Secured Roots vendor and security summary
A concise overview for a purchasing file, board packet, insurer, or technology review.
Last updated August 6, 2026Vendor and service
- Vendor
- Secured Roots LLC
- Service
- Hosted cybersecurity-governance and ongoing-compliance workspace for local government
- Pricing model
- Flat per organization; card or government invoice/PO path; partner pricing by agreement
- Primary contact
- gabe.holcomb@securedroots.com
Core functions
Risk assessment, tailored policy drafting, board-adoption packets, training roster and completion evidence, incident timelines and notice clocks, evidence storage, annual review, audit export, team roles, and partner client oversight.
Hosting and subprocessors
Vercel hosts the application; Supabase provides PostgreSQL, authentication, and file storage; Stripe provides hosted payments and invoicing; Resend delivers transactional email; OpenAI assists with requested policy drafting. The current details and data categories are maintained at securedroots.com/subprocessors.
Security summary
- Server-validated authentication and organization-scoped PostgreSQL row-level security.
- Role-based access with a read-only auditor role and tighter incident access.
- MFA-protected, separately audited platform administration.
- Signature-verified, idempotent payment and email webhooks.
- HTTPS, restrictive browser security policy, rate limits, server-side secret handling, and no card data on Secured Roots servers.
- Operational monitoring, append-only administrative audit logs, backup verification, and restore-drill evidence.
Data ownership and continuity
Organizations can export their program records and evidence. Subscription lapse changes the workspace to read-only rather than denying access to existing records. Recovery planning treats database records and stored evidence files as separate recovery assets.
Current assurance position
Secured Roots documents its implemented controls and does not represent that it has a SOC 2 report, ISO 27001 certification, independent penetration-test report, third-party VPAT, or other external certification unless that document is supplied directly during procurement.
Available review materials
Trust center, privacy notice, subprocessor list, security-practices summary, accessibility statement, recovery runbook under controlled access, and responses to reasonable customer security questionnaires.