Data Security

Data Security

Follett is committed to data security and supporting our customers’ data privacy needs. As student data collection evolves, Follett continues to provide and enhance the necessary levels of security to ensure your student information is secure and private in our learning management and educational systems.

Student Privacy Pledge

SOC-2 Type 2 Certification

Follett is proud to have achieved SOC-2 Type 2 certification for our Follett Destiny® Library Manager and Destiny Resource Manager products, a rigorous standard for data security. This certification demonstrates our commitment to maintaining the highest level of information security by adhering to strict policies and procedures designed to protect customer data.

The Follett SOC 2 Type 2/ SOC 3 certification for our Follett Destiny® Suite demonstrates our sustained focus on security, trust, and compliance.

🛡️ TX-RAMP Level 2 Certified for Follett Destiny® Suite under the Texas Risk and Authorization Management Program (TX-RAMP). This certification reflects our commitment to meeting the State of Texas’s standards for cloud security, data protection, and risk management. It ensures that our platform is trusted to handle confidential and regulated data across Texas.

Follett has achieved an Authority to Operate (ATO) from a U.S. federal agency for the Aspen Student Information System (SIS). This ATO is agency-specific and aligns with the federal NIST 800-53 framework cybersecurity and privacy requirements.

Follett Software Security Champions

Follett Software values the contributions of independent security researchers who invest time and effort to make our applications more secure. We encourage responsible reporting of any potential areas for improvement or vulnerabilities that may be found in our applications via our Responsible Disclosure Program.

Reassure Your Stakeholders About the Safety of Student Data

Follett Software upholds compliance through adherence to numerous rigorous regulations, including:

  • Family Educational Rights and Privacy Act Regulations (FERPA)
  • General Data Protection Regulation (GDPR)
  • Children’s Online Privacy Protection Act (COPPA)
  • Breach Laws, Data Residency Laws
  • Digital Millennium Copyright Act (DMCA)
  • State contracts for reporting