Security and Trust
Certifications, Examinations, and Assessments
CollegeNET undergoes an independent SOC 2® Type II examination every year, most recently completed April 3, 2026. The SOC 2 report covers security, availability, confidentiality, and processing integrity, along with the Privacy Trust Services Criterion.
For payment card data, CollegeNET completes a PCI DSS Self-Assessment Questionnaire A (SAQ A) annually and submits the resulting Attestation of Compliance through SecureTrust, a compliance validation service, as well as to our bank. SAQ A applies to merchants that fully outsource all cardholder data functions to PCI DSS validated third parties. CollegeNET does not store, process, or transmit cardholder account data on its own systems.
CollegeNET also regularly completes the HECVAT (Higher Education Community Vendor Assessment Toolkit) for institutions that request one, and keeps a current version on hand for each academic year.
Available on request under a signed non-disclosure agreement:
- SOC 2 Type II report
- Additional compliance and review documentation
- Summary penetration test results
- System architecture and data flow diagrams
- A completed, current HECVAT
Data Ownership and Portability
Your institution owns its data, not CollegeNET. You can request a full copy of your production data at any time, and CollegeNET will provide it in XML or another mutually agreed format within 30 days of a written request. Your data is also available continuously through CollegeNET's authenticated and fully documented API.
Infrastructure and Hosting
Because we care about the security of your data, CollegeNET builds, owns, and operates its hosting environment directly, rather than outsourcing it to a separate hosting company or absorbing it into someone else's cloud platform. That environment is physically housed in co-located data center space, with a secondary disaster recovery site located far enough away that a single regional event wouldn't affect both. Institution data is logically separated from other customers' data within the platform.
Both facilities are staffed around the clock, monitored by video surveillance, and enclosed within physical barriers that restrict access to authorized personnel only. The facilities include redundant power, fire suppression, and multiple network provider connections.
Network traffic is filtered through stateful firewalls, and multiple network- and host-based intrusion detection systems monitor continuously, with alerts routed to on-call security staff around the clock, 365 days a year.
Data Encryption
Data in transit is protected with TLS 1.2 or better, using strong, industry-standard encryption ciphers. Data at rest, including backups, is encrypted using AES-256. CollegeNET manages and rotates encryption keys through a documented key management process.
Access Control and Authentication
CollegeNET encourages every institution to use single sign-on. Series25 applications support Shibboleth, SAML 2.0, ADFS, and LDAP (including Active Directory), among other identity providers, at no additional cost. CollegeNET is a member of the InCommon Federation. Sessions expire automatically after a period of inactivity.
Inside 25Live, permissions are managed through role-based Security Groups, using a multi-layered system that governs feature access, record-level access, and scheduling responsibility for specific spaces and resources.
Internally, CollegeNET staff access is governed by role-based access controls and unique individual accounts, and all administrative access requires multi-factor authentication.
Application Security and Development
Development, testing, and production environments are separated, and every change goes through documented authorization, testing, and approval before it reaches production. Security patches are applied within 30 days of release. CollegeNET also undergoes external vulnerability scanning through an approved scanning vendor on a regular basis, a good practice performed voluntarily alongside its PCI DSS obligations.
In addition to internal penetration testing performed by CollegeNET's own IT and QA teams after every major release, an independent third party conducts additional testing as part of the annual SOC 2 examination cycle.
Institutions that want to integrate 25Live with other campus systems can use the Series25 WebServices API, a REST-based API documented to the OpenAPI 3.0 specification, supporting both JSON and XML.
Artificial Intelligence and Your Data
Some 25Live and Connect25 features use AI to speed up routine tasks. In 25Live, it can help a scheduler create an event for a specific time and headcount, refine a location search, and build complex searches. In Connect25, it can help build forms and workflows. In every case, a person reviews the result before it's final, and every AI feature is opt-in and can be turned off institution-wide.
CollegeNET's AI features use a scoped connection to a third-party language model solely to generate responses. No customer data is used to train any model, no institutional data is retained by the AI provider, and access is limited to specific, narrow use cases. Staff who work with AI features complete responsible AI training as part of CollegeNET's broader privacy and security program.
Business Continuity and Disaster Recovery
CollegeNET maintains a documented disaster recovery and business continuity plan, reviewed at least annually and tested every year through a tabletop exercise.
Backups run on a frequent, regularly scheduled basis across production servers and databases, with transaction logs replicated on an ongoing basis from the data centers. Backups are encrypted and sent to an independent, geographically separate storage provider on a regular schedule, with backup encryption keys kept in a separate, secured location from the backups themselves.
If CollegeNET's primary data center became unusable, systems administrators would be alerted immediately through 24/7 monitoring and would fail over to our redundant site. In a worst-case scenario, CollegeNET is committed to recovering and relocating quickly, and most incidents resolve far faster than that.
Workforce Security
Every CollegeNET employee goes through a background check before joining, and anyone with access to sensitive or customer data signs a confidentiality agreement that's renewed regularly. Staff working remotely follow a documented Hybrid and Remote Work Policy, and remote access to CollegeNET systems requires two-factor VPN authentication. Anti-malware protection is required on every employee workstation.
Incident Response
CollegeNET maintains a documented incident response plan, staffed by a team that completes annual incident response training, with at least one member on call 24 hours a day, 7 days a week. If an incident affects your institution, CollegeNET commits to prompt notification and ongoing updates until it's resolved, in addition to the support already available from your account manager and CollegeNET's technical support team. CollegeNET also carries cyber-risk insurance covering service outages, data loss, and security incidents.
Privacy and Compliance
CollegeNET has had no data breaches requiring notification to individuals, institutions, or regulators, and no violations of its internal privacy policies or applicable privacy law. CollegeNET does not process or store institutional data in the European Economic Area or in China.
We have a strict policy against selling, renting, or trading personally identifiable information to third parties for marketing or any other purpose. Read the full Privacy Policy (collegenet.com/privacy) for details on what we collect and how we use it.
What Data We Collect
- Protected health information (PHI): Not required
- Credit card or payment information: Not required
- Biometric or genetic information: Not required
- Student record data covered by FERPA: 25Live doesn't require it. Connect25 may include student organization contact and membership information your institution chooses to enter.
- Personal data from EU or UK individuals (GDPR): Only if your institution voluntarily enters it into Connect25. Not stored or processed in the EU, UK, or China.
- Device and IP address information: Collected in security logs only.
- Session cookies: Limited to identity provider session tokens used for sign-in.
Built for Higher Education, Not Retrofitted for It
CollegeNET works exclusively with colleges and universities, so security here looks different than it does anywhere else. Our platform is built and secured in-house, with compliance reports that cover the infrastructure your data actually lives on, not a third-party platform underneath it.
Frequently Asked Questions
Is data encrypted in transit?
Yes. All data in transit is encrypted with TLS 1.2 or better.
Is data encrypted at rest?
Yes. Data at rest, including backups, is encrypted with AES-256.
Where are your servers located?
Both the primary and secondary sites are located within the United States, far enough apart that a single regional event wouldn't affect both.
Do you support single sign-on?
Yes. 25Live and the rest of the CollegeNET scheduling suite support Shibboleth, SAML 2.0, ADFS, and LDAP (including Active Directory), at no additional cost. CollegeNET is a member of the InCommon Federation.
Who owns our data?
Your institution does, always. You can request a full copy at any time.
Do you sell or share our data with third parties?
No. CollegeNET has a strict policy against selling, renting, or trading personally identifiable information. CollegeNET develops its software entirely in-house, without subcontractors.
Can our institution run its own security testing against your systems?
Yes, with a signed non-disclosure agreement and at a mutually agreed time and methods.
Want to Know More?
Contact your CollegeNET account manager or use our form to request a SOC 2 report, compliance documentation, a completed HECVAT, or answers to your institution's specific security questions under an NDA.