Information Security & Compliance

Power your digital signage with peace of mind.

We base our information security program on industry standard frameworks and conduct regular audits to ensure we are meeting our commitments to ourselves and our customers.

SOC 2 Type 2
TX-Ramp
HECVAT
HECVAT Lite
Pen Test
VPAT
SIG lite
CAIQ
SOC 2 Type 2 Audit

We engage with third party partners to conduct a SOC 2 Type 2 audit and application penetration.

State Ramp & Texas Ramp

We are a member of State Ramp and we are TX-Ramp Level 1 certified and renew that certification every three years.

Other Assessments

Higher Education Community Vendor Assessment (HECVAT) and Consenesus Assessment Initiative Questionaire (CAIQ).

StateRAMP logoAICPA SOC logoTX-RAMP logo

Platform Security & Access Controls

Identity: Knowing Who Is Signing In
SSO · MFA / Passkeys

Access is tied to your organization's real identity system, not a shared login. Accounts are provisioned and removed automatically as your team changes, closing the offboarding gap. Passkeys remove the password from sign-in entirely.

Authority: Controlling What Each Person Can Do
Role-Based Access · User Management

Permissions can be scoped so a department, campus, or location manages its own content, while central communications retains control over emergency and brand-critical channels, administration that scales without one person becoming a bottleneck.

Accountability: Knowing What Happened
Audit Logs

A durable record of who did what and when available for incident investigation, internal policy compliance, and audit evidence requests.

Independent Verification
SOC 2

A third-party confirmation that we actually operate the controls above as described, so your security review can be a document exchange instead of an open-ended assessment.

Accessibility
WCAG 2.1 AA

A separate commitment from the controls above, this determines whether an institution can select us at all. Organizations with accessibility mandates can procure Carousel without an unresolved legal exception.

Need the Documentation?

Get direct access to our compliance reports and security documentation through our Trust Center ... no calls or emails required.

Request Compliance Documents →
"Carousel will continue to make investments in this area to ensure the highest level of security and compliance and build and maintain trust with our customers.”

Company-Wide Security Training

Image of a computer screen at a desk with Ninjio on the screen.

At Carousel, we prioritize information security and compliance. We have a dedicated team responsible for leading and managing security initiatives that support our products and organization, but you can rest assured knowing that it’s not just this InfoSec team who is concerned about security; we are a company full of security-conscious champions! Security is everyone’s responsibility even if it’s not in your job title. We provide weekly security training opportunities that ensure our entire company is proactively prioritizing and integrating security considerations into everything we do.

Security Policies & Practices at Carousel

We understand the importance of a layered approach when it comes to protecting our organization and our customers' data. In addition to hiring great people, we have implemented 20 information security policies that outline our organization's approach to security. We also maintain playbooks and procedures to support our incident response, risk management, vendor management, vulnerability management, security operations, and other information security and privacy programs that we have at Carousel. On top of all of that, we also have advanced tooling and technologies in place that enable us to secure your data more effectively and efficiently.

Need the Documentation?

Get direct access to our compliance reports and security documentation through our Trust Center ... no calls or emails required.

Request Compliance Documents →