Resources
SOC 2 Report
We are pleased to share our finalized SOC 2 Type 2 report. Protecting the confidentiality and integrity of your data is our highest priority. This independent assessment reflects our ongoing commitment to maintaining a robust and proven security posture
2026 Penetration Test Confirmation
We are pleased to share the formal Attestation of the annual external Penetration Test for Pathify, conducted by an independent third-party security firm between February 2026 and March 2026.
Higher Education Community Vendor Assessment Tool (HECVAT) - 4.1.6 (2026)
Pathify simplifies vendor risk assessments for higher education institutions by offering a completed Higher Education Community Vendor Assessment Tool (HECVAT). By providing full transparency into our data privacy practices, infrastructure, and security controls, Pathify helps IT and information security teams verify compliance quickly and accelerate procurement.
Voluntary Product Accessibility Template (VPAT)
This document is the 2026 VPAT v2.5 (and includes a summary view of the Pathify position as it relates to applicable concerns and the ethical position informing that position, and a strict compliance statement, criteria by criteria against Web Content Accessibility Guidelines 2.2 AA (WCAG 2.2AA)
Acceptable AI Policy (AAIP)
Governs the permitted and prohibited uses of the AI Agent and AI features within Pathify systems, organized by AI Agent function and by how each function is treated under Colorado Senate Bill 26-189 and analogous state frameworks. It sets out what data reaches the model provider, the per-data-point controls the institution holds, the FERPA school official architecture, and how each function is classified for automated decision-making purposes
Data Processing Addendum (DPA)
Pathify's data processing terms as processor, covering security measures, subprocessors, cross-border transfer mechanisms, breach notification, and jurisdiction-specific terms for the United States, EEA, Switzerland, the United Kingdom, Australia and New Zealand. Schedule 5 lists the subprocessors in effect as of its Last Updated date.
CXP Terms of Use
The terms that apply to individuals using the Campus Experience Platform, including acceptable use, use of the AI Agent, intellectual property, security and privacy, and accessibility. These sit alongside the agreement between Pathify and the institution rather than replacing it.
CXP Privacy Policy
Pathify's published privacy policy for the Campus Experience Platform ("CXP"), addressed to the students, applicants, faculty, staff and alumni who use it.
Pathify Testing Methodologies
The purpose of this document is to describe the testing methodologies Pathify conducts regularly on its codebase and internal systems to ensure that the Pathify software is snappy and secure and that Pathify’s internal systems are within widely adopted industry standards.
Monitoring
Compliance
