Skip to main content

The Public Schools of Northborough and Southborough

Ten Schools, Three Districts, One Community of Learners

  • Logo of Canvas, featuring the word "canvas" in grey text alongside a circular graphic with dots, symbolizing interconnectedness.

Additional Resources

The Public Schools of Northborough and Southborough have adopted Canvas by Instructure as our Learning Management System for Algonquin, Trottier, and Melican.  Canvas is very user-friendly and puts all the digital tools and resources teachers use into one location. This robust LMS helps students stay organized, get faster and more valuable feedback and makes communication and collaboration a lot easier. 

 

On 9/2/2026, we received the following information on how Canvas has increased their security:

Stronger protection for administrator and educator access

  • We have strengthened multi-factor authentication (MFA) required for administrator accounts across our products.
  • Sensitive administrative actions require a second identity check when they're performed.
  • When a support engineer needs to work on an issue in your environment, they receive access scoped to your institution and to that task alone. The access is time-limited and expires when the work is done.
  • You can access systems that hold sensitive data only if both the person and the machine are authorized. Access requires a verified user signing in from a company-managed device.

 

Round-the-clock monitoring and detection

  • We engaged Reliaquest as our dedicated partner that monitors our environment around the clock, every day.
  • Logs and alerts are centralized, so unusual behavior surfaces quickly.
  • Automated detection identifies abnormal activity in our data platform and alerts our teams as it occurs.

 

Vulnerability Management

  • We're identifying vulnerabilities more effectively and addressing them faster. AI-assisted code analysis runs alongside our scanners and independent testing, and critical findings go to the front of the queue ahead of feature work.
  • We have expanded and standardized input and output sanitization practices across our applications.

 

Enhanced access and identity management

  • We’ve tightened Okta authentication policies, deployed Device Assurance and Device Trust, and laid the foundation for Okta Privileged Access Management.
  • Access to AWS, Canvas Site Admin, and Salesforce now requires the use of a company-managed device.
  • As part of a broader access review, we audited accounts across our key systems, including administrative consoles, internal tools, GitHub/Okta, and further tightened privileged access.

 

Blocking threats before they reach our applications

  • We migrated from AWS Web Application Firewall to Fastly Signal Sciences Web Application Firewall, which filters malicious traffic and provides greater configurability and broader coverage.
  • CrowdStrike Falcon EDR runs across company servers. SentinelOne continues to protect laptops.
  • We have expanded automated link scanning and blocking across our customer support channels.

 

Enhanced independent testing and validation

  • We added more independent firms that conduct penetration testing against our products and review our application security practices.
  • We increased the number of assessments made against recognized security frameworks, and we maintain the attestations your team relies on for vendor review.
  • Our bug bounty program pays independent researchers to identify and report potential security issues.
  • On 9/2/2026, we received the following information on how Canvas has increased their security:

    Stronger protection for administrator and educator access

    • We have strengthened multi-factor authentication (MFA) required for administrator accounts across our products.
    • Sensitive administrative actions require a second identity check when they're performed.
    • When a support engineer needs to work on an issue in your environment, they receive access scoped to your institution and to that task alone. The access is time-limited and expires when the work is done.
    • You can access systems that hold sensitive data only if both the person and the machine are authorized. Access requires a verified user signing in from a company-managed device.

     

    Round-the-clock monitoring and detection

    • We engaged Reliaquest as our dedicated partner that monitors our environment around the clock, every day.
    • Logs and alerts are centralized, so unusual behavior surfaces quickly.
    • Automated detection identifies abnormal activity in our data platform and alerts our teams as it occurs.

     

    Vulnerability Management

    • We're identifying vulnerabilities more effectively and addressing them faster. AI-assisted code analysis runs alongside our scanners and independent testing, and critical findings go to the front of the queue ahead of feature work.
    • We have expanded and standardized input and output sanitization practices across our applications.

     

    Enhanced access and identity management

    • We’ve tightened Okta authentication policies, deployed Device Assurance and Device Trust, and laid the foundation for Okta Privileged Access Management.
    • Access to AWS, Canvas Site Admin, and Salesforce now requires the use of a company-managed device.
    • As part of a broader access review, we audited accounts across our key systems, including administrative consoles, internal tools, GitHub/Okta, and further tightened privileged access.

     

    Blocking threats before they reach our applications

    • We migrated from AWS Web Application Firewall to Fastly Signal Sciences Web Application Firewall, which filters malicious traffic and provides greater configurability and broader coverage.
    • CrowdStrike Falcon EDR runs across company servers. SentinelOne continues to protect laptops.
    • We have expanded automated link scanning and blocking across our customer support channels.

     

    Enhanced independent testing and validation

    • We added more independent firms that conduct penetration testing against our products and review our application security practices.
    • We increased the number of assessments made against recognized security frameworks, and we maintain the attestations your team relies on for vendor review.
    • Our bug bounty program pays independent researchers to identify and report potential security issues.