Security
Open OnDemand takes security seriously, and we work with institutional security teams to make that evaluation easy.
Security overview
Read about Open OnDemand's security architecture and the enhancements we've made to protect organizations and users in the documentation's security overview.
HECVAT
In partnership with OSC Security, the Open OnDemand maintainers have completed a Higher Education Community Vendor Assessment Toolkit (HECVAT) for Open OnDemand. Per our security policy, we don't publish the HECVAT publicly, but it's available on request.
- Learn more about the HECVAT: educause.edu HECVAT overview
- Request a copy: security [at] openondemand.org (security[at]openondemand[dot]org)
Security audits
Open OnDemand has undergone independent security review by Trusted CI, the NSF Cybersecurity Center of Excellence:
- 2021 Trusted CI Engagement Final Report — vulnerability assessment tooling and disclosure process review
- 2019 Trusted CI Vulnerability Assessment Report — initial First Principles Vulnerability Assessment