Built for your IT team's standards, not around them
Everything below in one place, so it can be forwarded, printed or pasted into a procurement form without anyone having to ask us first.
THE SPECIFICATION
Position by position.
Tenancy
Own subdomain and own isolated database per institution. Every request resolves to one institution before it touches data.
Deployment
Browser based, nothing to install. On-premises single-tenant deployment supported from the same codebase.
Single sign-on
SAML 2.0 and OIDC. Google and Microsoft supported.
Access control
Role based, enforced at the API rather than hidden in the interface. Super admin, admin and manager tiers, plus custom roles built per institution.
Audit
Complete trail. Platform domain events, an automatic record of every mutating administrative request, and a per-institution activity feed.
Encryption
In transit and at rest.
Data residency and retention
Configurable.
Compliance
HECVAT, GDPR and FERPA aligned.
AI architecture
RAG-based isolation. AI operates as an assistive and explainable system, not an autonomous decision maker on high-stakes outcomes. The Career Readiness Score is computed deterministically, and no student personal data reaches the model in the Command Center path.
AI cost transparency
Every AI call is metered and attributed by activity, model and student, with a full call ledger.
Entitlements
Modules gated per plan and overridable per institution: SSO, API access, white labelling, custom questions, data export, advanced reporting.
Roles
The institution is the controller of its education records. SkillDrift processes on your instructions under a data processing agreement. Purposes, subprocessors, retention and residency are set out there rather than left to interpretation.
Portability, for the institution
Export your analytics, summary and detailed, as CSV, at any time. Placement analytics, department scorecards and cohort data. Nothing is held hostage and there is no exit fee.
Portability, for the student
A student can download their own profile, dimension scores, learning history and interview records. Student initiated and student controlled.
The written position
Our full data ownership and processing position, including the split between institutional data and student data, is set out in the software usage agreement and the data processing agreement. Both are available on request before you sign anything.
DOCUMENTS
Ask and we will send the file, not a description.
Completed HECVAT workbook
The Higher Education Community Vendor Assessment Toolkit, filled in.
GDPR data processing documentation
Processing purposes, subprocessors, retention, residency, and the rights available.
Written FERPA position
How we treat education records and what the institution remains controller of.
LTI 1.3 conformance evidence
For your LMS team.