store either way.
Is Annoto accessible (WCAG)?
Yes. Annoto conforms to WCAG 2.1 AA, with keyboard navigation and screen-reader support. A VPAT is available on request.
Where is our data stored, and what does Annoto keep?
Annoto adds an engagement layer over your existing video and supports regional data residency. For specifics on what's stored and retention, request our Data Processing Agreement.

Talk To Us

Book a 15 minute demo to see Annoto inside your LMS, or send your security questionnaire, VPAT or DPA request straight to our security team.