Skip to content
ComputingAmerica

Higher Education & Research

The most open network in the country, holding some of the most sensitive work in it.

A research university is a genuinely hard security and software environment, and it is hard for reasons that are structural rather than fixable. Openness and collaboration are the mission, not an oversight. Faculty are not employees in the way a corporate security model assumes. Federal sponsors impose obligations that arrive as terms in an award document rather than as a control framework. And the same institution is simultaneously a hospital, a utility, a hotel chain, a payment processor and a defense subcontractor. We have built and run software on this side of the fence, and we design for the institution that exists rather than the one an enterprise architecture diagram would prefer.

What we hear

The problems that actually show up.

Not a market overview. These are the specific failures that bring people to us in this sector.

  • Research security asked for as a question nobody can answer

    NSPM-33 and the sponsor disclosure regime expect an institution to know its researchers' outside affiliations, subawards and collaborations. That information exists, scattered across conflict-of-interest filings, publication records, award documents and public data, and nobody has ever joined it up.

  • Controlled data in an uncontrolled environment

    One award brings CUI into scope and suddenly a lab that has always worked in the open needs an NIST 800-171 enclave, a system security plan and a POA&M, on the timeline of the award rather than of the IT department.

  • Program administration eating the program

    Cohort tracking, placements, completion evidence and reporting to a sponsor run on spreadsheets maintained by the person who has the least time. Programs are lost to administrative overhead far more often than to bad outcomes.

  • A workforce pipeline that stops at the diploma

    The institution graduates capable people every year and the regional employers who need them have no structured way to meet them before an interview.

  • Instructional infrastructure that cannot scale

    Hands-on technical courses need isolated environments per student, reset between sections and available at 2am the night before it is due. Building that once is a project; running it every semester is a system.

What we build here

Systems we’ve shipped in this sector.

Some of these are whole products; some are one screen that removed a week of manual work. Both count.

  • Research-collaboration graphs and affiliation risk review tooling
  • Sponsored-program, subaward and disclosure workflow systems
  • CUI enclaves and NIST 800-171 system security plan evidence automation
  • Cyber ranges, instructional labs and competition platforms
  • Cohort, scholarship and program-tracking systems with sponsor reporting
  • Research data platforms, catalogs and controlled-access repositories
  • Instrument and core-facility scheduling and chargeback
  • Student-facing service portals built to Section 508 and WCAG

Integrates with

The estate you already have.

We work through supported interfaces, not screen-scraping that breaks at the next upgrade.

  • Banner
  • PeopleSoft
  • Workday Student
  • Kuali Research
  • Canvas / LMS integrations
  • InCommon / Shibboleth
  • ORCID
  • Globus
  • Elasticsearch

Built to

The standards this sector answers to.

Engineered in from the start. Retrofitting conformance costs several times as much and produces a worse result.

  • NSPM-33
  • NIST 800-171 / CMMC Level 2
  • FERPA
  • HIPAA (academic medical centers)
  • Export control: EAR / ITAR
  • Section 508 / WCAG 2.2 AA

Case studies

Work in this sector.

Next step

Working in higher education & research?

Bring the specific failure, not a requirements document. Forty-five minutes and we’ll tell you what we’d do about it.