Data & Security

What to verify before
you sign the contract.

Every SIS vendor claims to be secure. This checklist is what districts should actually verify before signing, not what vendors claim in marketing.

Talk to Alma
The short answer

Before signing, verify: SOC 2 Type II attestation on file (not just SOC 2 Type I), AES-256 encryption at rest and TLS 1.2+ in transit, mandatory MFA for administrator accounts, breach notification within 30 days written into the contract, data ownership and portability terms specified, subprocessor list current and reviewable, incident response SLA documented, and cyber insurance coverage confirmed. If any of these can't be verified in writing, negotiate them in before signing.

The verification difference

Verification is what happens after the vendor answers the RFP.

RFP responses tell you what a vendor claims. Verification is what proves those claims are true. This checklist is what your IT director and legal counsel should complete after selection but before signature.

The nine categories of pre-signing verification:

  • Certifications: Actual attestation documents, not just claims
  • Encryption: Standards for data at rest, in transit, and in backups
  • Access controls: MFA, RBAC, audit logs, session management
  • Breach protocols: Detection, notification, response, and remediation processes
  • Subprocessors: Who else has access, and how the list is maintained
  • Contract language: Specific clauses that must be present
  • Insurance: Cyber liability coverage and its limits
  • Business continuity: What happens if the vendor is acquired, sold, or fails
  • District obligations: What your district must do to maintain compliance

Common questions, answered directly.

Request the current SOC 2 Type II attestation letter and full report. SOC 2 Type I is a point-in-time snapshot; Type II covers a 6-12 month audit period and is significantly more rigorous. The report should be current within the past 12 months. Also request any ISO 27001 certification documentation if the vendor claims it.

AES-256 encryption or equivalent for data at rest. TLS 1.2 or higher for data in transit. Encrypted backups with the same standards. Ask specifically who manages encryption keys - vendor-managed keys are less secure than third-party key management services. Include these standards in the contract, not just the sales conversation.

Notification of any confirmed or reasonably suspected data breach within 30 days at the outside, ideally within 72 hours. Specific description of what information will be included in the notification. Named contact person and escalation path. Commitment to cooperate with district investigation and any regulatory reporting the district must complete. Access to logs and forensic data if requested.

Every SIS vendor uses subprocessors - cloud hosts (AWS, Azure, Google Cloud), analytics providers, support tools, backup services. Each subprocessor is a potential attack surface and each needs to be FERPA-aligned. Request a current subprocessor list, ask how the list is updated when subprocessors change, and require notification of material changes to the subprocessor list.

Ask specifically. Data ownership, contract terms, and security controls should transfer to a successor entity without renegotiation. The contract should give the district the right to terminate without penalty in the event of a change of control. Some vendors have been acquired by private equity in recent years - the terms you signed with the original company may not automatically bind the new owner.

Ask Alma directly about current ownership structure and what contractual protections apply in the event of a future acquisition. A vendor that answers this question specifically and in writing is giving you something concrete to hold them to later.

Yes. Request proof of current cyber liability insurance with limits appropriate to your district's data volume. For most K‑12 districts, coverage limits should be at least 5 million dollars. Verify that the policy covers breach notification costs, forensic investigation, legal defense, and regulatory fines - not just direct data loss.

The vendor is responsible for platform security, but the district is responsible for the security of user accounts, staff training, and configuration decisions. Ensure your district has MFA enabled for all administrator accounts, staff training on phishing and social engineering, offboarding processes that remove access immediately when staff leave, and regular reviews of who has administrator access.

Most vendors allow it with prior notice and specific rules of engagement. Ask about the process during evaluation. Some larger districts contract with penetration testing firms to test vendor platforms before signing. Whether that's worthwhile depends on your district's risk tolerance and available resources.

Ask Alma to provide the SOC 2 attestation, insurance certificate, subprocessor list, and standard contract clauses during your evaluation. Any modern vendor should be able to provide these without hesitation.

Ready to see how Alma handles this?

Get straight answers to the questions this guide raises. Schedule a walkthrough with Alma.

Schedule a Demo