Security at Tassel
Effective date: November 10, 2026 · Last updated: October 9, 2026
Schools trust Tassel with their graduates' information and their biggest day of the year. Here's how we protect both.
Infrastructure
Our platform runs on Microsoft Azure in the United States, with redundancy across multiple availability zones and automated backups stored in multiple regions.
Data protection
Data is encrypted in transit and at rest. Student information is automatically deleted two years after it is provided, or earlier at the institution's request at the end of its engagement.
Access control
Multi-factor authentication is required for all internal system access. Access follows the principle of least privilege and is removed promptly when it is no longer needed. Company devices are encrypted and centrally managed.
Secure development
Every code change is peer reviewed and tested before release. We run regular automated security scanning of our code, dependencies, and infrastructure.
Resilience and incident response
We maintain documented incident response, disaster recovery, and business continuity plans and test them regularly. If we confirm a security incident affecting student information, we notify the affected institution promptly.
Certifications and frameworks
- TX-RAMP Level 1 certified (Certificate TX1071990, valid through November 15, 2027).
- Our security program is aligned with the NIST Cybersecurity Framework.
- FERPA: we act as a school official and use student records only to provide our services.
Accessibility
We design and test to WCAG 2.1 AA and maintain a VPAT.
Documentation for customers
Our HECVAT, VPAT, and security policies are available to customers and prospective customers on request. Email [email protected].
Report a security concern
If you believe you've found a security issue, email [email protected].