{"id":18134,"date":"2025-01-15T17:44:25","date_gmt":"2025-01-15T17:44:25","guid":{"rendered":"https:\/\/www.schoolstatus.com\/?p=18134"},"modified":"2025-01-15T17:55:13","modified_gmt":"2025-01-15T17:55:13","slug":"safeguarding-student-privacy","status":"publish","type":"post","link":"https:\/\/www.schoolstatus.com\/blog\/safeguarding-student-privacy","title":{"rendered":"Safeguarding Student Privacy"},"content":{"rendered":"\n
Protecting data\u2014especially student data\u2014is of paramount importance. SchoolStatus demonstrates an unwavering commitment to data security for all of our partners through the dynamic application of robust protocols, training, and multi-layered protection systems designed specifically for safeguarding your sensitive information. By implementing rigorous security measures across corporate policies, physical security, data architecture, and software security implementation, SchoolStatus ensures that student privacy remains protected while enabling educators to leverage valuable data insights to improve student outcomes.<\/p>\n\n\n\n
SchoolStatus works with industry-leading providers to protect your data. We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, security, integrity, availability, and privacy of any Personal Data stored by SchoolStatus or its Affiliates. <\/p>\n\n\n\n
Learn more about how we store, process, and secure your information below:<\/p>\n\n\n\n
SchoolStatus is proud to participate in SOC2 Type II auditing and reporting and is certified by both 1EdTech and iKeepSafe. As indicated by our iKeepSafe certifications, SchoolStatus is compliant with applicable laws, including FERPA and COPPA. In addition to our written privacy policy, we maintain staff training requirements, data sharing restrictions, and parents\u2019 rights procedures. We comply with data retention and data deletion best practices and legal requirements.<\/p>\n\n\n\n
We maintain a vulnerability scanning program, perform regular penetration testing, and have annual security assessments. This means that we double-check our work with an external group that looks for mistakes that put your data at risk. When they identify issues, we quickly remediate them and retest to ensure resolution.<\/p>\n\n\n\n
SchoolStatus\u2019s products are hosted at data centers based in the United States, running on Amazon Web Service (AWS), Heroku, and Linode infrastructure. These data centers provide physical security around the clock, state-of-the-art fire suppression, redundant utilities, and Internet connections to ensure that our customers\u2019 data is available, safe, and secure.<\/p>\n\n\n\n
Your data is protected between you and our systems. We take multiple steps to prevent eavesdropping between you and our systems, as well as within our infrastructure. All network traffic between you and our servers is protected using state-of-the-art encryption. Sensitive data is stored encrypted in our servers as well as (encryption at rest) for an additional layer of security. SchoolStatus maintains secure key storage and rotation policies.<\/p>\n\n\n\n
Data in transit is at TLS 1.2 or higher. Data at rest uses AES-256 bit or equivalent encryption, while all client-server communication uses secure means (HTTPS, SFTP, etc.). SchoolStatus maintains documented encryption key management procedures and secure key storage and rotation policies. Upon a contract and execution of an NDA, SchoolStatus will provide additional information.<\/p>\n\n\n\n
We\u2019re consistently updating our systems to protect your data. Our virtual systems are refreshed regularly with the latest images to ensure up-to-date patching and to reduce the window of a potential compromise.<\/p>\n\n\n\n
Our policy is that only people who need access, get access. Access to systems that hold and process sensitive data is limited to necessary staff based on the principle of least privilege. We log all accesses to identify irregularities and mitigate them quickly. We maintain role-based access control policies, perform regular access reviews, and have automated account deactivation procedures. Our products support SAML-based single sign-on (SSO).<\/p>\n\n\n\n
We use scalable cloud technology to maintain a high level of uptime. If an individual data center fails, our systems keep going.<\/p>\n\n\n\n
We back up and test our backups on a regular basis. In the unlikely event of an incident, we restore our systems in the least time possible. <\/p>\n\n\n\n
You may also find additional details about our approach to data privacy, such as Employee Single Sign On, Physical Security policies, and Data Storage Security in our June 2024 article, \u201cThe Importance of Data Security When It Comes to Student Privacy<\/a>.\u201d<\/p>\n\n\n\n Our full Terms of Service is available here<\/a>, as well as in our Data Processing Addendum here<\/a>.<\/p>\n\n\n\nSchoolStatus Terms of Service<\/strong><\/h6>\n\n\n\n
SchoolStatus Privacy Policy<\/strong><\/h6>\n\n\n\n