Canvas Lite, Instructure’s free replacement for Canvas Free-for-Teacher, requires every teacher who signs up to submit a government-issued ID and a live selfie through third-party identity vendor Veriff. Instructure’s own launch materials do not disclose that Veriff reported a data breach in November 2025 exposing unencrypted ID images, addresses and dates of birth belonging to thousands of people.
That matters because independent educators are working against a hard deadline. Anyone still on the old Free-for-Teacher tier has until October 6, 2026 to export their courses or lose access to them permanently, and the only path Instructure offers forward is Canvas Lite.
This piece lays out exactly what Veriff’s breach exposed, why Instructure’s Canvas Lite announcement leaves it out, what ID-and-selfie verification actually protects against, and a practical way to weigh the trade-off before the export window closes.
What does Canvas Lite actually require, and when does the export window close?
Canvas Lite caps each teacher at 5 active courses, 50 learners per course and 500MB of storage per course, and it requires a government ID plus a live selfie verified through Veriff before a teacher can create a single course. Free-for-Teacher accounts must export their content between September 30 and October 6, 2026, or lose it.
Canvas Lite launched on September 30, 2026 at its own domain, canvaslite.instructure.com, separate from the institutional Canvas environments that schools and universities license directly. Course analytics, attendance tracking and API access tokens are held back for the paid tier. Students invited into a Canvas Lite course do not go through Veriff’s check, only the teacher creating the course does, according to Instructure’s own Canvas Lite launch announcement.
Instructure describes Canvas Lite as hosting all data in the United States and frames the identity check as a safeguard, stating in its press release announcing Canvas Lite that the product “ensures that independent educators get a safe, reliable environment without compromise.” That framing is worth holding up against what happened to the vendor running the check.
What did Veriff’s November 2025 data breach actually expose?
Unauthorized access to Veriff’s systems began around November 18, 2025, was detected on December 10, and exposed the names, government ID images, postal addresses and dates of birth of 8,583 people who had verified their identity through Veriff on behalf of Total Wireless, a prepaid wireless brand.
Total Wireless confirmed its own systems were never touched; the exposed data originated entirely inside Veriff’s environment, per reporting on the Veriff security incident. Total Wireless notified affected customers on December 10, 2025 and offered twelve months of Experian IdentityWorks credit monitoring, and filed formal notice with the Maine Attorney General’s office on January 9, 2026.
Three class-action lawsuits followed in the Southern District of New York. Court filings allege the ID images sat “unencrypted and unredacted” on Veriff’s systems, a claim detailed in coverage of the Total Wireless and Veriff class action lawsuits. No settlement has been reached as of this writing, and the full Total Wireless data breach notification details remain the clearest public account of what Veriff’s systems exposed.
Why doesn’t Instructure’s Canvas Lite announcement mention the Veriff breach?
It doesn’t, because Instructure’s press release and launch blog post describe Veriff only as “our verification partner” and make no reference to Veriff’s breach history. The gap was first raised publicly by an independent blog, and we verified its characterization of the two events against Total Wireless’s own breach notification and the court filings rather than take it at face value.
The independent education blog Canvas Insider was blunt about the omission in its analysis of the Free-for-Teacher shutdown and Canvas Lite launch, arguing that acknowledging Veriff’s incident “would have cost nothing” and would have given teachers a fuller picture before they uploaded a photo ID to a company most of them had never heard of. That is a fair standard, and it is exactly the kind of check that a documented LMS vendor evaluation checklist is built to catch before a tool goes anywhere near a school’s signup flow, free tier or not.
Is the Veriff breach connected to Free-for-Teacher’s shutdown, or is the timing a coincidence?
The two incidents are separate companies and separate breaches, but the timing is not entirely coincidental. Instructure discontinued Free-for-Teacher permanently after attackers used a Free-for-Teacher account as an entry point into a wider Canvas security incident detected in April and May 2026, months after Veriff’s own breach had already occurred.
Instructure’s Canvas security incident update page describes unauthorized access detected on April 29, 2026, followed by a second intrusion on May 7 that exploited a vulnerability tied to a Free-for-Teacher account, letting attackers alter pages shown to some students and teachers before Instructure disabled the access. Exfiltrated data included usernames, email addresses, course names, enrollment information and messages, though Instructure says core learning data, submissions and credentials were not compromised. Instructure brought in CrowdStrike, took Canvas offline to harden it, and negotiated the return and destruction of the stolen data with the attacker.
Put together, Canvas Lite replaces a free tier that was itself the entry point for a breach, with a signup process that hands a teacher’s government ID to a vendor that had already had a breach of its own. Neither fact alone is disqualifying. Both facts sitting in the same product timeline is the part worth pausing on.
What does ID-and-selfie verification actually protect against, and what doesn’t it?
ID-and-selfie verification is built to stop bots, spam accounts and people impersonating a teacher to get free access to course tools, not to guarantee that your personal data stays safe once you submit it. Passing the check proves you are a real, matched person; it says nothing about how securely the vendor doing the matching stores your ID image afterward.
The mechanism itself is simple: Veriff’s software compares a live selfie, including basic liveness signals to rule out a photo of a photo, against the face on the submitted ID, then checks the document’s security features. That is a genuinely useful anti-fraud step for a free tool with no other gatekeeping. But the ID image and the selfie both have to be stored somewhere to make that comparison possible, and storage is precisely where Veriff’s November 2025 breach happened. Verification and data security are two different guarantees, and Canvas Lite’s marketing leans on the first to imply the second.
How long does Veriff retain a teacher’s ID image and selfie, and can it be deleted?
By Veriff’s own published retention schedule, verification data such as ID images stays in active storage for 90 days and can then sit in an archive for up to three years, and Veriff states it will not notify anyone before that data is deleted or its retention period lapses. There is no self-serve deletion request path for the individual being verified.
Veriff’s published data retention policy puts the responsibility for requesting early deletion on “the Customer” (in this case Instructure, not the teacher whose ID and face were captured). An independent educator signing up for Canvas Lite has no direct account relationship with Veriff to invoke, unlike the data-subject-access channels most identity vendors offer their enterprise clients. If you want your verification data gone sooner than three years, the request has to go through Instructure, and Instructure’s public materials do not describe a process for that.
A vendor-risk checklist: should you migrate to Canvas Lite before October 6?
There is no universal right answer, but the decision comes down to five questions any training provider already asks about a new vendor before signing on: what data it collects, how long that data is kept, who can request deletion, what its breach history looks like, and what your real alternative is if you decline. Canvas Lite’s ID step scores worse than most free tools on several of these.
| Question | Why it matters | What we found for Canvas Lite / Veriff |
|---|---|---|
| What personal data does the vendor collect? | Sets the size of your exposure if the vendor is breached. | Government ID image, live selfie, full name, and the date of birth printed on the ID. |
| How long is that data retained? | Longer retention means a longer window in which a breach can happen. | 90 days in active storage, up to 3 years archived, by Veriff’s own default retention schedule. |
| Can the individual, not just the institution, request deletion? | Independent educators have no IT or legal team to run interference for them. | No self-serve path found; only the Instructure-Veriff customer relationship can request early deletion. |
| Has the vendor had a prior breach? | Past incidents are the best available predictor of how the next one is handled. | Yes. A November 2025 breach exposed 8,583 people’s ID images, alleged in court filings to be unencrypted. |
| What happens if you decline verification? | Defines your actual alternative, not a hypothetical one. | You cannot create a Canvas Lite course; Free-for-Teacher access ends after October 6, 2026. |
Separate The Two Incidents
Keep the Canvas platform breach and the Veriff vendor breach distinct when you brief colleagues or a school board: one is Instructure’s own systems, the other is a vendor Instructure now routes teacher IDs through. Conflating them makes an otherwise solid risk write-up easy to wave off as alarmist.
What should you do if you decide not to migrate to Canvas Lite?
If the ID requirement is a dealbreaker, export your Free-for-Teacher courses before October 6, 2026 and move to a platform that does not require a government ID to open a free account, such as a self-hosted Moodle instance, Google Classroom, or a low-cost LMS with a standard email-based educator signup.
Canvas’s own export tool packages a course as a Common Cartridge or IMSCC file from the course settings menu, the same format instructors already use for end-of-term archiving, so this is a familiar step rather than a new one. Confirm your destination platform can import that format before the window closes, since not every free tool accepts a Canvas export cleanly. If you are evaluating a longer-term replacement rather than a stopgap, working through a full LMS RFP template with vendor security questions before you commit is worth the extra hour, given how little time the October 6 deadline leaves for a second attempt.
How does Canvas Lite’s ID check compare with other free LMS tiers?
Most free LMS tiers verify a signup with an email address or an existing Google or Microsoft account, not a government ID and a live selfie. Canvas Lite’s approach is unusually strict for a free, consumer-facing tier, closer to the identity checks used for financial services or age-restricted platforms than to typical edtech onboarding.
Google Classroom signs teachers in through an existing Google account and asks for nothing beyond that. A self-hosted Moodle instance has no signup verification step at all, since the administrator controls who gets an account. Free trials on commercial LMS platforms typically confirm a work email address and move on. Canvas Lite is the outlier in requiring a photo of a government ID and a biometric selfie simply to create a free account, which raises the stakes of every other question on the checklist above.
Does the Veriff breach or the ID requirement affect institutional Canvas customers?
No. Canvas Lite is a separate, teacher-signup product on its own domain, and Instructure describes it as distinct from the Canvas instance a school or university licenses and manages through its own single sign-on. Institutional Canvas customers are not required to verify identity through Veriff and are not bound by Canvas Lite’s export deadline.
That said, institutions are not exempt from vendor-risk homework of their own. The April-May 2026 Canvas platform breach did touch institutional customers directly, which is a separate incident from Veriff’s but a reminder that Instructure itself carries breach history alongside its identity vendor. Reviewing your own contract against a current LMS governance framework and confirming Instructure’s SOC 2 Type II compliance status, along with how it flows down to sub-processors like Veriff, is a reasonable next step regardless of which tier you are on.
Ask For The DPA, Not Just The Privacy Policy
Before anyone on your team uploads an ID to Canvas Lite, ask your institution’s procurement contact whether Instructure’s data processing addendum with Veriff covers individual free-tier signups or only enterprise accounts. Most free-tier terms answer this in one line that is easy to miss, and it changes who you can actually complain to.
Conclusion
Canvas Lite’s ID requirement is not going away, and neither is the October 6 export deadline. What is within your control is whether you migrate blind or migrate after actually pricing in Veriff’s breach history against your own tolerance for risk.
Run the five-question checklist above against Canvas Lite before you decide, and do the same for whatever alternative you are weighing if you choose to leave instead. A training software security guide covering how to question a vendor’s data handling is a reasonable next stop if this is the first time your organization has had to think this hard about a free tool’s fine print.
FAQ
Q1. Is Canvas Lite's ID verification data stored by Instructure or by Veriff?
The government ID image and selfie are captured and stored by Veriff, Instructure’s third-party verification partner, not by Instructure directly. Instructure receives a pass or fail result from the check rather than holding the raw ID image itself, based on how Veriff’s identity verification service is described in its own data retention documentation.
Q2. Can I request that Veriff delete my ID image and selfie after verification?
There is no publicized self-serve deletion request path for the individual who was verified. Veriff’s default retention policy keeps data active for 90 days and archived for up to three years, and early deletion requests must come from “the Customer,” meaning Instructure, not the teacher who submitted the documents.
Q3. Does the Canvas Lite ID check apply to students, or only to teachers?
Only teachers creating a Canvas Lite course go through Veriff’s identity verification with a government ID and live selfie. Students invited into a Canvas Lite course sign up normally and are not required to submit any identity documents, according to Instructure’s own launch materials.
Q4. What happens if I miss the October 6, 2026 export deadline for Free-for-Teacher?
Instructure’s export window for Free-for-Teacher accounts runs from September 30 to October 6, 2026. After that date, content on the old Free-for-Teacher tier becomes permanently unavailable, so any courses not exported and moved into Canvas Lite or another platform by then are lost.
Q5. Does the Veriff data breach affect institutional Canvas customers, not just Canvas Lite users?
No. Veriff’s November 2025 breach involved identity verification data tied to a different customer, Total Wireless, not Instructure, and Canvas Lite’s ID check does not apply to institutional Canvas accounts at all. Institutional customers were affected instead by a separate Canvas platform security incident detected in April and May 2026.
Q6. Is Canvas Lite the same product as Canvas Free-for-Teacher?
No. Canvas Lite is a new, separate free tier on its own domain that replaces Free-for-Teacher, with tighter usage limits, a paid tier for features like analytics and API access, and the added requirement of government ID and selfie verification through Veriff that Free-for-Teacher never had.
Q7. What is a reasonable alternative if I do not want to submit ID verification to use a free LMS?
Google Classroom signs teachers in through an existing Google account with no separate ID check, and a self-hosted Moodle instance has no vendor-run verification step at all since the administrator controls account creation. Both are worth exporting your Canvas courses toward before the October 6 deadline if the ID requirement is a dealbreaker.