Bank-Level Encryption
AES-256 · TLS 1.3
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Encrypted backups add another layer of protection.
Bank-level encryption, SOC2-compliant infrastructure, and enterprise-grade security practices protect your scheduling data.
Security control map
Protection across the data lifecycle
Encrypt
AES-256 at rest · TLS 1.3 in transit
Monitor
Continuous 24/7 security monitoring
Control
Role-based access and MFA support
Recover
Continuous backups and point-in-time recovery
How we protect your data
ScheduleForward protects account information, schedules, assignments, preferences, time-off information, trade history, calendar settings, and technical logs with encryption, access controls, audit logging, continuous monitoring, and enterprise-grade infrastructure.
Security controls cover the full data lifecycle—from encrypted transmission and storage to permissions, monitoring, backups, recovery, retention, and vendor oversight.
Encryption, SOC2-compliant infrastructure, healthcare-grade safeguards, continuous backups, role-based access, and reliable availability work together to protect scheduling data.
AES-256 · TLS 1.3
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Encrypted backups add another layer of protection.
Security · availability · confidentiality
ScheduleForward's infrastructure meets SOC2 Type II compliance standards, with annual third-party audits, continuous monitoring, and documented security policies.
Healthcare data protection
Access controls, audit logging, and data-integrity safeguards protect sensitive healthcare scheduling information.
Recovery and redundancy
Data is continuously backed up across multiple geographic regions, with real-time replication, multi-region redundancy, point-in-time recovery, and 30-day backup retention.
Granular permissions
Fine-grained permissions ensure staff only see what they need. Administrators control who can view and modify schedules, with audit trails for changes.
24/7 monitoring
Real-time monitoring, redundant systems, automated failover, and an SLA support reliable access to the scheduling platform.
ScheduleForward's Privacy Policy, last updated January 18, 2026, lists retention by data type and states that data is securely deleted or anonymized when no longer needed.
These providers are bound by contractual obligations to protect data. ScheduleForward does not sell personal information and shares data only as necessary to operate the service.
Authentication, communications, and calendar synchronization use established service providers with defined operational purposes.
Authentication and database services
Account credentials, sessions, and application data as required to operate the service
SMS notification delivery
Phone numbers and opted-in service communications
Email delivery
Schedule notifications, system alerts, and service updates
Cloud storage
ICS calendar files used for external calendar synchronization
ScheduleForward can provide detailed security documentation, complete vendor security questionnaires, or schedule a call with the security team.
ScheduleForward provides detailed security documentation and can complete vendor security questionnaires for procurement review.
ScheduleForward is workforce scheduling software. It does not collect, store, or process protected health information or other HIPAA-regulated data, so HIPAA compliance and Business Associate Agreements do not apply.
ScheduleForward maintains SOC2-compliant infrastructure with security, availability, and confidentiality controls, annual third-party audits, and continuous monitoring.
Security is maintained through testing, training, incident planning, secure development, monitoring, retention controls, and vendor assessment.
Third-party penetration testing
Employee security training and background checks
Defined incident-response procedures
Secure software development lifecycle
Vulnerability scanning and patch management
System access logging and monitoring
Data minimization and retention policies
Third-party vendor security assessments
Review encryption, access controls, MFA, data scope, SOC2 Type II, uptime, backups, and procurement support.
All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Backups are encrypted as well.
Role-based access controls and fine-grained permissions ensure staff only see what they need. Administrators control who can view and modify schedules, and audit trails record changes.
Yes. Multi-factor authentication is available as part of ScheduleForward's enterprise security controls.
No. ScheduleForward does not collect, store, or process protected health information or other HIPAA-regulated data. It is workforce scheduling software rather than a clinical records or patient-data system, so HIPAA compliance and Business Associate Agreements do not apply.
ScheduleForward maintains SOC2-compliant infrastructure with security, availability, and confidentiality controls, annual third-party audits, continuous monitoring, and documented security policies.
ScheduleForward provides a 99.9% uptime guarantee supported by real-time monitoring, redundant systems, and automated failover. Data is continuously backed up with real-time replication, multi-region redundancy, point-in-time recovery, and 30-day retention.
Yes. ScheduleForward can provide detailed security documentation, complete vendor security questionnaires, and schedule a call with the security team.