Collaboratory IT + Systems FAQ
Collaboratory is a secure, cloud-based solution engineered to integrate seamlessly into the higher education technical ecosystem with minimal IT burden. These FAQs provide a comprehensive overview of Collaboratory's technical architecture, security protocols, and integration capabilities, offering IT professionals and data managers a clear understanding of how Collaboratory functions as a reliable, enterprise-grade partner for your campus data.
Foundational Aspects of the Platform
What are your application and database platforms?
A SaaS (Software as a Service) - based application powered by a graph postgres database, API written in Go, and a Javascript frontend user interface. The entire SaaS application is hosted securely on Amazon Web Services (AWS) data centers within the United States.
Is a plug-in required for your web-based platform? If yes, which one?
No.
Where is data stored?
Do you use any 3rd party repository for file transfer, file storage or file sharing?
Are your infrastructure components fully redundant?
Yes.
What is the availability of the system?
Is there a scheduled maintenance window?
How do you scale your system during peak usage?
How are systems monitored?
What kind of authentication and access control procedures are in place?
Are logs maintained of access to an institution’s data?
Yes.
Do you offer a test environment?
We offer a test environment for inbound API integrations.
How is data imported?
Collaboratory accepts flat file uploads during the onboarding process to populate the dataset with units, members, courses, and community organizations. Collaboratory also supports inbound API integrations that allow campus systems (e.g., SIS, LMS, HR system, or an existing engagement database) to securely send data into Collaboratory on an ongoing basis. You can learn more about Collaboratory’s inbound API here.
How is data exported?
What aspects of Collaboratory are customizable?
Every Collaboratory portal comes equipped with a core, standardized dataset informed by national best practices and field literature. However, to reflect your specific institutional context, campuses can define and manage custom fields, including drop-downs, checkboxes, and text inputs across any step of the Activity Form. Campuses also have the flexibility to remove or "unrequire" standard fields. These custom responses are captured alongside our core data and are fully available for your reporting and data exports. Note that the ability to fully customize data fields and form structure is available to institutions specifically within Collaboratory’s Strategic Tier contract.
Is Collaboratory mobile-enabled and capable of functioning across various devices?
Is technical support documentation available?
Yes. All users can access Collaboratory's online Help Center that includes a full suite of resources and technical documentation to assist with utilizing Collaboratory. Collaboratory also has in-app chat functionality provided by Intercom to provide with real-time assistance 9am ET - 5pm ET.
Security
Has a security audit been performed to any of the following standards: PCI-DSS, CIS Security Benchmarks, ISO 27001/2, NIST 800-12, or other?
What detection methods do you have to determine if the data has been breached by an outside source?
Do you regularly update virus protection?
Are new security patches installed within two weeks of release?
Yes.
Do you perform testing for security risks?
Yes.
Do you test against the OWASP Top 10 Application Security Risks? How often?
Yes. Once per quarter.
Do you perform penetration testing?
Yes. We do automated penetration testing of Collaboratory. ZAP is the tool we use to do vulnerability testing. OWASP is the standard we adhere to that identifies vulnerabilities and builds them into the tool. We use the ZAP security scanner quarterly. We apply fixes to medium- to critical-level vulnerabilities.
How often do you scan for vulnerabilities on your network and applications?
Quarterly.
Do you restrict and monitor your employee access to data 24x7?
What were the findings of your most recent security audit?
Can Collaboratory provide a current third-party/independent attestation of information security controls (e.g. SSAE 18, PCI DSS, AOC), or a self-attestation (e.g. HECVAT, CSA CAIQ) on a regular basis?
Does Collaboratory agree to respond and cooperate during an information security investigation/assessment, process/record review/audit?
Does Collaboratory provide audit logs?
How do you protect against outside threats?
Data Privacy + Protection
What measures do you take to ensure data privacy?
Please see our Privacy Policy.
Is it possible for any third party to access data?
Who at the provider’s premises can see your data and what internal controls does the provider have in place to prevent unauthorized viewing, copying or emailing of customer information?
How do you isolate and safeguard institutional data from other clients?
How is data purged?
What actions do you take to destroy data after it is released by a customer?
How often is data backed up?
How are data backups maintained?
Can data be restored?
Yes.
What encryption protocols are used to secure data at rest and data in motion within the product?
Are backups encrypted?
What are your disaster recovery strategies?
Compliance
Is Collaboratory ADA compliant?
Is the system and do your policies support FERPA compliance?
Does your hosting provider have a SAS 70 type II certification or equivalent certification?
What Data is Collected
Does Collaboratory store/transmit/receive or have access to any credit card information?
What personal data does Collaboratory collect?
Is sensitive data masked/encrypted such that only authorized individuals have access to the data?
SSO + Authentication
Do you support SSO and if so, which standards?
How long does it take to set up SSO?
Approximately 2 weeks.
What minimal attributes does Collaboratory request to establish SSO?
- EduPersonPrincipalName
- givenName
- Surname
- eduPersonAffiliation
Is Collaboratory a member of the InCommon Federation to assist with SSO setup?
Yes.
Do you support account lockout when login credentials are entered incorrectly?
How are community partner / non-SSO passwords protected?
Does Collaboratory support multi-factor authentication (MFA)?
What are the password strength parameters?
Communications
What is your procedure for handling a data breach and how will the customer be notified?
Is the institutional member notified of hardware failures, configuration errors, or compromises?
In case of a database failure, what point in time can you restore the application’s data and how long will it take?
Does Collaboratory send emails on behalf of the institution?
What is the maximum number of emails per day that Collaboratory would send to users?
Will Collaboratory generate email from a specific IP address or set of IP addresses?
The specific IP numbers and domains used by Collaboratory include the following. They were confirmed on 9/2020:
-
54.240.35.1
-
54.240.35.2
-
54.240.35.3
Do Collaboratory domains have applicable SPF and DKIM records in place to send authenticated email?
Can Collaboratory send email via authenticated SMTP?
No.
API, Integrations, + AI
Do you offer third party integrations?
Does Collaboratory integrate with, link to, or access a payment gateway?
Does Collaboratory offer an outgoing, public API?
Does Collaboratory support inbound data feeds from other campus systems?
Yes. Collaboratory offers an inbound API integration that allows campus systems (for example, your SIS, LMS, HR system, or an existing engagement database) to securely send data into Collaboratory on an ongoing basis. Campuses typically use this to keep foundational information current, such as units, courses/sections, member records (faculty, staff, and students), partner organizations, and activities, so that engagement professionals can focus more on using the data and less on re-entering it. Inbound API setup is coordinated with your campus IT contact and the relevant data owners, and Collaboratory’s team provides guidance through testing, validation, and go-live. You can learn more about Collaboratory’s inbound API here.
Does Collaboratory provide a sandbox or test environment for institutions?
Yes.