K12 Insight is now officially Onflo! Learn more
Security at a Glance

Built for K‑12 trust, from the ground up

workspace_premium ISO/IEC 27001:2022 Certified verified SOC 2 Type II Audited school FERPA & COPPA Aligned health_and_safety HIPAA Aligned encrypted AES‑256 Encryption dns 99.9% Uptime SLA fingerprint SSO & MFA Support visibility 24/7 Threat Monitoring

Our Guarantee: Data Privacy and Security

Onflo provides K‑12 school districts with a secure, reliable environment engineered to protect sensitive educational records and student survey data. Built to align directly with FERPA and COPPA guidelines, Onflo safeguards district data through enterprise‑grade AES‑256 encryption, strict role‑based access controls, Single Sign‑On (SSO) integration, and full data ownership. School districts maintain complete control over their information: customer data is never sold to third parties, nor is it ever used to train AI/ML models without explicit written consent.

verified_user

Introduction

At Onflo, protecting data privacy, confidentiality, and availability is foundational to customer trust. Our security program aligns with global standards — including ISO 27001:2022, SOC 2 Type II, HIPAA, and FERPA — combining continuous 24/7 threat monitoring, mandatory employee training, and security‑by‑design principles across all development stages.

Our security practices extend beyond compliance. We continuously monitor threats around the clock, train our employees extensively, and embed security principles at every stage of system design, development, and operations.

admin_panel_settings

Security Governance

Onflo's security program is led by a dedicated security team reporting directly to executive leadership. The Onflo team maintains a Security Steering Committee that reviews policies, risk posture, and program effectiveness on a quarterly basis.

Annual risk assessments are conducted to identify, evaluate, and mitigate potential threats to our systems and customer data. Findings are tracked through remediation and reported to leadership until resolved.

workspace_premium

Certifications & Compliance

Onflo holds and maintains third‑party certifications validating our control environment:

  • ISO/IEC 27001:2022 Certified — validates adherence to international information security management systems (ISMS) standards.
  • SOC 2 Type II Audited — annual independent audits confirm the effectiveness of security, availability, and confidentiality controls over time.
  • FERPA Aligned — meets federal compliance mandates for educational records privacy and student data security.
  • HIPAA Aligned — satisfies administrative, physical, and technical safeguards for Protected Health Information (PHI).
  • COPPA Aligned — ensures compliance with the U.S. Children's Online Privacy Protection Rule.
encrypted

Data Security & Encryption

Onflo applies multi‑layered defenses to safeguard data across its lifecycle:

Encryption

  • Data in Transit: all communications are encrypted using HTTPS with TLS 1.2 and TLS 1.3 protocols.
  • Data at Rest: all customer data is encrypted using AES‑256‑bit encryption.
  • Key Management: managed via enterprise key management systems with strict access controls and full auditing.

Infrastructure Protection

Onflo infrastructure employs next‑generation firewalls, intrusion prevention systems, and web application firewall (WAF) technologies to defend against malicious traffic and common web exploits. Administrative access to systems is tightly controlled and monitored through secure, auditable remote access solutions. A centralized monitoring and alerting platform provides continuous visibility into system activity, enabling rapid detection and response to potential threats.

  • Perimeter Defense: protected by next‑generation firewalls, Intrusion Prevention Systems (IPS), and Web Application Firewalls (WAF) to prevent web exploits and malicious traffic.
  • System Visibility: administrative remote access is strictly controlled and auditable. A centralized platform provides real‑time monitoring and alerting for threat detection.
domain

Physical Security & Data Center Controls

Onflo is hosted in secure, enterprise‑grade data centers operated by leading cloud and colocation providers. These facilities maintain comprehensive physical security controls, including:

  • 24/7 on‑site security personnel and monitoring
  • Biometric access controls and multi‑zone security perimeters
  • CCTV surveillance with extended retention
  • Redundant power systems with UPS and generator backup
  • Environmental controls including fire suppression and climate management
  • SOC 2 and ISO 27001 certified facilities
fingerprint

Authentication & User Access Controls

Every user account is protected with a unique ID and password that are securely stored using industry‑standard hashing algorithms. To strengthen authentication, multi‑factor authentication (MFA) is available for all accounts. Sessions are managed with secure tokens that expire automatically, reducing the risk of unauthorized access.

Customer Security Controls

Administrators have access to the following security features to protect their accounts:

  • IP allowlisting to restrict account access to approved networks
  • Inactive session timeout policies
  • Custom password complexity requirements
  • Password expiry
  • Multi‑factor authentication

Access to data is controlled through a role‑based access model, ensuring users can only view or manage information appropriate to their responsibilities. Onflo supports Single Sign‑On (SSO) integration with major identity providers, making authentication both seamless and secure. All access is logged and monitored, and anomalies are flagged for immediate review.

privacy_tip

Privacy and Data Ownership

Onflo maintains a comprehensive Privacy Policy that provides transparency on how data is collected, processed, retained, and shared. Key commitments include:

  • Full Data Ownership: customers retain complete ownership of their data and can export it at any time in multiple formats.
  • No Third‑Party Sales: customer data is never sold to third parties.
  • AI/ML Training: customer data is not used for AI or machine learning training without explicit written consent.

Data Processing Agreement

A Data Processing Agreement (DPA) is available upon request for customers requiring documented contractual commitments under GDPR and other privacy regulations.

inventory_2

Data Retention

Onflo maintains clear data retention policies to ensure customer data is handled appropriately throughout its lifecycle:

  • Active Account Data: retained for the duration of the subscription.
  • Closed Accounts: when you close your account, your data is retained securely for a limited period to allow recovery, then permanently deleted.
  • Backups: retained for 6 months for security and compliance purposes.
  • Deletion Requests: processed within 30 days of verified request receipt.
public

Data Residency

All customer data is hosted in secure, geographically distributed data centers within the United States. These facilities are built with redundancy and resilience to ensure availability, and they undergo regular third‑party audits to confirm compliance with globally recognized standards.

For international customers, we utilize Standard Contractual Clauses (SCCs) and other approved transfer mechanisms to ensure lawful cross‑border data flows in compliance with GDPR and other applicable regulations.

policy

Regulatory Compliance

Onflo complies with major international and U.S. data protection standards:

  • FERPA: for educational institutions, Onflo complies with FERPA requirements, ensuring student records are secured and handled appropriately.
  • HIPAA: Onflo maintains HIPAA‑aligned safeguards to protect Protected Health Information (PHI).
  • COPPA: for children below 13, Onflo protects the privacy of children per COPPA rules.
dns

System Reliability

Onflo understands that service availability is critical. Our systems are designed for resilience:

Uptime SLA
99.9%
Less than 9 hrs unscheduled downtime / yr
RTO
4 hrs
Max time to restore service after an incident
RPO
15 min
Max data loss window in a disaster scenario

Disaster Recovery: capabilities are built into our infrastructure with failovers across multiple geographic sites. Annual disaster recovery drills validate our preparedness.

sync

Business Continuity

We maintain a Business Continuity Plan (BCP) that is tested annually. Critical business functions can continue during disruptions through geographic distribution, redundant systems, and documented procedures. Our BCP addresses scenarios including natural disasters, infrastructure failures, and pandemic conditions.

code

Secure Software Development (DevSecOps)

Security is integrated directly into the software development lifecycle (SDLC).

Code Security

Continuous automated and manual reviews, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and OWASP Top 10 / ASVS alignment.

Deployment Controls

All changes pass peer review and gated CI/CD controls including branch protections, signed builds, secrets scanning, and policy‑as‑code. We implement environment‑specific approvals, progressive delivery, and rollback capability. Vulnerabilities are triaged with defined SLAs, and pipelines enforce fail‑fast policies for critical findings before promotion to production.

manage_search

System Scans and Upkeep

We operate a structured vulnerability management and patching program:

  • Critical patches are tested and deployed promptly
  • All systems are reviewed regularly to ensure they remain current
  • Continuous vulnerability scanning across all environments
  • Quarterly compliance scans
  • Annual penetration tests through independent security firms
  • Targeted testing before major releases
groups

Personal Security

Our people are a vital part of our security program:

  • All employees undergo background checks
  • Mandatory annual security training covering phishing awareness, data protection practices, and secure technology use
  • Regular phishing simulations with consistent pass rates above industry benchmarks
  • Employee access based on the principle of least privilege and reviewed regularly
handshake

Vendors and Service Providers

Onflo carefully manages third‑party risks:

  • All service providers undergo security and compliance review before engagement
  • Contractual obligations require providers to protect customer data
  • Independent audit reports (SOC 2) collected annually to validate controls
  • Sub‑processors include leading cloud hosting providers, secure payment processors, and trusted communication partners

Sub‑processor List

A current list of sub‑processors is available at subprocessor-list and is updated when changes occur.

fact_check

Audit Logging and Monitoring

Onflo maintains a centralized logging and monitoring program to ensure visibility, accountability, and rapid detection of security events.

Security‑relevant logs are collected from application components, infrastructure, authentication systems, and network controls, and are centrally aggregated into a Security Information and Event Management (SIEM) platform. Logs include authentication attempts, access to customer data, administrative actions, and system events. All logs are time‑synchronized, protected from unauthorized modification, and retained in accordance with our log retention policy.

A dedicated 24×7 Security Operations Center (SOC) monitors security alerts and investigates anomalous activity. Confirmed incidents are handled in accordance with our documented Incident Response Plan, including containment, remediation, and post‑incident review.

warning

Incident Response and Breach Notification

We maintain a documented Incident Response Plan (IRP) and Breach Response Plan with clearly defined responsibilities and escalation paths. Our systems are monitored continuously to detect and contain threats quickly.

Notification Commitment

In the event of a confirmed security incident or breach involving personal data, we commit to notifying affected customers within 72 hours, consistent with applicable laws. Following an incident, we provide customers with a post‑incident report detailing the impact, root cause, and remediation measures.

Security Breach Protocol

In case of a breach, our priority is immediate containment and mitigation. We initiate investigation procedures, preserve forensic evidence, and take corrective actions to restore services securely. Affected customers are notified promptly, and full transparency is maintained throughout the process.

phone_iphone

Mobile Platform Security

On mobile platforms, we follow secure development practices, limit required permissions, and always request explicit user consent before collecting or processing sensitive data.

verified

Insurance Coverage

Onflo maintains cyber liability insurance coverage to protect against data breach costs and service disruptions.

how_to_reg

User Responsibilities

While we provide strong technical and organizational safeguards, customers also play an important role in maintaining security:

  • Enable multi‑factor authentication (MFA) for all administrator accounts
  • Assign access based on the principle of least privilege
  • Protect account credentials and never share passwords
  • Report any suspicious activity immediately to privacy@onflo.com
mail

Contact Us

For security and privacy inquiries: privacy@onflo.com

Certifications & Compliance