How we detect, respond to, and recover from security incidents
SafeClass Shield · Last Updated: June 1, 2026
This policy applies to all security incidents affecting SafeClass Shield systems, data, or operations, including:
Confirmed data breach · Ransomware · CSAM detection · Mass account compromise
Suspected breach · Service unavailability > 1hr · Targeted attack · PII exposure
Single account compromise · Failed intrusion attempt · Abnormal access patterns
Policy violation by staff · Minor configuration issue · Low-risk vulnerability found
The Incident Response Team (IRT) consists of:
| Recipient | Timeline | Channel | Legal Basis |
|---|---|---|---|
| Affected Parents/Users | 24 hours (P1/P2) | Email + In-app notification | Contractual / State laws |
| Affected Schools | 24 hours confirmed breach | Direct email to IT contact | FERPA 34 CFR 99 |
| EU Data Supervisory Authority | 72 hours | Regulatory portal / email | GDPR Art. 33 |
| EU Data Subjects | Without undue delay (high risk) | GDPR Art. 34 | |
| FBI / Law Enforcement | Immediately for criminal acts | Direct report | Federal law |
| NCMEC CyberTipline | Immediately for CSAM | cybertipline.org | 18 U.S.C. § 2258A |
| State AGs | Per state law (typically 30–72hr) | Regulatory filing | State breach laws |
| Insurance Provider | Within 48 hours (P1/P2) | Phone + email | Policy requirement |
We use essential cookies to keep you logged in and secure your account. With your permission, we also use analytics cookies to improve the platform. Privacy Policy · Terms