Most Secure Course Evaluation Software (2026): ISO 27001, SOC 2, GDPR & Data Residency Compared
A vendor-by-vendor security comparison of course evaluation platforms for European universities — ISO/IEC 27001, SOC 2 Type II, EU data residency, encryption and GDPR Article 9 handling — written for IT-security, DPO and procurement teams.
Koji Education Team
Product ·
Short answer: the "most secure" course evaluation platform for a European university is the one that pairs an independently audited security programme — an ISO/IEC 27001 certificate or a SOC 2 Type II report — with EU/EEA data residency, strong encryption in transit and at rest, per-tenant isolation, and a lawful, minimised approach to the special-category data that inevitably lands in free-text student comments. Judged that way, no single tool wins outright: EvaSys leads on formal certification plus self-hosting, Qualtrics carries the broadest certification stack but is US-headquartered, and Koji runs EU-resident infrastructure on SOC 2 Type II providers with GDPR-by-design and annual third-party penetration testing. This guide compares them honestly so your information-security, data-protection and procurement teams can shortlist with confidence.
Why security is a procurement gate, not a footnote
Course evaluation data looks innocuous until you read it closely. A single free-text box can contain a student naming a specific teacher, disclosing a disability, alleging harassment, or revealing a mental-health crisis. That turns an ordinary feedback dataset into a store of GDPR Article 9 special-category data and, occasionally, a de facto safeguarding or whistleblowing channel. Under the ESG (Standards and Guidelines for Quality Assurance in the European Higher Education Area) universities are also expected to manage information reliably. So the security review is not a box-ticking exercise your IT team does at the end — it is a gate that should shape the shortlist.
For a fair, honest comparison you need to separate marketing language ("bank-grade security", "fully GDPR compliant") from verifiable, audited fact. Below are the five checks that actually discriminate between vendors, followed by a comparison table and an honest note on when each tool is the right call.
The five checks that actually matter
1. Independent certification: ISO/IEC 27001 vs SOC 2
These are the two credentials procurement should ask for by name — and they are not the same thing. ISO/IEC 27001 is an international certification of an Information Security Management System (ISMS): an accredited body audits the organisation and issues a certificate. SOC 2, developed by the AICPA, is an attestation report against the Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy); a Type II report tests that controls operated effectively over a period (typically 6–12 months), which is stronger evidence than a point-in-time Type I. Ask which the vendor holds, request the certificate or the report under NDA, and check the scope — a certificate that excludes the product you are buying is worth little.
2. Data residency and international transfer
For most European institutions, keeping personal data inside the EU/EEA is the path of least resistance for a DPIA. Where data leaves the EEA, you need a valid transfer mechanism (an adequacy decision, Standard Contractual Clauses, or the EU–US Data Privacy Framework) and a post-Schrems II transfer risk assessment. A vendor with an EU data centre and no onward transfer simplifies your paperwork dramatically.
3. Encryption and tenant isolation
Baseline expectations in 2026: TLS 1.2+ in transit with HSTS, AES-256 at rest, keys managed in a KMS, and genuine per-institution isolation so one tenant can never reach another's data. Ask whether isolation is logical (row-level) or stronger (separate schemas/credentials).
4. Special-category and free-text handling
Because open text carries Article 9 data, check how the platform handles it: data minimisation, retention limits, access controls on raw comments, redaction/pseudonymisation options, and small-cohort protections against re-identification. A tool that dumps raw comments into an unrestricted dashboard is a liability regardless of its certificates.
5. Sub-processors, penetration testing and the DPA
Finally: an up-to-date sub-processor list, evidence of regular independent penetration testing, and a signable Data Processing Agreement (Article 28) with breach-notification terms. These are the operational details that a serious security team will insist on.
Security comparison at a glance
| Platform | ISO/IEC 27001 | SOC 2 Type II | Primary data residency | Notes (as of publication) |
|---|---|---|---|---|
| EvaSys (electric paper) | Yes — certified since April 2024 | Not the primary credential | Germany / EU; self-hosted / on-premise option | Strongest data-control story via on-prem; long-established German vendor |
| Qualtrics | Yes (plus 27017/27018/27701, ISO 42001) | Yes | EU data-centre options; US-headquartered (SAP) | Broadest stack incl. FedRAMP High, HITRUST; assess transfer governance |
| Explorance Blue | Not publicly stated | Yes — hosted data centre in Canada, audited annually | Canada (EU hosting: confirm with vendor) | GDPR/FERPA/HIPAA aligned; Canada has partial EU adequacy for commercial data |
| FeedbackFruits | Yes | Via Trust Center | Netherlands / EU | EU-headquartered; also holds TX-RAMP |
| Watermark | Not publicly detailed | Not publicly detailed | US | Request trust documentation directly; strong Canvas integration |
| Koji for Education | Infrastructure on SOC 2 Type II providers* | Providers hold SOC 2 Type II* | AWS Frankfurt (eu-central-1) | EU residency, AES-256-GCM at rest, TLS+HSTS, per-institution isolation, annual third-party pen test |
*Koji hosts on Supabase/AWS infrastructure whose providers maintain SOC 2 Type II certifications; confirm Koji's current company-level certification status and roadmap in its trust centre. We have deliberately not claimed a certificate Koji may not yet hold at company level — honesty here matters more than a checkbox.
Sources for competitor claims are linked at the end; we have not invented any certification, and where a vendor's public documentation was silent we say so rather than guessing.
Vendor-by-vendor, honestly
EvaSys is the most straightforward answer for a security team that wants maximum control: it is ISO/IEC 27001-certified (since April 2024), German-hosted, GDPR-focused, and — crucially — offers a self-hosted / on-premise deployment. If your institution's policy is "student data never leaves our own infrastructure", EvaSys is hard to beat. The trade-off is that its evaluation model is a traditional standardised survey engine: robust and secure, but limited on conversational depth and automated qualitative analysis.
Qualtrics carries the deepest certification stack in this category — ISO 27001, 27017, 27018 and 27701, the newer ISO 42001 AI-management standard, SOC 2 Type II, FedRAMP High and HITRUST — and offers EU data-centre options. The nuance is corporate: as a US-headquartered platform (owned by SAP), your DPIA should document the transfer position (SCCs / EU–US Data Privacy Framework) even when data is stored in the EU. Qualtrics is a heavyweight, priced and scoped accordingly.
Explorance Blue holds a SOC 2 Type II attestation (its hosted data centre in Canada is audited annually) and aligns with GDPR, FERPA and HIPAA. Canada benefits from a partial EU adequacy decision for commercial organisations, which eases transfers, but if EU residency is a hard requirement, confirm hosting options with the vendor. Blue is a mature, widely deployed course-evaluation specialist.
FeedbackFruits is EU-headquartered (Netherlands), ISO 27001-certified and GDPR/FERPA aligned, with a public Trust Center — a clean fit for institutions that want an EU vendor with pedagogy-oriented feedback tooling.
Watermark is a capable, Canvas-integrated US platform, but at the time of writing its specific certification scope was not clearly documented publicly; ask for its trust pack before shortlisting.
Koji for Education takes a "secure-by-architecture, honest-by-default" approach: infrastructure hosted on AWS Frankfurt (eu-central-1) via providers that maintain SOC 2 Type II certifications, AES-256-GCM encryption at rest, TLS with HSTS in transit, strict per-institution isolation (separate schemas, authentication and storage), annual independent penetration testing with an executive summary available on request, and automated dependency scanning on every code change. Because free-text and conversational answers carry Article 9 risk, Koji is built around data minimisation, EU residency and a signable DPA. It shares its AI interview engine with the main Koji research platform, so the same security posture underpins both consumer and academic use.
When a competitor is the better choice
- You require data to stay on your own servers. Choose EvaSys (or another self-hostable tool). No SaaS EU-hosting story beats on-premise for institutions with that policy.
- You need the widest certification stack for a global, multi-jurisdiction rollout. Qualtrics is the safe institutional default, provided you can fund it and manage the transfer paperwork.
- You are standardising on Canvas and want tight native integration. Watermark or FeedbackFruits may reduce integration risk — just get their trust documentation first.
- You want conversational depth, automatic thematic analysis and closing-the-loop tracking on EU-resident infrastructure. That is where Koji is designed to win, without asking you to trade away security for richness.
Security should never be the reason you settle for shallow feedback — but it should absolutely be the reason you eliminate a vendor that cannot produce audited evidence.
How to run the review
- Ask every shortlisted vendor for its ISO 27001 certificate and/or SOC 2 Type II report, and check the scope.
- Confirm where data is stored and the transfer mechanism if it leaves the EEA.
- Require the DPA, sub-processor list, and most recent penetration-test summary.
- Test how the tool handles free-text Article 9 data and small cohorts.
- Fold it all into your DPIA before signing.
Frequently asked questions
Is ISO 27001 or SOC 2 "better" for course evaluation software? Neither is universally better. ISO/IEC 27001 is an international certification of a security management system; SOC 2 Type II is an attestation that specific controls operated effectively over time. Many mature vendors hold both. What matters is that an independent auditor has verified the programme and that the certificate/report covers the product you are buying.
Does GDPR require an EU-hosted course evaluation tool? No — GDPR permits transfers outside the EEA with a valid mechanism (adequacy, SCCs, or the EU–US Data Privacy Framework) and a transfer risk assessment. But EU/EEA residency is the simplest route through a DPIA, which is why many European universities prefer it.
Why does free-text feedback raise the security stakes? Open comments frequently contain special-category data (health, beliefs, sexual orientation) and sometimes safeguarding disclosures, bringing GDPR Article 9 into play. The platform must minimise, restrict access to, and protect that data — including against re-identification in small classes.
Can a newer platform like Koji be as secure as an established vendor? Security is about architecture and evidence, not age. Koji runs on EU-resident, SOC 2 Type II-certified infrastructure with strong encryption, tenant isolation and annual independent penetration testing. Ask any vendor — new or old — for the same audited evidence and judge on that.
What documents should procurement collect before signing? The security certificate/report (with scope), data-residency confirmation, the Article 28 DPA with breach terms, the sub-processor list, and the latest penetration-test summary — all folded into your DPIA.
Related reading
- GDPR-compliant course evaluation software (2026)
- NIS2 and course evaluation: the security duty GDPR doesn't cover
- Data sovereignty and Schrems II: EU hosting for course evaluation
- Koji vs Qualtrics for course evaluation
- Koji vs EvaSys
Ready to run a security-first evaluation? See how Koji handles EU data residency and GDPR — or request our penetration-test summary and DPA to start your DPIA today.