Security & Trust
How we protect your data and keep the Platform secure
How we protect your data
This page sets out the controls that protect data on School Bus Hero: how access is granted and checked, how information is encrypted, how long it is kept, and the published standards we build against. Every control described here is one we operate today.
Payment Security
All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor — the highest level of certification in the payments industry.
- We never store credit card numbers on our servers
- All payment data is transmitted directly to Stripe over encrypted connections
- Stripe handles all card storage, processing, and PCI compliance
Access Controls
We use role-based access controls to ensure that users can only access the data and features appropriate to their role.
- Employer team members have configurable permissions set by the account owner
- Applicant data is only shared with employers when the applicant explicitly expresses interest
- Administrative access is limited to authorized personnel with additional authentication requirements
- Two-factor authentication (2FA) is available for all accounts
Infrastructure & Encryption
The Platform is hosted on secure cloud infrastructure with multiple layers of protection.
- All data is encrypted in transit using TLS/SSL (HTTPS everywhere)
- All data is encrypted at rest with AES-256 — both the database and uploaded files
- Backups are encrypted, held in a separate location from the live systems, and retained for no more than 30 days
- Deleted data is removed from live systems immediately and ages out of those backups within that window — so a deletion is complete within 30 days, everywhere
- Infrastructure is monitored for unauthorized access and anomalies
Uploaded documents
Anything you upload is treated as confidential by default, and the controls below apply to all of it.
- A document is never public. It has no shareable address and is not indexed by search engines.
- Every download runs a permission check first. The link the browser follows is valid for sixty seconds and cannot be passed on.
- You choose who sees what you upload. Nothing is shared automatically.
- Every access is recorded — who opened which document, and whose it was.
- Delete your account and what you uploaded is deleted with it.
- Records an employer created about your employment stay with that employer. Federal rules require them to keep driver qualification files for three years after employment ends, and we do not delete them out from under either of you.
- Files are encrypted at rest with AES-256, and in transit with TLS.
Standards we build to
We build to the standard a public school district would ask of a vendor, whether or not the customer is one.
- NIST Cybersecurity Framework 2.0 — the framework our security program is organized around.
- WCAG 2.1 Level AA — the accessibility standard public entities are held to. We hold ourselves to it too.
- Federal driver record rules — retention follows FMCSA requirements, so an employer's driver qualification files are never deleted out from under them.
We do not hold student records of any kind. School Bus Hero stores employment and credential records for adults.
Who else touches your data
We use a small number of established providers. Each one sees only what it needs to do its job.
| Provider | What they handle |
|---|---|
| DigitalOcean | Hosting, database and file storage. All encrypted at rest. |
| Cloudflare | Traffic routing and protection. |
| Stripe | Payments. Card details never reach our servers. |
| Resend | Transactional email. |
| OpenAI | Powers our assistants. Receives a name and the types of documents on file — never the documents themselves. Data sent through the API is not used to train their models. |
We do not sell personal information, and we do not share it with advertisers.
Responsible Disclosure
If you discover a security vulnerability or have concerns about the security of the Platform, we encourage you to report it responsibly. Please contact us at:
We take all reports seriously and will investigate and respond promptly. We ask that you give us reasonable time to address any issue before disclosing it publicly.