We base our information security program on industry standard frameworks and conduct regular audits to ensure we are meeting our commitments to ourselves and our customers.
We engage with third party partners to conduct a SOC 2 Type 2 audit and application penetration.
We are a member of State Ramp and we are TX-Ramp Level 1 certified and renew that certification every three years.


.png)
Access is tied to your organization's real identity system, not a shared login. Accounts are provisioned and removed automatically as your team changes, closing the offboarding gap. Passkeys remove the password from sign-in entirely.
Permissions can be scoped so a department, campus, or location manages its own content, while central communications retains control over emergency and brand-critical channels, administration that scales without one person becoming a bottleneck.
A durable record of who did what and when available for incident investigation, internal policy compliance, and audit evidence requests.
A third-party confirmation that we actually operate the controls above as described, so your security review can be a document exchange instead of an open-ended assessment.
A separate commitment from the controls above, this determines whether an institution can select us at all. Organizations with accessibility mandates can procure Carousel without an unresolved legal exception.
Get direct access to our compliance reports and security documentation through our Trust Center ... no calls or emails required.
Request Compliance Documents →
At Carousel, we prioritize information security and compliance. We have a dedicated team responsible for leading and managing security initiatives that support our products and organization, but you can rest assured knowing that it’s not just this InfoSec team who is concerned about security; we are a company full of security-conscious champions! Security is everyone’s responsibility even if it’s not in your job title. We provide weekly security training opportunities that ensure our entire company is proactively prioritizing and integrating security considerations into everything we do.

We understand the importance of a layered approach when it comes to protecting our organization and our customers' data. In addition to hiring great people, we have implemented 20 information security policies that outline our organization's approach to security. We also maintain playbooks and procedures to support our incident response, risk management, vendor management, vulnerability management, security operations, and other information security and privacy programs that we have at Carousel. On top of all of that, we also have advanced tooling and technologies in place that enable us to secure your data more effectively and efficiently.
Get direct access to our compliance reports and security documentation through our Trust Center ... no calls or emails required.
Request Compliance Documents →