Comparison Overview

Association of Science and Technology Centers

VS

Ann Arbor Hands-On Museum

Association of Science and Technology Centers

2000 Florida Ave NW, Suite 300, Washington, DC, US, 20009
Last Update: 2026-01-22
Between 750 and 799

The Association of Science and Technology Centers (ASTC) is a network of nearly 700 science and technology centers and museums, and allied organizations, engaging more than 110 million people annually across North America and in almost 50 countries. With its members and partners, ASTC works towards a vision of increased understanding of—and engagement with—science and technology among all people. Founded in 1973, ASTC provides a collective voice, professional support, and programming opportunities for science centers, museums, and related institutions. Through strategic alliances and global partnerships, ASTC's goal is to increase awareness of the valuable contributions its members make to their communities and the field of informal STEM learning and public engagement in science.

NAICS: 712
NAICS Definition: Museums, Historical Sites, and Similar Institutions
Employees: 43
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Ann Arbor Hands-On Museum

220 E. Ann Street, Ann Arbor, undefined, 48104, US
Last Update: 2026-01-23
Between 750 and 799

The Ann Arbor Hands-On Museum (AAHOM) opened in 1982 in an historic firehouse in downtown Ann Arbor and quickly became the cornerstone of informal science education in the community. This was achieved by working with scientists, artists, designers, engineers, and innovators who transferred their extraordinary talents and knowledge into the creation of simple, effective science exhibits that can be understood by children, their families, and audiences of all ages. Following several expansions, AAHOM now occupies 40,000 square feet, with 20,000 devoted to exhibit space for 250+ interactive exhibits designed to promote science discovery and literacy. Over 6 million visitors have visited AAHOM since it first opened its doors, making it one of the most popular science centers in the State of Michigan. The mission of the AAHOM is to create moments of discovery that inspire curiosity, exploration, and respect for STEM, and the natural world . Our vision is a world where curiosity today leads to more purposeful lives tomorrow. Thanks to a steadfast belief in the power of STEaM when placed in the hands of pre-K through 8th Graders, we enjoy one of the highest annual attendance rates at a science center in Michigan: reaching nearly 400,000 each year. AAHOM education programs align with State of Michigan Grade Level Content Expectations (GLCE) and Next Generation Science Standards (NGSS). Our exhibits have been displayed in libraries, community centers and shopping malls throughout the state. AAHOM’s regional and national reputation was built on its visionary planning and implementation of interactive STEaM-based exhibits; groundbreaking educational programs delivered to 47 counties throughout the state, 47 states across the country, and numerous countries around the world; and an exceptional ability to establish and maintain strong collaborative bonds with public and private organizations from a variety of disciplines.

NAICS: 712
NAICS Definition:
Employees: 36
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/sciencecenters.jpeg
Association of Science and Technology Centers
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/ann-arbor-hands-on-museum.jpeg
Ann Arbor Hands-On Museum
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Association of Science and Technology Centers
100%
Compliance Rate
0/4 Standards Verified
Ann Arbor Hands-On Museum
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Museums, Historical Sites, and Zoos Industry Average (This Year)

No incidents recorded for Association of Science and Technology Centers in 2026.

Incidents vs Museums, Historical Sites, and Zoos Industry Average (This Year)

No incidents recorded for Ann Arbor Hands-On Museum in 2026.

Incident History — Association of Science and Technology Centers (X = Date, Y = Severity)

Association of Science and Technology Centers cyber incidents detection timeline including parent company and subsidiaries

Incident History — Ann Arbor Hands-On Museum (X = Date, Y = Severity)

Ann Arbor Hands-On Museum cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/sciencecenters.jpeg
Association of Science and Technology Centers
Incidents

No Incident

https://images.rankiteo.com/companyimages/ann-arbor-hands-on-museum.jpeg
Ann Arbor Hands-On Museum
Incidents

No Incident

FAQ

Ann Arbor Hands-On Museum company demonstrates a stronger AI Cybersecurity Score compared to Association of Science and Technology Centers company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Ann Arbor Hands-On Museum company has disclosed a higher number of cyber incidents compared to Association of Science and Technology Centers company.

In the current year, Ann Arbor Hands-On Museum company and Association of Science and Technology Centers company have not reported any cyber incidents.

Neither Ann Arbor Hands-On Museum company nor Association of Science and Technology Centers company has reported experiencing a ransomware attack publicly.

Neither Ann Arbor Hands-On Museum company nor Association of Science and Technology Centers company has reported experiencing a data breach publicly.

Neither Ann Arbor Hands-On Museum company nor Association of Science and Technology Centers company has reported experiencing targeted cyberattacks publicly.

Neither Association of Science and Technology Centers company nor Ann Arbor Hands-On Museum company has reported experiencing or disclosing vulnerabilities publicly.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds any compliance certifications.

Neither company holds any compliance certifications.

Neither Association of Science and Technology Centers company nor Ann Arbor Hands-On Museum company has publicly disclosed detailed information about the number of their subsidiaries.

Association of Science and Technology Centers company employs more people globally than Ann Arbor Hands-On Museum company, reflecting its scale as a Museums, Historical Sites, and Zoos.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds SOC 2 Type 1 certification.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds SOC 2 Type 2 certification.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds ISO 27001 certification.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds PCI DSS certification.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds HIPAA certification.

Neither Association of Science and Technology Centers nor Ann Arbor Hands-On Museum holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.

Description

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Risk Information
cvss3
Base: 6.0
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
cvss4
Base: 6.0
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.