LMS Bridgefor professors ← Back

For institutions

If LMS Bridge is being adopted across multiple instructors in your program or department, your data governance, IT, and compliance teams will want documentation. Below is everything they typically ask for. Share the relevant links directly — no gatekeeping, no lead-capture friction.

FERPA-Compliant Implementation: Student identities are anonymized via SHA-256 hashing before any external processing. All API access is logged with 365-day retention for compliance audits. Canvas tokens are encrypted at rest with AES-256. Non-education domain users are blocked at login. Per-student data is never persisted; aggregate outcomes computed in-memory only. Sub-processors documented; the DUA template designates LMS Bridge as a "school official" under FERPA upon execution.

Data Use Agreement (DUA) — template

FERPA-aligned DUA template, designed to be redlined by your General Counsel against your institution's standard form. Includes Schedule A specific to the outcomes assessment data flow.

Download / view →

Privacy Policy

What we collect, why, how it's stored, retention windows, sub-processors, and FERPA position. The reference for what an instructor agrees to at signup.

Read →

Terms of Service

Click-through terms each individual instructor accepts at signup. Does not bind your institution; the DUA covers institutional designations.

Read →

Acceptable Use Policy

What instructors agree not to do with the Service. Includes the explicit duty to initiate a DUA conversation when use expands beyond individual pedagogy.

Read →

HECVAT / SIG Lite questionnaire

Pre-completed responses available on request. Covers data protection, business continuity, vulnerability management, sub-processors. Reply within 5 business days.

Request →

Sub-processor list + DPIA

Current sub-processors (AWS, Anthropic, Resend) with jurisdiction + data-flow notes, plus a draft Data Protection Impact Assessment for high-risk processing reviews.

Request →

Audit logging & FERPA safeguards

Complete audit trail (365-day retention) of all API access with hashed student IDs. Data anonymization, 30-day soft-delete policy, encryption at rest, and educator domain validation. Full documentation and testing results.

Request →
Who to talk to: for institutional procurement, security review, DUA negotiation, or scoping a pilot covering more than 3 instructors — hello@lmsbridge.ai. We aim to reply within one business day.