Current product practices

Assurance

Evidence-backed information to support a school’s security, privacy and service due-diligence review.

Scope of this page. This information describes current implementation practices reviewed on 3 August 2026. It does not certify compliance, define a service level, or replace an executed agreement and Statement of Work.

School-specific architecture and access

Information protection

Software delivery and integrity

Continuity and recovery controls

The production database is deletion-protected and configured for 14 days of automated backups. Uploaded documents are versioned, infrastructure is defined in source, and key storage resources are configured to be retained. Application health checks allow failed tasks to be replaced, while deployment rollback protects the last stable task definition. These controls support recovery but do not state a recovery-time or recovery-point objective and do not replace an agreed disaster-recovery plan and test schedule.

Review and approval controls

Scheduling inputs, exceptions, warnings and generated revisions remain visible to authorised school staff. Proposed exceptions must be accepted or rejected before solving, validation errors prevent approval, and the latest roster revision must be approved before an Excel export becomes available. Administrative deletion and reset controls are restricted to the Admin role.

Contract boundary

Specifications, licence rights, service levels, service reporting, service credits, maintenance notices, support response, incident reporting, migration, disaster recovery and disengagement arrangements must be defined in the executed agreement and Statement of Work where applicable. Nothing on this page creates those terms.

Requesting supporting evidence

Security, privacy and procurement questions can be sent to support@rosterbeam.com. Please do not include student or staff information in an initial request.