Procurement brief

Secured Roots vendor and security summary

A concise overview for a purchasing file, board packet, insurer, or technology review.

Last updated August 6, 2026
Request supporting documents

Vendor and service

Vendor
Secured Roots LLC
Service
Hosted cybersecurity-governance and ongoing-compliance workspace for local government
Pricing model
Flat per organization; card or government invoice/PO path; partner pricing by agreement
Primary contact
gabe.holcomb@securedroots.com

Core functions

Risk assessment, tailored policy drafting, board-adoption packets, training roster and completion evidence, incident timelines and notice clocks, evidence storage, annual review, audit export, team roles, and partner client oversight.

Hosting and subprocessors

Vercel hosts the application; Supabase provides PostgreSQL, authentication, and file storage; Stripe provides hosted payments and invoicing; Resend delivers transactional email; OpenAI assists with requested policy drafting. The current details and data categories are maintained at securedroots.com/subprocessors.

Security summary

  • Server-validated authentication and organization-scoped PostgreSQL row-level security.
  • Role-based access with a read-only auditor role and tighter incident access.
  • MFA-protected, separately audited platform administration.
  • Signature-verified, idempotent payment and email webhooks.
  • HTTPS, restrictive browser security policy, rate limits, server-side secret handling, and no card data on Secured Roots servers.
  • Operational monitoring, append-only administrative audit logs, backup verification, and restore-drill evidence.

Data ownership and continuity

Organizations can export their program records and evidence. Subscription lapse changes the workspace to read-only rather than denying access to existing records. Recovery planning treats database records and stored evidence files as separate recovery assets.

Current assurance position

Secured Roots documents its implemented controls and does not represent that it has a SOC 2 report, ISO 27001 certification, independent penetration-test report, third-party VPAT, or other external certification unless that document is supplied directly during procurement.

Available review materials

Trust center, privacy notice, subprocessor list, security-practices summary, accessibility statement, recovery runbook under controlled access, and responses to reasonable customer security questionnaires.