Last reviewed 3 August 2026
School-specific boundaries
Each school deployment is configured with its own hostname, application credentials, database and document storage. RosterBeam does not use one shared roster database with tenant identifiers.
Authentication and roles
School applications use Auth0 organization membership and explicit Viewer, Planner or Admin roles. The application verifies the signed identity and expected school organization before permitting access. Production onboarding requires multi-factor authentication to be configured and verified in the school identity provider.
Private application infrastructure
The application runs behind an HTTPS load balancer. Database services are private, uploaded documents are stored in non-public encrypted object storage, and application secrets are supplied through AWS Secrets Manager.
Review-first operation
Scheduling inputs, warnings and proposed changes remain subject to human review. Approval is required before roster exports are made available.
Current assurance information
The Assurance page records current technical and operational practices and their evidence boundaries.
Reporting a concern
Please send security concerns to support@rosterbeam.com. Avoid including student or staff information in an initial report.