eSchoolData Hosting and Support
eSchoolData (eSD) is a Renaissance product supported by the Central Susquehanna Intermediate Unit (CSIU). CSIU provides eSchoolData implementation, application support, training, and related services to its clients. The eSchoolData databases and supporting infrastructure are hosted in Amazon Web Services (AWS), with AWS hosting provided and managed by Renaissance rather than CSIU. As the owner of eSchoolData, Renaissance establishes and maintains the information security practices and controls applicable to the product and its hosted environment. The information below is provided by Renaissance and describes the security measures used to protect customer and student data.
As a leading provider of technology products to K–12 schools worldwide, information security is critically important to Renaissance’s business. Every day, millions of students, teachers, and administrators depend upon our commitment to protect their data. We take this commitment seriously.
This Information Security Overview describes the ways in which we protect your data. Renaissance may update or modify these security measures from time to time provided that such updates and modifications do not materially decrease the overall security of the relevant personal data.
If you are interested in learning more about how we handle the privacy of your data (data use, collection, disclosure, and deletion) please visit our
Privacy Hub for more information. You may also access our
Trust Center to view our SOC 2 Type 2 report and other details about our Privacy Program controls.
Technical Controls
Data Storage & Hosting
Cloud-Hosted Products:
Renaissance products are designed around the core pillars of confidentiality, integrity, and availability. Renaissance products are developed, tested, and deployed in Amazon Web Services (AWS) across several geographically and logically separated locations. AWS complies with an array of industry recognized standards including ISO 27001 and SOC 2. Please visit AWS Global Infrastructure for more information.
Renaissance Data Center:
The Renaissance Data Center (RDC) hosts a subset of ancillary systems and data processing activities supporting Renaissance Growth Platform customers. The RDC is located in Wisconsin, USA. Systems processing data run on dedicated servers, network infrastructure, and data stores.
Encryption
Data encryption is an important component of the protection of sensitive data. Renaissance’s information security team reviews and updates encryption controls based on the latest standards and guidelines published by Open Web Application Security Project (OWASP) and National Institute of Standards and Technology (NIST).
- In transit: Renaissance requires encryption over public connections, using Transport Layer Security (TLS), commonly known as SSL, using industry-standard protocols, ciphers, algorithms, and key sizes. The current standard is TLS 1.2 or better.
- At rest: Renaissance requires encryption using industry standard Federal Information Processing Standards (FIPS) approved encryption algorithms. The current standard is AES 256 or better.
Credentials and Access Controls
In-Product Controls: Each school or district has a universally unique identifier within Renaissance products and all data stored and processed in Renaissance applications is associated with the customer identifier. Each user is assigned unique login credentials, which must be authenticated before the user can access the school or district site. Users are assigned to distinct roles, such as student, teacher, or administrator, which limits what information users can access or edit. Our products integrate with several Student Information Systems for automated rostering and Single-Sign-On (SSO) providers for tighter identity and authentication controls.
Renaissance Corporate Controls: Renaissance maintains a role-based access control program built around the principles of least privilege, least functionality, and the implementation of need-to-know. Renaissance employee and contractor accounts are provisioned with a role that provides access based on their job requirements. All accounts require multi-factor authentication and have strong password requirements. Access to Renaissance corporate systems and data requires the use of Renaissance managed devices.
Application Security
Renaissance takes several measures to build products and solutions that are designed to preserve the confidentiality, integrity, and availability of the data entrusted to us. We physically and logically segment our environments to control the movement of data. We establish and enforce baseline configuration and system hardening standards that address secure practices for development, acquisition, configuration, patching, and maintenance. We implement well-documented change management processes that require the use of Infrastructure as Code and automated product deployment pipelines, where changes are first developed in a development environment, promoted to a testing or staging environment for quality and security checks, and eventually promoted to production environments for use by customers.
Threat and Vulnerability Management
The Renaissance Threat and Vulnerability Management Program integrates application security testing, vulnerability scanning, and threat modeling with an automated remediation workflow. We implement vulnerability scanners which actively and passively scan assets in both the corporate and product environments. We have also deployed a cloud security platform to scan for vulnerabilities and assess threats in our cloud platform and infrastructure. Our processes assess product configuration for compliance with industry standards and best practices.
We also implement Dynamic Application Security Testing (DAST), utilizing both unauthenticated and authenticated testing schemes based on OWASP standards to discover run-time vulnerabilities in our applications. The DAST process, which is an integral piece of our software development cycle, tests our software for exploitable weaknesses and vulnerabilities before it is deployed to the production environment. The DAST process also plugs into the Threat and Vulnerability Management remediation workflow.
Penetration Testing
Renaissance engages with a third party to conduct penetration tests on each application and its underlying infrastructure annually. Penetration test results are used to validate the security controls we’ve implemented. All penetration test findings are assessed and remediated through our Threat and Vulnerability Management processes. Fixes are deployed through our product development pipelines.
Endpoint Security
Endpoint detection and response (EDR, also referred to as anti-virus) tooling is installed on Renaissance systems. In the product environments, much of Renaissance’s product infrastructure is built on AWS managed services and serverless technology, which provides additional malware detection capability. EDR and our cloud service provider provided malware and intrusion detection systems are integrated into a Managed Detection and Response (MDR) solution for analysis and automated response activities.
Network and Infrastructure Security
Renaissance implements layered network and infrastructure security controls to protect customers’ data. We deploy next-generation firewalls, segmented network designs, and segmented cloud infrastructure account designs to control the flow of traffic. We also utilize intrusion detection and prevention systems. Employee and contractor access to Renaissance systems requires the use of managed hardware that implements conditional access controls. Employees and contractors remotely access Renaissance systems using a VPN and Secure Access Service Edge (SASE) solution that utilizes identity-based access and next-generation firewalling.
Logging, Monitoring, and Alerting
Renaissance collects and analyzes an array of log data including system logs, system security configuration logs, access control logs, system process analysis, network traffic analysis, and network bandwidth consumption. Log and activity data is centralized into our MDR, which then correlates and analyzes event data. When anomalous activity or threats are detected by the MDR, automated alerts are sent to our team of responders. We monitor our MDR and our operational systems 24 hours a day, 7 days a week, and any suspicious or anomalous activity is promptly investigated.
Business Continuity & Disaster Recovery
Renaissance maintains and tests Business Continuity and Disaster Recovery plans to protect your data. Backups are taken at least every 24 hours and are protected using segmentation and vaulting technologies. Additionally, services are deployed into scalable groups and are load
balanced across compute and storage services running in geographically diverse availability zones to provide high availability and reduce the risk of service outage. Renaissance also manages much of its cloud infrastructure as code, which facilitates quick recovery or rollback in case of outage, and better transparency into changes in infrastructure over time.
Physical Controls
Cloud-Hosted Products: Renaissance cloud products are hosted on AWS, a durable technology platform that aligns to an array of industry-recognized security and availability standards. For more information about AWS, please visit
https://aws.amazon.com/about-aws/global-infrastructure/.
Renaissance Data Center: The Renaissance Data Center, which hosts a subset of ancillary systems and data processing activities supporting Renaissance Growth Platform customers, is located at Renaissance’s corporate headquarters in Wisconsin. Entry into Renaissance properties is controlled via employee magnetic key entry. Only Cloud Operations and Network Services personnel who are responsible for management of data center infrastructure are allowed unescorted access to the Renaissance data center. Physical access to the data center is controlled through a proximity card system and a motion-based detection system. All visitors to the data center, as well as their internal employee escorts, must sign an access log. We also monitor log files, review access logs, track system usage, and monitor network bandwidth consumption.
The environmental conditions within the data center are monitored and maintained at a consistent temperature and humidity range. Electrical power is filtered and controlled by dual uninterruptible power systems. Backup power is provided by an automatic-start generator. Waterless fire protection and early-warning water systems are also installed and monitored.
Administrative Controls
Governance and Risk Management
Renaissance maintains a comprehensive information security program built around the NIST Cybersecurity Framework (CSF). We implement NIST Special Publication 800-53 controls associated with each of the CSF functions. We also assess our Information Security and Privacy programs against the Center for Internet Security (CIS) Critical Security Controls and annually complete a SOC 2 Type 2 examination of controls. See Compliance below for more information about our SOC 2 Type 2 report.
Cybersecurity Risk Committee: The Renaissance Cybersecurity Risk Committee is charged with identifying, tracking, and managing cybersecurity risks. The committee communicates with executive leadership and the board of directors to keep them informed of key cyber and business level risks facing Renaissance. The Committee is also charged with evaluating Renaissance information security and privacy policies, procedures, and operations along with Renaissance’s products, product development, and product deployment systems to identify
potential areas of vulnerability and risk. These evaluations are used to develop policy, practices, and processes aimed at mitigating or removing vulnerabilities and risks. The Committee assesses all observed and perceived risks to develop policy, practices, and priorities to manage risk to an acceptable level.
Incident Response and Incident Reporting
Renaissance maintains an Incident Response Plan and has a standing Incident Response Team. Our incident response plan establishes roles and responsibilities, incident declaration, incident assessment, as well as response phases to include identification, containment, eradication, recovery, reporting, and lessons learned.
The Incident Response Team monitors our detection and response systems 24 hours a day, 7 days a week. Suspicious and anomalous activity is promptly investigated. The Incident Response Team also performs Tabletop Exercises at least twice annually. Tabletop Exercise results are used to further refine the Incident Response Plan, policy, and risk management practices.
We encourage district representatives with any questions or concerns regarding privacy, security, or related issues to contact our Chief Information Security Officer via e-mail at
infosecurity@renaissance.com.
Security Education, Training & Awareness
Renaissance employees and contractors are required to complete Privacy and Information Security training on an annual basis. Renaissance regularly communicates information about the current cybersecurity threat landscape to all employees and contractors. Additionally, Renaissance conducts an anti-phishing and social engineering awareness and training program. Supplemental training events, such as International Privacy Week and Cybersecurity Awareness Month, are also major elements of the training program.
Compliance
Audits: Renaissance’s enterprise Information Security & Compliance Program completes the SOC 2 Type 2 examination of controls on an annual basis. The examination is formally known as a Type 2 Independent Service Auditor’s Report on Controls Relevant to Security and Privacy, and reports on Renaissance’s systems and the suitability of the design, implementation, and reporting of our information security and privacy controls. Our SOC 2 Type 2 is scoped to specific products and services. For more information on our audit process, including which products are included in our SOC 2 Type 2 report, please contact
infosecurity@renaissance.com or visit our
Trust Center.
Employees: All Renaissance employees and contractors have a duty to safeguard the data entrusted to them. Additionally, employees and contractors are required to read, sign, and agree to abide by Renaissance’s Information Security and Information Technology policies. Background checks are conducted as part of the onboarding process for employees and contractors to the extent permitted by law.
Vendors/Sub-processors that Support Our Products: Renaissance maintains a vendor compliance program. Vendors’ security and privacy practices are reviewed and analyzed. Additionally, Renaissance enters into written contracts with each vendor/sub-processor containing terms that offer similar levels of data protection obligations and protection for customer personally identifiable information as identified in our Data Protection Addendum with customers. Our vendors/sub-processors are documented here: Sub-Processors.
The Renaissance Shared Responsibility Model
Effective security and compliance are a shared responsibility between Renaissance and our customers. As a SaaS provider, Renaissance is committed to providing a secure platform to serve our customers’ needs. As part of our service, we help relieve the burden of planning, deploying, and maintaining our software and its supporting infrastructure. Renaissance customers assume the responsibility to securely configure and use our products. For Renaissance customers to rely on the information processed by our products, customers are expected to evaluate and implement appropriate security controls in their IT systems. Below is an overview of security and compliance responsibilities. This is not an all-inclusive list:
Area | Renaissance | Customer | Cloud Provider (AWS) |
Platform Security | Performs
secure development, patching, hardening, and maintenance of the cloud infrastructure
and compute resources. Provides secure network access and data transfer services. Vulnerability management, security testing, security
audits, and risk management. | Secure
any systems required for integrated rostering, Single-Sign-On, and/or reporting. | Ensures
physical data center security, hardware maintenance,
managed service maintenance, and firmware updates. |
Network Security | Provides
secure networking between Renaissance environments and cloud infrastructure
with segmented design and least
functionality principles. | Follow best practices for securing networks. Detect
and respond to security events and alerts for systems under their control. | Physically and logically
secure the networking layer. |
Identity
and Access Management | Secure corporate identities and access control technologies. Provide baseline identity services to customers that
allow for secure access and access controls. | Secure identities and credentials within their control. Review access controls within Renaissance products. Remove users who no longer require access. Remove data integration recipients who are no longer
authorized to receive data. | Provides Identity, Access, and Authentication services
to support the secure use of the platform and available services. |
Asking Questions and Reporting Vulnerabilities
Standard Deletion and Retention Schedule
Except as otherwise agreed between Customer and Renaissance, Renaissance will delete PII according to the below schedule after termination or expiration of an agreement between the parties. As indicated in the below schedule, Renaissance may retain PII for a period of time after termination or expiration of the Subscription Period for the purpose of allowing Customer to obtain a copy of their PII, meet applicable legal obligation(s), permit the orderly deletion of the data after termination or expiration, or as otherwise set forth in the Agreement between Renaissance and the Customer, including the applicable Data Protection Agreement.
In the event of any conflict between this schedule and the Customer Agreement and/or Data Protection Agreement, the terms of the Customer Agreement and/or Data Protection Agreement shall apply over the schedule.
Product Type | Availability for Customer Download | PII Deletion | Backup Medium PII Deletion | Pending Renewals or Extensions |
State, District, School Product Licenses (excluding
Premium* Hybrid Classroom Licenses, Renaissance
Fundamentals, and Student Information Systems) | Customer may retrieve a copy of their PII using the self-service feature via their account (to the extent
such functionality exists in the Products) for a period of thirty (30) days
following the termination or expiration of the
Subscription Period, after which the PII may no longer be available to
Customer. In the event a self-service functionality does not exist within the product, the customer
may contact Customer Support for assistance during that thirty (30) day period. | PII will be deleted from the production
databases within ninety (90) days after termination or expiration of the
Subscription Period. | PII will be deleted from the
backup databases within one hundred and eighty (180) days after termination or expiration of the Subscription Period. | The time periods for deletion of PII
set forth in this schedule will be extended
by thirty (30) days, and an additional ninety (90) days for PII in backup
medium, if the customer has not provided Renaissance with a final
determination not to enter into a renewal or extension of the agreement or sign a new agreement. |
Student Information System
(“SIS”) Licenses** | Upon expiration or termination of the
subscription period, the customer will receive up to four (4) read-only
accounts that they may use to export PII for a period of one hundred and
eighty (180) days after the termination or expiration of the subscription
period, after which the PII may no longer be available to Customer. | PII will be deleted from the production
databases within three hundred and sixty-five (365) days after termination or
expiration of the Subscription Period. | PII will be deleted from all backup
databases within four hundred and fifty-five (455) days after the termination or expiration
of the subscription period. | The time periods for deletion of PII
set forth in this schedule will be extended by thirty (30) days, and an
additional ninety (90) days for PII in backup medium, if the customer has not
provided Renaissance with a final determination not to enter into a renewal
or extension of the agreement or sign a new agreement. |
*Excludes the Premium Hybrid Classroom Licenses and Renaissance Fundamentals; if applicable, refer to your applicable Classroom License or the Data Protection Agreement for the relevant schedule.
**Due to the breadth and significance of PII which a Customer may maintain in a SIS, and the length of time it may take to conduct an orderly transfer of the PII, Renaissance retains PII in SIS products for a longer period to allow Customer sufficient time for such transfer.