The information Secured Roots needs—and what it is used for.
Secured Roots provides cybersecurity-governance software to local governments and their service partners. We do not sell personal information or use customer records for advertising.
Last updated August 6, 2026Information we process
- Account details such as name, work email, authentication state, and organization role.
- Organization profile, assessment answers, policies, board-adoption records, evidence, annual reviews, and compliance status.
- Training-roster names, work emails, titles, assignments, scores, completion history, and certificates.
- Incident records and notice timelines entered by authorized organization users.
- Billing contacts, addresses, purchase-order references, subscription state, and invoice metadata. Payment-card data is entered directly into Stripe.
- Operational records such as audit events, delivery status, request identifiers, rate limits, and sanitized error summaries.
Why we use it
We use this information to provide and secure the service, isolate organization workspaces, generate requested documents, send authorized notifications, maintain compliance records, process billing, assist customers, prevent misuse, and meet legal obligations. We do not run third-party advertising trackers in the application.
Sharing
Information is shared with the service providers listed on the subprocessor page only for their stated functions, and when required by law or directed by the customer. Organization administrators control which personnel are included and which members can access the workspace.
Retention and organization control
Organization records remain available for export. Inactive personnel can be excluded from new training assignments while their historical training evidence is retained for audit periods. Authorized organization and platform workflows support export, deactivation, and controlled deletion. Some records may be retained where required for security, billing, dispute, legal, or audit purposes.
Security and incident records
Incident information can be especially sensitive. Its access is restricted by role and can be configured per incident. Please do not place passwords, secret keys, or unnecessary personal information into free-text fields or email support messages.
Requests and questions
An authorized organization contact may request access, correction, export, or deletion assistance by emailing gabe.holcomb@securedroots.com. We verify authority before acting on organization records.