Our Commitments

The NROC Project is committed to accessibility and security.

On Universal Access And Opportunity

We believe that all students should have access to high-quality educational opportunities.

Universal access and opportunity—the idea that ALL students, including systematically disenfranchised and underrepresented populations, deserve fair and inclusive treatment—is a lens that we apply to our mission-based work.

We rally behind and build curricula and tools that strengthen college and career readiness because we know that postsecondary education often improves career trajectories, positively disrupting the cycle of generational poverty and its associated ills.

We don't think NROC is the answer, but we consistently aim to be part of the solution. From design ethics to partnerships, universal access and opportunity drives our organizational priorities.

On Accessibility

We're dedicated to making learning experiences engaging and accessible for everyone.

Wherever possible, we adhere to a conformance level of AA of the Web Content Accessibility Guidelines (WCAG 2.2). These guidelines outline the following accessibility principles.

  • Perceivable - Information and user interface components must be presentable to users in ways they can perceive;
  • Operable - User interface components and navigation must be operable;
  • Understandable - Information and the operation of user interface must be understandable; and
  • Robust - Content must be robust enough that it can be interpreted reliably by a wide variety of user agents, including assistive technologies.

Download our current Voluntary Product Accessibility Template (VPAT) or read the EdReady Accessibility Statement.

On Security and Privacy

AICPA SOC aicpa.org/soc4so

We take data protection and access seriously.

EdReady employs best practices in data security, and only the minimum possible amount of personally identifiable data (PII) is acquired by default. We maintain a System and Organization Controls (SOC 2 Type II) security certification with AICPA, a cybersecurity risk management authority.

Regardless of the nature of our partnership and any other specified service-level agreements, our security commitments include, but are not limited to, the following:

  • Use of encryption technologies to protect data both at rest and in transit.
  • Network segmentation to ensure that customer data are not shared with other customers.
  • Flexible and (optionally) hierarchical permissions and data-access structures to manage roles in a manner that mirrors local requirements.
  • Robust single-sign-on (SSO) and API capabilities to integrate with external account-management and access-control systems.
  • Direct interaction with NROC’s development and support teams as part of our ‘community-guided’ model, including matters of enhanced security.

Read our standard Terms of Use and Privacy Policies.