> ## Documentation Index
> Fetch the complete documentation index at: https://support.nectir.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Nectir AI Security and Compliance

> Where to find Nectir's SOC 2 report, HECVAT, VPAT, and subprocessor list, how to request Trust Center access, and how Nectir handles your data.

## Trust Center

Nectir's security and compliance documents are in the [Nectir Trust Center](https://app.vanta.com/nectir/trust/3as22kb996slor315lr4s). To see them, request access from the Trust Center page; Nectir grants access to current and prospective customers.

| Document                                  | What It Covers                                                                                                           |
| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| SOC 2 Type II report                      | Independent audit of Nectir's security controls                                                                          |
| GDPR report                               | Independent report on Nectir's GDPR controls                                                                             |
| HECVAT                                    | Nectir's answers to the Higher Education Community Vendor Assessment Toolkit                                             |
| VPAT and Accessibility Conformance Report | Support for WCAG 2.2 Level A and AA and Revised Section 508                                                              |
| Security policies                         | Access control, information security, vulnerability and patch management, AI ethics and governance, and related policies |
| Architecture diagram                      | The Nectir AI platform's components and data flow                                                                        |

FERPA has no vendor certification. For how Nectir protects student records, see the HECVAT and the SOC 2 report.

## How Nectir Handles Your Data

* **No selling or sharing:** Nectir doesn't sell your data or share it outside the service.
* **Subprocessors:** AI processing runs through subprocessors under Nectir's Data Processing Agreement (DPA). See Nectir's [subprocessor list](https://www.nectir.io/legal/subprocessors).
* **Conversations:** only the user who has a conversation can read it. Instructors and Workspace Owners see [usage analytics](/managing/assistant-analytics), such as message counts per user and the Key Topics across conversations, but not who asked what. Nectir enables identifiable exports (names, emails, and message text) only for approved research cases, and only Workspace Owners can download them.
* **LMS data:** see [What Data Nectir Accesses](/lms-integrations/canvas-overview#what-data-nectir-accesses) for what the Canvas integration receives, including the grade scopes it requests but doesn't use.

Questions about data handling? Contact [support@nectir.io](mailto:support@nectir.io).
