What we attest to today. What’s on the roadmap.
Honest scope: this page distinguishes what UniRubric has today (complete) from what is signed-up-for and underway (in progress), from what is committed but not yet started (planned), from what does not apply to this product (not applicable).
Australian Privacy Principles (APP)
CompleteRegistered AU operator. Privacy Policy and Notifiable Data Breach scheme alignment documented. Cross-border disclosure section in Privacy Policy at /privacy.
GDPR — Article 28 DPA
CompleteData Processing Addendum available on contract. EU tenant region (eu-central-1) available for institutions with sovereignty requirements.
GDPR — Article 35 DPIA
In progressData Protection Impact Assessment template authored. Institution-specific DPIA completed jointly with each EU pilot.
Target: Per-pilot basis from first EU institutional pilotFERPA (US institutions)
In progressFERPA-aligned data handling documented. School Official designation language available in MSA. US tenant region (us-east-1) available on contract.
Target: Reviewed jointly with each US pilotSOC 2 Type II
PlannedType I readiness assessment scheduled. Type II audit follows the first full reporting period.
Target: Audit firm engagement begins after the first institutional pilot is in steady-state; Type II report follows a full reporting period thereafterISO/IEC 27001
PlannedNot currently required by Australian higher-ed RFPs. Will pursue if at least three institutional procurement processes request it.
Target: Demand-drivenCSA STAR (Level 1 — self-assessment)
CompleteCAIQ-Lite v4 pre-fill maintained as the canonical CSA STAR Level 1 document for UniRubric. Reissued at least quarterly and on material configuration change.
CSA STAR (Level 2 — third-party attestation)
PlannedFollows SOC 2 Type II completion.
Target: Follows SOC 2 Type II completionPCI DSS
Not applicableUniRubric never sees a card number. Payment is handled by Stripe and PayPal, both PCI DSS Level 1. We store only Stripe/PayPal customer references.
HIPAA
Not applicableUniRubric is an education product, not a health product. No PHI handled.