Data & Security

What every SIS vendor
should have to answer.

Recent breaches have made SIS vendor security a board-level conversation. Here are the questions that separate rigorous vendors from marketing claims.

Talk to Alma
The short answer

Ask about certifications (SOC 2 Type II, ISO 27001), encryption (at rest and in transit), access controls (role-based, MFA, audit logs), breach history and response protocols, subcontractor management, and data ownership and portability. If a vendor cannot answer any of these in specific detail, that is the answer.

Why this matters now

Security is no longer a checkbox item.

K‑12 has become one of the most targeted industries for cyberattacks. Student data has long-term value on illicit markets because the identity remains valid for years. A single SIS breach can compromise millions of records because a single platform typically holds the entire district's student data.

Categories of security questions every SIS RFP should include:

  • Certifications and audits: What third-party attestations does the vendor hold?
  • Encryption and data handling: How is data protected at rest, in transit, and in backups?
  • Access controls: How is access granted, monitored, and revoked?
  • Incident response: What happens when there is a breach or suspected incident?
  • Subcontractor management: Who else has access to district data through the vendor?
  • Data ownership and portability: Who owns the data, and how easily can it be exported?
  • Compliance: FERPA, COPPA, state-specific privacy laws, and vendor obligations

Common questions, answered directly.

At minimum: SOC 2 Type II attestation, which is an independent audit of the vendor's security controls. ISO 27001 certification is a strong additional signal, particularly for larger vendors. Vendors serving European or Canadian districts should also demonstrate GDPR or PIPEDA compliance. Ask for actual attestation letters, not just marketing claims.

Data should be encrypted at rest (in storage) using AES-256 or equivalent. Data should be encrypted in transit using TLS 1.2 or higher. Backups should be encrypted with the same or stronger standards. Ask specifically whether encryption keys are managed by the vendor or a third-party key management service - the second is stronger.

Role-based access control (RBAC) so users only see the data their job requires. Multi-factor authentication (MFA) for all administrator accounts and ideally all staff. Single sign-on (SSO) integration with district identity providers. Comprehensive audit logs showing who accessed what data and when. Automatic session timeouts. The ability to revoke access instantly when a staff member leaves.

Alma supports all of the above natively, including granular role-based permissions down to individual data fields - ask for a walkthrough of the permission structure during your evaluation rather than taking a feature list at face value.

How the vendor detects security incidents. How quickly they will notify the district of a confirmed or suspected breach (state laws often require notification within 30 to 60 days). What their incident response process looks like from detection through resolution. Whether they have insurance coverage. Whether they've had incidents in the past and what they learned.

Vendor honesty about past incidents is more important than the absence of incidents. Every major software company has had security events. What matters is how the vendor handled it: transparency with customers, root cause analysis, changes made afterward, and response timelines. A vendor claiming zero incidents in a decade should be viewed with skepticism.

Ask about subcontractors and subprocessors. Cloud hosting providers (AWS, Azure, Google Cloud). Analytics services. Support tools. Backup services. Each subcontractor is a potential attack surface. Vendors should be able to provide a current subprocessor list and notify districts when it changes.

Your district owns the data. Any contract that says otherwise should be rejected. The SIS vendor is a data processor acting on the district's behalf. Additionally, ask about data portability: can you export all your data in standard formats at any time, and what happens to your data if you terminate the contract? The answer should be that all data is exported to you and then deleted from vendor systems within a defined window.

California (SOPIPA, CCPA), Illinois (SOPPA), New York (Education Law 2-d), Connecticut, and many others have K‑12 specific data privacy laws that impose obligations on SIS vendors. Federal FERPA and COPPA apply everywhere. Ask specifically which laws apply to your district and how the vendor demonstrates compliance.

Ask Alma directly about SOC 2 status, encryption standards, incident response, and data ownership during your evaluation. Any vendor should be able to answer these questions with specific detail.

Ready to see how Alma stacks up?

Get straight answers to the questions this guide raises. Schedule a walkthrough with Alma.

Schedule a Demo