vet···EDTECH AI & Vendor Risk Vetting

Give every AI tool a red, yellow, or green light.

vetEDTECH walks you through a structured security & privacy review of any AI tool or third-party service, then produces a clean report you can hand straight to District Information Security. The rubric mirrors the HECVAT 4 framework higher-ed institutions actually use — plus the specific documentation your CISO asks for.

Green — Approve

Strong, documented controls. Independent audit on file, no model-training on your data, least-privilege access. Safe to recommend for approval.

Yellow — Conditions

Workable, but with gaps. Approvable if specific conditions are met — a contract clause, a narrower scope, or follow-up documentation.

Red — Hold

A critical control is missing or the tool trains on your data. Needs remediation or a different vendor before it goes anywhere near institutional accounts.

How it works

STEP 01

Describe the tool

Name, vendor, what it does, and what data it would touch.

STEP 02

Answer in plain language

Each question explains itself — no security background needed.

STEP 03

Get a live score

The rubric scores as you go and flags any deal-breakers.

STEP 04

Export the report

One clean PDF for your CISO. Saved to your library for next time.

Review Library

Saved assessments, stored in this browser

New Review

Scored against HECVAT 4 categories · saves automatically as you go

Plain-Talk Glossary

The IT terms your CISO uses — translated