SchoolsResearch logo
SchoolsResearch
Technology • Consulting • Digital Transformation

Security & Trust

Security, privacy, and trust at SchoolsResearch.

SchoolsResearch is designed for organizations running complex, mission-critical operations. We treat the security, privacy, and integrity of customer data as a core product requirement—not an add‑on. This page explains our current security posture and how we protect data across our platforms.

Encryption in transit and at rest
Strict access control and least privilege
Cloud infrastructure security and resilience

Data protection and encryption

We protect customer data using modern encryption standards and layered controls. All data exchanged with SchoolsResearch is encrypted in transit using TLS, and sensitive data at rest is encrypted using strong, industry‑standard algorithms. Access to production data is restricted to authorized personnel with a documented business need.

  • • TLS encryption for data in transit between clients, services, and APIs.
  • • Encryption at rest for databases and storage containing customer data.
  • • Strict separation between production and non‑production environments.
  • • Role‑based access control for administrative operations and support.

Identity, authentication, and access control

SchoolsResearch enforces least‑privilege access and strong authentication for internal and customer‑facing systems. Access is reviewed regularly and removed promptly when roles change. We prioritize controls that reduce the risk of account compromise and unauthorized data access.

  • • Unique accounts for employees, with no generic shared logins.
  • • Strong password policies and support for multi‑factor authentication where applicable.
  • • Role‑based permissions that limit access to necessary systems and data.
  • • Formal onboarding and offboarding processes to ensure timely access changes.

Infrastructure, hosting, and resilience

SchoolsResearch runs on modern cloud infrastructure with built‑in security, availability, and resilience features. We design our architecture to minimize single points of failure and to support secure, scalable deployments for complex operational workloads.

  • • Use of reputable cloud providers with robust security and compliance programs.
  • • Network security measures including firewalls and access controls at multiple layers.
  • • Regular backups and tested restore procedures for critical data and systems.
  • • Monitoring and alerting for key infrastructure and application health indicators.

Monitoring, incident response, and vulnerability management

We monitor our environments for unusual activity, apply security updates, and follow a structured process for responding to incidents. Our goal is to detect, contain, and remediate issues quickly while communicating clearly with affected customers.

  • • Logging and monitoring of authentication events, access to sensitive systems, and key application flows.
  • • Regular patching and updates for operating systems, runtime environments, and dependencies.
  • • Documented incident response procedures that cover triage, investigation, remediation, and communication.
  • • Internal reviews of security events to improve controls and reduce recurrence.

Privacy, data handling, and subprocessors

Our Privacy Notice explains how we collect, use, store, and retain personal data. We only engage subprocessors that meet our security and privacy expectations, and we limit data sharing to what is necessary for SchoolsResearch to operate.

  • • Clear documentation of how customer and end‑user data is processed within our platforms.
  • • Due diligence for subprocessors, focusing on security, reliability, and compliance posture.
  • • Contractual commitments that require appropriate security safeguards and data protection practices.
  • • Defined retention periods and deletion processes for certain categories of data.

Responsible disclosure

We appreciate the work of security researchers and customers who help identify potential issues. If you believe you have found a vulnerability in a SchoolsResearch system, please contact us so we can investigate and remediate promptly.

When reporting, include as much detail as possible, such as the affected component, steps to reproduce, and any relevant logs or screenshots. Please avoid testing in ways that would disrupt service or access data you do not own.