Red Rover Logo

Trust Center

Start your security review
View & download sensitive information
ControlK

Welcome to the Red Rover Trust Center. Red Rover provides human capital management solutions for K-12 school districts, helping them manage personnel needs through a platform that handles a wide array of critical back office processes.

This Trust Center serves as a comprehensive resource, offering a clear and accessible overview of Red Rover's commitment to security and trust. Here, you will find detailed information about our security practices, data protection measures, and operational policies designed to safeguard your information.

Our commitment to trust is demonstrated through a robust security program that encompasses various aspects of our operations. We adhere to stringent information security policies, which are the foundation of our security program. These policies guide our approach to minimizing information misuse, compromise, or loss, and ensure we meet regulatory, legal, and contractual obligations.

Key aspects of our trust posture include:

  • Certifications and Audits: Red Rover undergoes independent audits, such as the SOC 2 Type 2 examination, to provide assurance regarding the design and operating effectiveness of our controls related to security. This report covers the Red Rover Platform and its ability to meet service commitments and system requirements based on trust services criteria relevant to security.
  • Data Protection: We prioritize the confidentiality and integrity of customer data. Our Data Protection Policy outlines procedures and technical controls, including storing all production data at rest on encrypted volumes and segmenting customer production data to ensure only authorized access. We host our services on Microsoft Azure, utilizing multiple regions for redundancy and disaster recovery. Our data retention policy details how customer data is managed, including deletion processes and retention periods for active and inactive accounts.
  • Operational Practices: Our operational practices are designed to maintain a secure environment. This includes strict acceptable use policies for all workforce members, requiring background checks, ongoing security awareness training, and secure offboarding processes. We also have a Responsible Disclosure Policy to facilitate the reporting and disclosure of vulnerabilities by external entities and anonymous reporting of information security policy violations by internal entities, fostering an environment of trust and partnership with the security community. Furthermore, we have a comprehensive Vendor Management Policy to ensure that third-party service providers meet our security requirements for protecting Red Rover information.

This overview provides a high-level summary of our dedication to security and trust. We encourage you to explore the other sections of our Trust Center for more in-depth information on each of these areas.

Documents

COMPLIANCESOC 2 Type 2
Built onSafeBase by Drata Logo