HECVAT-Lite style answers
Standing answers to the questions that appear on HECVAT-Lite and comparable higher-education, municipal and government vendor assessments. Published so a reviewer can evaluate StrategyHub™ without waiting on a questionnaire round trip. Answers describe the product as it runs today; where a control does not exist, the answer says so.
Last updated August 24, 2026 · This is a self-assessment, not an independent audit.
Company and product
Describe the product and the data it holds.
StrategyHub™ is a multi-tenant SaaS strategic planning and strategy execution platform. Customer data consists of strategy content (vision, goals, initiatives, nested actions, KPIs and measurements, budgets, risks, milestones, wins, comments, attachments), account data (names, email addresses, organization membership, role assignments), and operational data (audit log entries, notification records, integration configuration).
Is the product designed to store regulated data (PHI, cardholder data, FERPA-restricted records, classified information)?
NoNo. StrategyHub is not designed for and should not be used to store PHI, payment card data, FERPA-restricted education records, or classified information.
Who operates the service?
Progress Partners Consulting LLC (DBA Gamechangers Consulting LLC), a U.S. entity. Security contact: security@strategyhub.io. Privacy contact: privacy@strategyhub.io.
Third-party assessments and certifications
Do you have a current SOC 2 Type II report?
NoNo. Not currently in scope or in progress. The underlying platform and infrastructure providers maintain their own audit programs; their reports are available from them under NDA.
Do you have ISO 27001 certification?
NoNo.
Has a third-party penetration test been performed in the last 12 months?
NoNo. Internal automated security scanning and row-level-security policy review are performed continuously, including a nightly automated sweep. An external penetration test has not yet been commissioned.
Do you hold FedRAMP, StateRAMP, CJIS or HIPAA authorization?
NoNo. Do not procure StrategyHub for workloads that require these authorizations.
Data residency and hosting
Where is customer data stored?
YesThe production PostgreSQL database and all file storage are hosted on Amazon Web Services in us-west-2 (Oregon, United States).
Can the application tier be served from U.S. infrastructure?
YesYes. A U.S. front door is available at strategyhub.io in addition to the managed platform origin, and individual workspaces can be pinned to it when a contract requires it.
Is data replicated or backed up outside the United States?
PartialBackups are managed by the platform provider within the same AWS region. StrategyHub does not currently have a contractual instrument pinning every subprocessor's processing region to the United States, though production data storage is in-region.
Is a published RPO/RTO available?
NoNo. Backups are managed by the platform provider; recovery objectives are not contractually stated and disaster recovery test evidence is not published.
Access control and authentication
Do you support SAML 2.0 single sign-on?
YesYes — Okta, Microsoft Entra ID and Google Workspace, available on the Enterprise plan.
Do you support multi-factor authentication?
YesYes. TOTP MFA is available to every user, with an email step-up verification fallback. Workspace admins can require MFA for all members of their workspace.
Can access be restricted by network location?
YesYes. IP and CIDR allowlisting is configurable per workspace and enforced server-side on every authenticated request.
Describe the role model and where it is enforced.
YesRoles are Admin, Goal Owner, Initiative Owner and Viewer, plus per-goal permission grants. Roles are stored in a dedicated authorization table — never on the user profile — and evaluated by a security-definer database function, so authorization is enforced in the database rather than only in the UI.
Is anonymous or self-service sign-up to an existing workspace possible?
NoNo. Anonymous sign-up is disabled; workspace membership requires an invitation.
Tenant isolation
How is one customer's data isolated from another's?
YesEach customer organization is a distinct tenant. Isolation is enforced by PostgreSQL row-level security policies: every read and write is scoped to the requesting user's organization memberships by the database itself, not by application query code. Insert and update policies additionally verify that referenced parent records belong to the same organization, which prevents a record from being re-pointed into another tenant. Table privileges are granted explicitly per role.
Are secrets and tokens exposed through the API?
NoNo. Webhook secrets, integration tokens, embed tokens, domain verification tokens and API key hashes are not readable through the public data API; only server-side code with elevated privileges can read them.
Encryption
Is data encrypted in transit?
YesYes. TLS for all client-to-application and application-to-database traffic. HSTS, X-Content-Type-Options: nosniff, Referrer-Policy and X-Frame-Options are set on both the managed origin and the U.S. front door.
Is data encrypted at rest?
YesYes, provided by the underlying managed database and object storage services.
Logging, monitoring and incident response
Is there an audit log of user activity?
YesYes. Workspace activity is recorded in an audit log capturing who changed what and when, visible to workspace admins.
Do you have a written incident response plan with notification timelines?
YesYes. It is published at /incident-response and commits to notifying affected workspace admins within 72 hours of confirming an incident where customer data was or may have been accessed, with a one-hour acknowledgement target for critical reports.
Data ownership, portability and deletion
Can a customer export all of its data without vendor assistance?
YesYes. Workspace admins can download a complete machine-readable JSON export of everything their workspace owns at any time from Settings → Data portability. No support ticket is required.
How is data deleted at the end of the relationship?
Individual records are deletable in-product by authorized roles. Full workspace or account deletion is performed by StrategyHub on written request to privacy@strategyhub.io and completed within 30 days of verification. On a lapsed subscription the workspace becomes read-only and nothing is deleted for 60 days. Operational logs may be retained beyond customer data deletion for a limited period for security purposes.
Artificial intelligence
Is customer data used to train AI models?
NoNo. StrategyHub does not use customer data to train any model. AI features send only the specific strategy text needed for a request, server-side, under a StrategyHub API credential, routed through the Lovable AI Gateway to Google Gemini models. Model-provider retention is governed by that provider's commercial API terms; StrategyHub does not assert a zero-retention guarantee. AI features are optional and per-request.
Accessibility
Is a VPAT or accessibility conformance report available?
PartialNot as a standing published document. The application is built on accessible component primitives with semantic markup, keyboard navigation and focus management, but no third-party WCAG audit has been performed. Accessibility questions are answered individually — contact sales@strategyhub.io.
Related: Security & U.S. data residency · Subprocessors · Incident response
