Capture Higher Ed Trust Center

Transparency about security, compliance, and infrastructure in one place.

Trust Center

Capture Higher Ed

Data-driven enrollment solutions for higher education

Updated on 2026-05-31

Capture Higher Ed provides behavioral intelligence and predictive analytics to help colleges and universities identify, engage, and enroll prospective students.

SOC 2 Type II certified. 2026 audit complete — report now available.
Annual SOC 2 Type II audit via independent assessorContinuous vulnerability scanning and remediation35 security policies reviewed and maintained annuallyFERPA-aligned data handling for student records

Uptime

99.99%

trailing 12 months

Policies

35

actively maintained security policies

Compliance

2

SOC 2 Type II, TX-RAMP Type 2

Certifications & compliance

SOC 2 Type II

Scope: Security, Availability & Confidentiality

Certified

Audit year: 2025

TX-RAMP Type 2

Scope: Texas Risk and Authorization Management Program

Certified
FAQs

Available documents

SOC 2 Type II Report

Audits

Independent auditor report for the June 1, 2025 – May 31, 2026 examination period, covering the Security, Availability, and Confidentiality trust service criteria.

Request onlyConfidentialUpdated on 2026-05-31

TX-RAMP Type 2 Report

Certifications

Texas Risk and Authorization Management Program certification documentation.

Request onlyConfidentialUpdated on 2025-11-01

HECVAT

Assessments

Higher Education Community Vendor Assessment Toolkit — completed questionnaire.

Request onlyConfidentialUpdated on 2026-01-15

VPAT — Capture Behavioral Intelligence

Accessibility

Voluntary Product Accessibility Template for the Capture BI platform.

Request onlyConfidentialUpdated on 2025-12-01

VPAT — Capture Interactive

Accessibility

Voluntary Product Accessibility Template for Capture Interactive products.

Request onlyConfidentialUpdated on 2025-12-01
Stack & infrastructure

Hosting: Amazon Web Services (AWS)

Encryption: AES-256 at rest, TLS 1.3 in transit

Retention: Audit logs retained per SOC 2 requirements

Backups: Automated daily backups with tested recovery procedures

Regions: us-east-1

Data centers: AWS US East (N. Virginia)

Policies & controls

Written Information Security Program

Owner: IT Security • Organization-wide security program governance

Cadence: Reviewed annually

Access Control

Owner: IT Security • Least-privilege access, MFA enforcement, role-based controls

Cadence: Reviewed annually

Incident Response

Owner: IT Security • Detection, containment, eradication, recovery, and post-incident review

Cadence: Reviewed annually

Business Continuity & Disaster Recovery

Owner: IT Security • RTO/RPO targets, backup procedures, recovery testing

Cadence: Reviewed annually

Change Management

Owner: IT Security • Jira-tracked change approval, testing, and rollback procedures

Cadence: Reviewed annually

Encryption

Owner: IT Security • AES-256 at rest, TLS 1.3 in transit, key management

Cadence: Reviewed annually

Vendor Risk Management

Owner: IT Security • Third-party assessment, SOC 2 report collection, ongoing monitoring

Cadence: Reviewed annually

Data Classification

Owner: IT Security • Classification tiers, handling requirements, labeling standards

Cadence: Reviewed annually

Subprocessors (4)
Amazon Web Services logo

Amazon Web Services

United StatesCloud infrastructure

Primary cloud provider for compute, storage, and database services.

Microsoft 365 logo

Microsoft 365

United StatesProductivity and collaboration

Email, document collaboration, and identity management via Azure AD.

OpenAI logo

OpenAI

United StatesArtificial intelligence

AI model inference for select product features.

S

Snowflake

United StatesData warehouse and analytics

Cloud data warehouse for analytics and reporting on enrollment data.