Security

Last updated October 8, 2026

How iSoar protects accounts and district data, and how to report a security concern.

This page describes how iSoar Network protects iSoar accounts and the data districts trust us with. It covers the measures that are in place today.

1. Where iSoar runs

The iSoar service and its data are hosted on Amazon Web Services (AWS) in the United States, in the US West (Oregon) region. The iSoar web app is delivered by Vercel. The database runs on a private network and cannot be reached from the internet.

2. Encryption

  • All traffic to iSoar uses HTTPS (TLS). Uploaded files can only be read over encrypted connections.
  • The database, its backups, file storage and server disks are encrypted at rest.
  • Uploaded files are private. They are never publicly listed, and each download uses a short-lived signed link.

3. Accounts and access

  • Passwords are stored only as salted bcrypt hashes. We cannot see anyone's password.
  • Sign-in sessions use short-lived access tokens that are renewed with a refresh token.
  • Districts can let staff and families sign in with Google instead of a password.
  • Every account sees only what its role allows, and permissions are enforced by the server, not only hidden in the app.
  • Sign-in and other sensitive requests are rate limited to slow down password guessing.
  • Administrators can review an audit log of changes to records.

4. How we run the service

  • Application keys and passwords are stored in AWS Secrets Manager, not in code.
  • The production database has automated daily backups, kept for 7 days, and is protected against accidental deletion.
  • Code changes are tested before release, and releases are deployed automatically from our source repository.
  • Only iSoar Network staff who need production access to operate the service have it.
  • Security headers and input validation are applied to every API request.

5. Incidents

If we confirm unauthorized access to customer data, we notify affected districts within 72 hours of confirming it, as described on our Student data privacy page.

6. Report a security concern

If you believe you have found a security problem in iSoar, email theisoarnetwork@gmail.com with the subject "Security report". Please include the steps to reproduce it and do not access, change or delete other people's data while testing. We will acknowledge your report and keep you informed while we fix it.

Questions about this page?

Write to iSoar Network at theisoarnetwork@gmail.com.

Email us