
HECVAT-Ready Wayfinding & Digital Signage for Universities & Colleges
Eye-In Media meets the security, privacy, and accessibility standards required by Canadian and US post-secondary institutions — including the HECVAT framework used by 240+ universities and colleges.
100% Canadian SaaS
Azure Canada Hosted
No Personal Data Collected
PIPEDA Compliant
WCAG 2.1 AA
Majority Women-Owned
Security Summary for IT Procurement Teams
Eye-In Media's Wayfinder platform is anonymous by design. It does not collect, store, process, or transmit any personal, institutional, or sensitive data of any kind. No user accounts are created. No integration with institutional systems is required. The platform operates as a fully standalone SaaS solution hosted exclusively on Microsoft Azure Canada — making it one of the lowest-risk technology deployments a university can make, with no data sovereignty concerns and no FERPA, HIPAA, or PIPEDA obligations triggered for the institution.
What Is HECVAT?
Understanding the Framework
The Higher Education Community Vendor Assessment Toolkit (HECVAT) is the standard security evaluation framework used by colleges and universities across North America to assess technology vendors before procurement.
240+
Institutions Use HECVAT
Developed by EDUCAUSE, Internet2, and REN-ISAC, HECVAT has become the de facto standard for higher education vendor security reviews — covering cybersecurity, privacy, accessibility, and compliance in a single framework.
4.1
Current Version (HECVAT 4.1.5)
Released February 2025, HECVAT 4 consolidates Full, Lite, and On-Premise assessments into one unified workbook with conditional logic — vendors only answer sections relevant to their solution type and data handling.
7
Assessment Sections
HECVAT 4 covers Organization, Product, Infrastructure, IT Accessibility, Privacy, AI Governance, and Case-Specific areas. Vendors complete only the sections triggered by their qualifying answers — most of which do not apply to Eye-In Wayfinder.
0
Personal Data Collected by Eye-In
Because our platform collects zero personal or institutional data, the majority of HECVAT's conditional sections are simply not triggered. Eye-In Media's security review process is fast and uncomplicated for university IT teams.
Data Privacy
What Data Does Eye-In Wayfinder Collect?
Short answer: almost nothing personal. Here is the full picture, exactly as your IT security team will need it.
Data Category
Collected?
Stored?
Transmitted?
Personal identifiable information (PII) — name, email, student ID
✗ No
✗ No
✗ No
Student records or academic data (FERPA / PIPEDA protected)
✗ No
✗ No
✗ No
Health or medical information (PHI / HIPAA)
✗ No
✗ No
✗ No
Authentication credentials (passwords, tokens)
✗ No
✗ No
✗ No
Financial or payment data
✗ No
✗ No
✗ No
Device identifiers or persistent cookies tied to individuals
✗ No
✗ No
✗ No
Anonymous session analytics (aggregated navigation events)
✓ Yes
✓ Yes
✗ No
CMS content — maps, directories, building info (non-personal)
✓ Yes
✓ Yes
✗ No
* Anonymous analytics are aggregated and contain no personal or device-level identifiers. Accessible only to authorized Eye-In Media administrators. All data hosted exclusively on Microsoft Azure Canada.
HECVAT 4 Assessment
HECVAT Start Here — Qualifying Questions
HECVAT 4 uses a "Start Here" tab (questions REQU-01 through REQU-08) to route vendors into only the relevant assessment sections. Here are Eye-In Media's answers — the ones that determine whether your institution needs a full review.
Ref
Qualifying Question
Collected?
REQU-01
Does the solution collect, store, or process personal data of students, staff, or guests?
No — fully anonymous
REQU-02
Does the solution integrate with institutional systems (SIS, LMS, HR, ERP)?
No — standalone deployment
REQU-03
Does the solution process protected health information (PHI)?
No
REQU-04
Does the solution process financial or payment data?
No
REQU-05
Does the solution require on-premises installation or network access?
No — 100% SaaS
REQU-06
Does the solution store or process data outside Canada?
No — Azure Canada only
REQU-07
Does the solution use AI/ML to make decisions about individuals?
No
REQU-08
Would a service outage disrupt critical institutional operations?
Low risk — wayfinding aid only
Assessment
Based on the qualifying responses above, Eye-In Wayfinder does not trigger the conditional sections of HECVAT 4 that require extended review at most Canadian and US institutions. A HECVAT Lite assessment and a full Security & Privacy Summary document are available upon request for institutions that require formal documentation.
Infrastructure Security
Security Controls
Our platform is built on enterprise-grade infrastructure with security measures aligned to higher education standards.
Encryption in Transit
TLS 1.2+ enforced on all connections between users and the platform.
Encryption at Rest
Azure-native AES-256 encryption for all stored data.
Admin MFA
Role-based access control with mandatory multi-factor authentication for all CMS administrators.
Azure Canada Infrastructure
Hosted exclusively on Microsoft Azure Canada — ISO 27001 certified data centres. Data never leaves Canada.
Business Continuity
Azure redundancy with automated failover and documented business continuity plan.
Incident Response
Documented incident response process with defined client notification protocol and SLA.
Trusted By
Canadian Healthcare & Education References
Eye-In Media is deployed and operational at leading Canadian healthcare and academic institutions.
McGill University Health Centre (MUHC)
Glen site — digital signage and wayfinding deployment
Lakeshore General Hospital
CIUSSS Ouest-de-l'Île-de-Montréal — live AR wayfinding deployment
Hôpital Fleurimont + Centre mère-enfant
CHUS, Santé Estrie — wayfinding solution
Montreal Children's Hospital
Wayfinding and interactive directory deployment
Eye-In Media is a semi-finalist for the Prix d'excellence de l'administration publique du Québec (IAPQ) — recognizing innovation in public sector technology.
Ready for Your IT Security Review?
We provide a full Security & Privacy Summary document, HECVAT Lite assessment, and direct access to our technical team — so your procurement process moves fast.