Fullbench

Security & data

What we hold, where it lives, and who can see it

Written for the person who signs off before your staff log in: where the data sits, who can reach it, and the record standing behind every action.

The district's credential summary: documents awaiting review, never filed, lapsed, lapsing within thirty days, and approved and current
The program record: a requisition released to every approved agency at one recorded instant, with the HR director's name on it
Every action in the program is attributable and exportable.Every document, by status, attributable and exportable.

The short answer

We hold no student data of any kind

Fullbench is an adult workforce program. It holds records about the people who work in your buildings and the agencies that supply them. It does not collect, receive, or store student names, IEP content, grades, attendance, or any other student record. There is nowhere in the program for one to go.

What we hold

District staff and agency-worker records: names, work contact details, the credential documents your office requires, assignment dates, hours worked, and rates. Nothing about students.

Where it lives

United States region, on managed cloud infrastructure. Encrypted in transit (TLS 1.2+) and at rest. Credential documents are stored in object storage, not in email.

Who can see it

Access is scoped by district in the program itself, not by policy. An agency sees only its own people and only the openings you released to it. Suspending an agency blinds it to your district the same day.

The record

Every action is attributable

Every release, submission, approval, credential decision, and status change is written to the program record with a name and a time. Your district can read all of it on screen at any time and export it as CSV, in pages of up to 5,000 rows. Ask and we run a full extract for you.

  • Retention and export. Your program record exports in full, on request, at any time. On written request we delete district data within 30 days of termination, excluding records we are required to retain for tax and payroll purposes.
  • Incidents within 72 hours. If we learn of unauthorized access to your district's data, we notify your named contact within 72 hours with what we know at that point, and follow up as we learn more.
  • Access control. Every account is tied to a named person and scoped to one district or one agency. An account outside your district cannot read your data through any route in the application.
  • Sub-processors. Managed cloud hosting, a managed database provider, an email delivery provider, and object storage, all US-region. We publish additions on this page before they take effect.

Your review

We answer your security questionnaire in writing.

Send the form your district uses and we complete every line of it, in writing, before anyone signs. If your review turns on particular controls, certifications, or a data-processing agreement, put them in front of us and you will get a direct answer on each one from the person who runs the program.

Next step

Questions the page did not answer? Send us your questionnaire.