The CampusCISO Trust Anchor

AI-augmented, not AI-generated.

Three structural commitments that define working with us: how we use AI in client work, how we handle institutional data, and how we make the methodology transparent.

Our Position

Our work is AI-augmented, not AI-generated. AI streamlines the analytical groundwork. A senior expert reviews, interprets, and validates every output before it reaches you.

The line between “AI-augmented” and “AI-generated” has been blurred across the sector. Buyers have to guess what was actually reviewed, where their data goes, and how expert methods are applied during their engagement.

The Trust Anchor is our answer. It includes three pillars.

1

AI augmentation in client work

How we use AI, and the two-checkpoint review discipline that governs every output.

2

Client data handling

Where institutional data lives, who can touch it, and what happens when the relationship ends.

3

Methodology transparency

The frameworks behind the work, published openly so the method can be read before, during, and after an engagement.

We publish this Trust Anchor so institutions and partners can examine our approach and decide whether our methods fit their own workflows and expectations.

Read the full Trust Anchor (version 1.1) →

PILLAR 1

AI augmentation in client work.

AI workflows are infrastructure. Expert judgment is the product.

AI and computational processes handle work that doesn’t require expert judgment but does require time and consistency. This is work a junior consultant would do at a traditional firm. AI does it faster, more consistently, and at a cost that helps us fit institutional budgets. The goal isn’t to replace expertise. It’s to expand the capacity of senior experts and make advisory support accessible across the full range of institution sizes and budgets.

What we use AI for

Intake normalization

Cross-reference against benchmarking data

Pattern recognition across hundreds of assessments

Initial draft structure

Consistency checking across deliverables

Two checkpoints, every time

The founder reviews, interprets, and validates every CampusCISO deliverable before it’s delivered. That review draws on nearly 30 years of higher education technology and security experience, including CISO roles at the University of Chicago, the University of Arizona, and the University of Wisconsin-Whitewater, and client-facing leadership at SunGard Higher Education and FireEye/Mandiant.

CHECKPOINT 01

During the work

We review and approve each output received from AI analysis before adding it to the deliverable. We reject, refine, or accept every AI recommendation.

CHECKPOINT 02

Before delivery

We review the assembled deliverable as a whole before delivering it to the client. We don’t delegate or automate either checkpoint.

What you're actually buying

There are two kinds of AI assessment services: advisory practices that produce expert-validated analysis informed by AI, and software platforms that produce automated outputs for institutions or consultants to interpret. Both have legitimate uses. CampusCISO operates the first model. When you work with us, you’re paying for expert interpretation, using AI as a research tool, not access to a tool while you’re left to interpret the outputs.

This matters for partners as well. Whether you present a CampusCISO report within your own engagement or co-deliver alongside us, you’re presenting expert-reviewed analysis to your client, not raw output from a platform. The Trust Anchor is the structural commitment behind that.

PILLAR 2

Client data handling.

Protecting each institution and building a dataset the sector can rely on are the same commitment, seen from two angles.

We treat responsible handling of client data as a core business obligation, not a management policy bolted on after the fact. We start by limiting what reaches us at all. CampusCISO provides strategic advisory support, so our work runs on structured assessment surveys, policy documents, and information you choose to share. We don’t access your tools or collect sensitive configurations, log files, or vulnerability scan output.

Under our contract terms, we do not knowingly store, process, or transmit student education records (FERPA), protected health information (HIPAA), payment card data (PCI), or similar regulated data. This intentionally limited data footprint presents a smaller risk by design.

Where it lives

Your institution’s working data lives in your dedicated space in the CampusCISO Portal, hosted in the United States.

Who can touch it

The founder and your designated Portal Users only. No junior analysts, no bench staff, no incidental access.

Never used to train AI

We operate every AI platform under commercial terms that bar training on client materials, so even incidental exposure during analysis doesn't become model memory.

Deleted when work is done

Dedicated workspaces and local working files are deleted on completion. Your portal space remains available for 90 days after a relationship ends.

During an engagement

Each engagement runs in its own dedicated workspace on a commercial AI platform, separate from other clients' work and from CampusCISO's general AI usage. We name every provider that touches your data in our subprocessor disclosure and Data Processing Addendum, available on request, and we complete security questionnaires, including the HECVAT.

De-identified observations contribute to the benchmarking dataset. We publish benchmark statistics only when a cohort reaches at least 30 institutions so no individual institution can be identified from aggregate findings.

When the relationship ends

When a client relationship ends, we keep your portal space available for up to 90 days so your team has time to download everything. After that window, we remove institution-specific data from our active systems. De-identified contributions to the higher education benchmarking dataset remain as part of the aggregate, without institutional identifiers.

Have specific AI or data governance requirements?

Discuss them before the engagement, not after. Standard institutional AI governance frameworks are typically compatible with CampusCISO's existing workflow. Specific platform or provider requirements can sometimes be accommodated. Requirements that would replace the streamlined model may not fit. We'll tell you up front either way.

PILLAR 3

Methodology transparency.

We publish our frameworks so you can read the exact methods before working with us, check your deliverable against them, and use the methods whether you hire us or not.

We publish our frameworks under Creative Commons Attribution-NoDerivatives 4.0 International (CC BY-ND 4.0). You're free to read, cite, redistribute, and apply them in your own work, including commercial work. What the license reserves is the right to publish a modified version of the framework.

Framework

Status

License

CampusCISO IT Policy Framework

Published now

CC BY-ND 4.0

Cyber Heat Map® Framework

Next, with 2026 update

CC BY-ND 4.0

TTX Coaching Framework

After that, 2027 update

CC BY-ND 4.0

Once a framework is published, a prospective client can read it before the proposal conversation. A current client can compare the deliverable they received to the published methodology. A partner can explain to their own client exactly what method underlies the analysis they're delivering. None of these require CampusCISO to take any further action.

A NOTE FROM THE FOUNDER

“Higher education cybersecurity teams often spend too much time on audits, compliance checklists, and reactive governance, risk, and compliance cycles while spending too little time on the continuous improvement strategies that actually build resilience. Nearly three decades supporting hundreds of institutions convinced me this is a sector-wide problem, not an institution-by-institution one. We set out to create methodologies that use the 80/20 principle to help teams remove the busywork and focus on the handful of tasks that actually move the needle. And we’ve decided to share them rather than lock them away for paying clients, so any institution can benefit from the work that’s gone into refining these models.”

Chris Schreiber, Founder, CampusCISO

What we will and will not do

Operating commitments.

These apply to direct engagements, partner-channel engagements, and the benchmarking research that supports both.

How we use AI

WE WILL

Use AI to assist with analytical groundwork: intake normalization, benchmarking cross-reference, draft structure, and pattern recognition.

Review, interpret, and validate every AI-produced output during the work and every client deliverable before delivery. No exceptions.

WE WILL NOT

Present AI outputs as expert analysis. What we deliver is expert analysis informed by AI groundwork, not the reverse.

How we handle your data

WE WILL

Delete each engagement's dedicated workspace when the work is complete.

Name every provider that touches your data in our subprocessor disclosure.

Pool benchmark data into cohorts of at least 30 institutions before publishing any statistic.

WE WILL NOT

Use client data to train AI models. Not now, not later, not as a condition of any future pricing tier.

How we share our methodology

WE WILL

Publish the methodology behind our engagements under CC BY-ND 4.0, free to read, cite, redistribute, and apply.

Make a free community edition of every CampusCISO framework available to everyone.

WE WILL NOT

Gatekeep the methodology behind paywalls or non-commercial use restrictions.

In closing

Have questions? Bring them to us. We’re happy to discuss.

We'd rather answer them in the proposal conversation than have them surface during a procurement review or mid-project. A conversation at the proposal stage is much cheaper than a conflict mid-engagement.