Protecting the data institutions trust us with.

You are the steward of sensitive information, from student records to research data to financial details. We treat that responsibility with the seriousness it deserves, and we designed Kuali's security practices to protect what you store on the platform.

OUR PROMISE

Our commitment to excellence.

Kuali provides secure, privacy-conscious cloud software solutions designed to support compliance with a wide range of regulatory requirements. Through a shared responsibility model, we partner with our customers to ensure both parties play their part in protecting data and meeting legal obligations.

As a cloud service provider (CSP), Kuali acts as a data processor, handling and processing data on behalf of our customers. Our core responsibility is to ensure that entrusted data is managed securely and in compliance with applicable privacy and security regulations. This includes implementing strong technical and organizational safeguards, protecting against unauthorized access, maintaining data integrity, supporting reliable backups, and assisting our clients in meeting their regulatory obligations.

We empower our clients to focus on their core business operations while confidently meeting their regulatory obligations. Together, we strive to protect the privacy and security of data in an increasingly complex digital landscape. For more detailed information about our privacy practices, please refer to our Privacy Policy.

Key areas of support:

Compliance Management

We support our clients’ compliance efforts related to applicable regulations by providing comprehensive security and privacy controls.

Our compliance documentation and reporting tools facilitate regular audits and assessments, supporting customers’ continuous alignment with regulatory standards. Data is encrypted both at rest and in transit, protecting it from unauthorized access and keeping it confidential.

Access and Audit Controls

Access to customer data is restricted to employees with a legitimate business need. Access is logged and monitored through audit trails. When an employee leaves the organization, access is revoked promptly in accordance with our offboarding procedures.

Data Protection and Security

We integrate with customer Identity Providers (IdPs) to support federated Single Sign-On (SSO), multi-factor authentication, and adherence to password security policies.

Our software features a configurable role- and permission-based access control.

All customer data is encrypted both in transit and at rest.

Our two-tier backup strategy includes:

Real-time replication across clusters with a minimum of two nodes, geographically aligned with data origin. These clusters are configured with automatic failover. If the primary server fails, a secondary server will automatically be promoted to replace it.

In addition to real-time replication, we perform standard backups, including daily snapshots.. We do snapshot backups at least daily. We test this strategy during our annual disaster recovery exercise.

Application Security

We leverage third-party tools and services to continuously scan for vulnerabilities. Detected issues are prioritized and remediated based on severity.

A formal Software Development Life Cycle (SDLC) process governs the design, implementation, and maintenance of all applications.

Risk Management

We conduct regular risk assessments to identify and mitigate potential threats.

Our risk management strategies are aligned with industry best practices and regulatory standards to protect against data breaches and other security incidents.

Training and Awareness

Our staff complete security training twice a year to stay informed about evolving security practices, emerging threats, and regulatory changes.

Incident Response

Kuali maintains a well-defined incident response plan to ensure prompt and effective management of security incidents and potential data breaches.

We support customers in fulfilling notification requirements to affected parties and relevant regulatory bodies.

Specific compliance requirements.

We recognize that our customers operate in diverse regulatory environments. We are committed to addressing these needs effectively.

Family Educational Rights and Privacy Act

Depending on the information stored in Kuali products, we may process education records on behalf of educational agencies or institutions subject to FERPA. Kuali is committed to supporting compliance with FERPA in partnership with our customers.

Kuali is responsible for providing secure infrastructure, access controls, and audit logging to support FERPA compliance.

Customers are responsible for classifying education records, managing user permissions, and ensuring proper configuration of their Kuali instance.

Note: While data marked as deleted is retained, requests for permanent deletion can be submitted through our customer support portal to support institutions’ FERPA compliance obligations.

Health Insurance Portability and Accountability Act (HIPAA)

When storing protected health information (PHI) in Kuali systems, we may act as a Business Associate under HIPAA.

Kuali is responsible for safeguarding infrastructure, maintaining audit trails, and signing a Business Associate Agreement (BAA) upon request.

Customers are responsible for ensuring appropriate use of PHI within the system, securing user access, and complying with use and disclosure policies. We partner with clients to ensure mutual understanding of responsibilities and appropriate use of the platform for HIPAA-related data.

Gramm-Leach-Bliley Act

GLBA (Gramm-Leach-Bliley Act)

While GLBA does not apply directly to Kuali, we understand it may apply to our customers. We are committed to supporting customers subject to GLBA.

Kuali provides technical and organizational safeguards including encryption, role-based access, and incident response.

Customers are responsible for data classification, user access policies, and ensuring GLBA-relevant processes are followed in their use of the software.

We are happy to collaborate on an agreement that defines shared responsibilities under GLBA.

General Data Protection Regulation

GDPR (General Data Protection Regulation)

If you store personal data in Kuali products, we may act as a data processor or subprocessor under the GDPR. Kuali supports compliance through a shared responsibility model:

Kuali is responsible for safeguarding infrastructure and implementing privacy-by-design features.

Customers are responsible for how data is collected, used, and managed within the application.

We support customers in fulfilling data subject rights, including access, rectification, erasure, and portability. Please note that data marked as deleted is retained unless a formal request for permanent deletion is submitted through our customer support portal. We are also happy to sign a Data Processing Agreement (DPA) upon request.

California Consumer Privacy Act

CCPA (California Consumer Privacy Act)

Kuali supports customers that may be subject to applicable state privacy laws, including the CCPA. In providing our services, Kuali generally acts as a service provider by processing personal information on behalf of customer institutions. Kuali supports customers by enabling workflows and best practices aligned with CCPA principles:

Kuali supports best practices in data handling, transparency, and user rights.

Customers are responsible for identifying whether CCPA applies to them and implementing relevant workflows for data access and deletion requests.

Payment Card Industry Data Security Standard (PCI DSS)

Kuali software is not designed to process or store payment card data. Customers are expected to ensure that no cardholder information is entered or stored within the system.

Shared responsibility with subservice providers.

As a cloud service provider (CSP), we rely on a select group of trusted subservice providers to support the delivery of our platform. In this context, we operate under a Shared Responsibility Model, which defines the division of security and compliance obligations between us and our subservice providers.

Under this model, our subservice providers are responsible for securing the infrastructure and services they deliver (e.g., physical data centers, network hardware, and core platform services), while we are responsible for how we configure, manage, and operate our application on top of those services. This includes safeguarding our customers’ data, managing access controls, and ensuring secure application behavior.

With our subservice providers, where applicable, we:

Perform continuous vulnerability scanning, monitoring, and patch management.

Require multi-factor authentication (MFA).

Enable logs and tools for continuous monitoring and auditability.

Enforce encryption at rest and in transit.

Restrict inbound ports and protocols to minimize exposure to network attacks.

Perform secure backups and routinely validate restore procedures as part of disaster recovery planning.

Apply the principle of least privilege in access configurations.

Disable insecure defaults, such as anonymous access and unrestricted administrative access.

Perform annual penetration testing and security audits.

Enable TLS encryption for all client-database connections.

Limit network access through IP whitelisting and private endpoints.

Use minimal base images for container deployments to reduce vulnerability surface.

Perform regular scanning of containers for known vulnerabilities before deployment.

CERTIFICATIONS & COMPLIANCE

Kuali certifications and assessments.

To offer additional assurance and support procurement requirements, Kuali maintains the following certifications and assessment reports:

SOC 2 Assessment

This is a widely recognized auditing framework that evaluates a service organization’s controls relevant to the Trust Services Criteria (TSC). For select products, an independent SOC 2 assessment demonstrates that Kuali has implemented controls to safeguard customer data and ensure operational resilience meeting the TSC for Security, Availability, and Confidentiality.

Higher Education Community Vendor Assessment Toolkit (HECVAT)

The HECVAT is a standardized security assessment tool published by EDUCAUSE in collaboration with community volunteers, Internet2, and REN-ISAC to evaluate cloud vendors’ information security and data protection practices. Kuali primarily serves institutions of higher education and is committed to alignment with institutional policies and regulatory requirements.

TX-RAMP

This is a state-run program that establishes standardized security assessment and authorization requirements for cloud products and services used by Texas state agencies, including public higher education institutions. It ensures that vendors providing cloud services to Texas public entities meet applicable baseline cybersecurity standards required for procurement and ongoing use.

Accessibility Conformance Report (ACR/VPAT)

This evaluates how well a software product conforms to accessibility standards. It helps institutions ensure digital equity and accessibility for users with disabilities. Kuali continuously works to improve product design with accessibility in mind and strives to conform to WCAG 2.2 AA guidelines.

Get the documents you need.

Existing Customers

Submit requests through your Kuali support portal.

Working with a Sales Rep

Reach out directly to your assigned Kuali sales representative. They can coordinate document requests and connect you with the right team.

New to Kuali

Please contact us if you would like to acquire any of the reports, have questions, or need further assistance.

Contact us →
START THE CONVERSATION

See Kuali's security program in detail.

Request our SOC 2 report, HECVAT documentation, or a walkthrough of how we protect institutional data.