Enterprise-grade security

Your data is protected.

Bank-level encryption, SOC2-compliant infrastructure, and enterprise-grade security practices protect your scheduling data.

SOC2 Type IIAES-256 and TLS 1.3 encryption24/7 security monitoringMFA support

Security control map

Protection across the data lifecycle

Reviewable

Encrypt

AES-256 at rest · TLS 1.3 in transit

Monitor

Continuous 24/7 security monitoring

Control

Role-based access and MFA support

Recover

Continuous backups and point-in-time recovery

How we protect your data

Multiple layers of security keep scheduling data private, secure, and available.

ScheduleForward protects account information, schedules, assignments, preferences, time-off information, trade history, calendar settings, and technical logs with encryption, access controls, audit logging, continuous monitoring, and enterprise-grade infrastructure.

Security controls cover the full data lifecycle—from encrypted transmission and storage to permissions, monitoring, backups, recovery, retention, and vendor oversight.

How we protect your data

Six layers of security for healthcare scheduling

Encryption, SOC2-compliant infrastructure, healthcare-grade safeguards, continuous backups, role-based access, and reliable availability work together to protect scheduling data.

Ask a security question

Bank-Level Encryption

AES-256 · TLS 1.3

All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Encrypted backups add another layer of protection.

SOC2-Compliant Infrastructure

Security · availability · confidentiality

ScheduleForward's infrastructure meets SOC2 Type II compliance standards, with annual third-party audits, continuous monitoring, and documented security policies.

Healthcare-Grade Security

Healthcare data protection

Access controls, audit logging, and data-integrity safeguards protect sensitive healthcare scheduling information.

Continuous Backups

Recovery and redundancy

Data is continuously backed up across multiple geographic regions, with real-time replication, multi-region redundancy, point-in-time recovery, and 30-day backup retention.

Role-Based Access Control

Granular permissions

Fine-grained permissions ensure staff only see what they need. Administrators control who can view and modify schedules, with audit trails for changes.

99.9% Uptime Guarantee

24/7 monitoring

Real-time monitoring, redundant systems, automated failover, and an SLA support reliable access to the scheduling platform.

Data lifecycle

Published retention periods, not vague promises

ScheduleForward's Privacy Policy, last updated January 18, 2026, lists retention by data type and states that data is securely deleted or anonymized when no longer needed.

Data typePublished period
Account informationDuration of account + 30 days
Scheduling dataPer organizational policy
Authentication logs6 months
Audit logs12 months active + 7 years archived

Third-party services

Trusted providers that help operate ScheduleForward

These providers are bound by contractual obligations to protect data. ScheduleForward does not sell personal information and shares data only as necessary to operate the service.

Authentication, communications, and calendar synchronization use established service providers with defined operational purposes.

Supabase

Authentication and database services

Account credentials, sessions, and application data as required to operate the service

Twilio

SMS notification delivery

Phone numbers and opted-in service communications

Resend

Email delivery

Schedule notifications, system alerts, and service updates

Amazon Web Services

Cloud storage

ICS calendar files used for external calendar synchronization

Healthcare procurement

Need more security information?

ScheduleForward can provide detailed security documentation, complete vendor security questionnaires, or schedule a call with the security team.

Security questionnaires

ScheduleForward provides detailed security documentation and can complete vendor security questionnaires for procurement review.

No protected health information

ScheduleForward is workforce scheduling software. It does not collect, store, or process protected health information or other HIPAA-regulated data, so HIPAA compliance and Business Associate Agreements do not apply.

SOC2 Type II

ScheduleForward maintains SOC2-compliant infrastructure with security, availability, and confidentiality controls, annual third-party audits, and continuous monitoring.

Our security practices

Proactive measures that keep data secure

Security is maintained through testing, training, incident planning, secure development, monitoring, retention controls, and vendor assessment.

Third-party penetration testing

Employee security training and background checks

Defined incident-response procedures

Secure software development lifecycle

Vulnerability scanning and patch management

System access logging and monitoring

Data minimization and retention policies

Third-party vendor security assessments

Security and compliance questions

Direct answers for your security review

Review encryption, access controls, MFA, data scope, SOC2 Type II, uptime, backups, and procurement support.

How does ScheduleForward encrypt data?+

All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. Backups are encrypted as well.

How is access to scheduling data controlled?+

Role-based access controls and fine-grained permissions ensure staff only see what they need. Administrators control who can view and modify schedules, and audit trails record changes.

Does ScheduleForward support multi-factor authentication?+

Yes. Multi-factor authentication is available as part of ScheduleForward's enterprise security controls.

Is ScheduleForward HIPAA compliant?+

No. ScheduleForward does not collect, store, or process protected health information or other HIPAA-regulated data. It is workforce scheduling software rather than a clinical records or patient-data system, so HIPAA compliance and Business Associate Agreements do not apply.

Is ScheduleForward SOC2 Type II compliant?+

ScheduleForward maintains SOC2-compliant infrastructure with security, availability, and confidentiality controls, annual third-party audits, continuous monitoring, and documented security policies.

What availability and backup protections are in place?+

ScheduleForward provides a 99.9% uptime guarantee supported by real-time monitoring, redundant systems, and automated failover. Data is continuously backed up with real-time replication, multi-region redundancy, point-in-time recovery, and 30-day retention.

Can ScheduleForward complete a security questionnaire?+

Yes. ScheduleForward can provide detailed security documentation, complete vendor security questionnaires, and schedule a call with the security team.