Security & Compliance

Third-Party / Vendor Security Policy

How Skoolfly assesses and manages security and data-handling risk from its vendors and partners.

1. Policy Statement

Skoolfly works with third parties that provide technology, hosting, payments, communication and other services. This policy defines how third-party and vendor security risk is assessed, contracted and monitored.

2. Purpose

The purpose of this policy is to ensure that third parties that touch Skoolfly data or systems meet appropriate security and data-protection expectations, and to reduce risk arising from the vendor ecosystem.

3. Scope

This policy applies to all third parties that process Skoolfly data, host or operate components of the platform, integrate with Skoolfly systems, or otherwise present security risk. It includes cloud providers, software and AI providers, payment processors, communication services and other vendors.

4. Vendor Risk Assessment

Before engaging a vendor that will access Skoolfly data or systems, Skoolfly performs a risk assessment proportionate to the vendor's role. The assessment considers the type and sensitivity of data involved, the vendor's access, its security practices, and the impact of its failure or compromise.

5. Vendor Classification

CriticalVendors whose compromise or failure could materially harm Skoolfly or its data; subject to the most rigorous review.
StandardVendors with limited access or data handling; subject to proportionate review and terms.
MinorVendors with minimal risk; subject to baseline requirements.

6. Due Diligence

Review vendor security posture, certifications and documented controls where relevant.

Assess the vendor's data-handling and confidentiality practices.

Check the vendor's track record and relevant public security disclosures.

Document the assessment and its outcome.

7. Contractual Security Requirements

Engagement with vendors that process data or access systems is documented in contracts that include appropriate confidentiality, security, breach-notification, and data-processing terms. Contracts should include the ability to audit or otherwise verify compliance where proportionate to risk.

8. Data Processing and Sub-processors

Where a vendor processes personal data on Skoolfly's behalf, a data processing agreement or equivalent terms apply, consistent with the Data Protection & Privacy Policy.

Vendors must not engage sub-processors without appropriate authorisation and should inform Skoolfly of changes that require re-assessment.

9. Access and Connectivity

Vendor access to Skoolfly systems is granted on a least-privilege basis.

Vendor credentials and integrations are managed, monitored and revoked when no longer required.

Integrations and vendor code follow the Secure Development and Access Control policies.

10. Ongoing Monitoring and Review

Vendors are monitored on a risk basis, including review of incidents, changes to service, and periodic re-assessment. Critical vendors are reviewed more frequently. Risk findings are addressed with the vendor or through compensating controls.

11. Incident Notification

Vendors are required to notify Skoolfly promptly of security incidents affecting Skoolfly data or systems, in line with contractual terms. Notifications are handled through the Incident Response Policy, including required downstream notifications where data is affected.

12. Termination and Transition

On termination, vendors return or securely delete Skoolfly data as agreed.

Access is revoked and integrations are decommissioned.

Exit and transition arrangements preserve data security and availability.

13. Roles and Responsibilities

Procurement / Business ownersInitiate assessments and own vendor relationships.
Security ownerOversees risk assessment, monitoring and incident handling.
LegalReview contracts and data-processing terms.
Engineering / DevOpsManage integrations, credentials and technical due diligence.

14. Review

This policy is reviewed at least annually, or when the vendor ecosystem, services or legal requirements change significantly.