Privacy notice

The information Secured Roots needs—and what it is used for.

Secured Roots provides cybersecurity-governance software to local governments and their service partners. We do not sell personal information or use customer records for advertising.

Last updated August 6, 2026

Information we process

  • Account details such as name, work email, authentication state, and organization role.
  • Organization profile, assessment answers, imported program files, extracted and user-confirmed metadata, policies, board-adoption records, evidence, annual reviews, and compliance status.
  • Training-roster names, work emails, titles, assignments, scores, completion history, and certificates.
  • Incident records and notice timelines entered by authorized organization users.
  • Billing contacts, addresses, purchase-order references, subscription state, and invoice metadata. Payment-card data is entered directly into Stripe.
  • Operational records such as audit events, delivery status, request identifiers, rate limits, and sanitized error summaries.

Why we use it

We use this information to provide and secure the service, isolate organization workspaces, generate requested documents, send authorized notifications, maintain compliance records, process billing, assist customers, prevent misuse, and meet legal obligations. We do not run third-party advertising trackers in the application.

Sharing

Information is shared with the service providers listed on the subprocessor page only for their stated functions, and when required by law or directed by the customer. Organization administrators control which personnel are included and which members can access the workspace.

Retention and organization control

Organization records remain available for export. Imported originals are retained as immutable audit evidence with their confirmed metadata. A document submitted to the public, no-account gap check is processed as untrusted input, is not placed in the evidence vault, and is discarded after analysis; its short gap summary expires after 24 hours unless it is claimed during account setup. Inactive personnel can be excluded from new training assignments while their historical training evidence is retained for audit periods. Authorized organization and platform workflows support export, deactivation, and controlled deletion. Some records may be retained where required for security, billing, dispute, legal, or audit purposes.

Security and incident records

Incident information can be especially sensitive. Its access is restricted by role and can be configured per incident. Please do not place passwords, secret keys, or unnecessary personal information into free-text fields or email support messages.

Requests and questions

An authorized organization contact may request access, correction, export, or deletion assistance by emailing gabe.holcomb@securedroots.com. We verify authority before acting on organization records.