Executive Summary
AI-generated analysis for Instructure
Instructure, Inc. (instructure.com) is an established educational technology company offering learning management solutions including Canvas, and has been assigned a Tier 3 (Moderate Risk) rating with high confidence (95%). The vendor presents a number of meaningful positive signals that establish baseline legitimacy and operational stability. On the positive side, Instructure demonstrates several strengths:
Key Findings
- The domain has been registered since 1998 and archived since 1999, reflecting over 26 years of established web presence.
- Sanctions screening across OFAC, EU, and UN watchlists returned zero matches, and no adverse media signals were identified in either recent or historical searches.
- Infrastructure exposure is minimal — only ports 80 and 443 are exposed, the vendor sits behind Cloudflare CDN, and no known CVEs are associated with the IP. This represents a well-controlled footprint significantly below the SaaS industry average of 8–12 open ports.
- Malware detection service and URLhaus confirm the domain is clean, with no malware, phishing, or blacklist entries detected.
- SOC 2 compliance is claimed on the vendor's published trust page (trust.instructure.com), and a possible HITRUST directory match was identified, though both require further verification (see findings below). Several concerns and gaps require attention before this vendor is approved for medium data access environments. The TLS certificate for the primary domain expires in 22 days, creating a near-term availability and trust risk. The public-facing website received a failing grade (F, 20/100) from Mozilla HTTP Observatory, indicating missing security headers including Content-Security-Policy and X-Frame-Options. The subprocessor page (trust.instructure.com/subprocessors) was found but contains placeholder content with no extractable entries — a material gap for GDPR Article 28 compliance. Additionally, the vendor's AI data usage policy, while discoverable, does not clearly state training or retention commitments for customer data. The LEI registration is lapsed as of the last update (July 2021), which warrants clarification. Overall, Instructure is a recognizable, long-established edtech vendor with clean threat intelligence signals and a minimal infrastructure footprint, but specific operational and transparency gaps — particularly the imminent certificate expiry, absent subprocessor list, and unclear AI data handling commitments — prevent an unconditional approval at medium data access level. A conditional rating is appropriate pending resolution of these items.
Independence Statement
All evidence underpinning this report was sourced independently from external data repositories, public registries, and threat intelligence platforms without vendor participation or input.