Incident Response
Audience: District IT, legal, and privacy officers
Purpose: How Ember detects, contains, and communicates about security incidents involving student data
Our commitment
Ember treats incidents involving student education records with the highest priority. We follow a structured response aligned with FERPA expectations and the notification terms in your Data Processing Agreement.
Severity levels
| Level | Description | Example | Our target response |
|---|---|---|---|
| Critical | Confirmed or strongly suspected unauthorized access to student records, or platform-wide outage | Suspected data exposure, authentication bypass | Acknowledge within 15 minutes; executive notification |
| High | Limited exposure risk or significant service degradation | Single-tenant anomaly, partial outage | Respond within 1 hour |
| Medium | Security concern without confirmed student data impact | Vulnerability report, failed external scan | Triage within 1 business day |
What we do in the first 30 minutes
- Assign an incident lead and open a dedicated response channel.
- Contain — revoke affected credentials, block malicious traffic, and isolate impacted systems if needed.
- Preserve evidence — secure audit logs and timeline data for investigation.
- Assess FERPA impact — determine whether student education records were accessed or disclosed.
- Notify your team — if student data may be involved, we contact your designated privacy officer per your DPA.
FERPA & district notification
When an incident may affect student records, we work with your district to:
- Identify scope (which students, which record types, what time window)
- Provide a factual timeline suitable for your legal and communications teams
- Support contractually required notifications to families or regulators
Notification windows follow your DPA — many districts align with a 72-hour assessment period for GDPR-style agreements.
Communication
To your district (initial):
Ember has identified [brief description] that may affect [scope]. We have taken [containment steps] as of [time]. A detailed update will follow within [agreed interval].
Ongoing updates are provided at least every 60 minutes for critical incidents until containment is confirmed.
After the incident
- Root cause analysis and remediation plan within 5 business days
- Control improvements documented for your security review
- Evidence retained per your agreement and applicable law
Your contacts
During onboarding, we collect:
| Role | Purpose |
|---|---|
| Privacy / FERPA officer | Primary contact for student data incidents |
| IT security lead | Technical coordination and SSO/roster context |
| Executive sponsor | Escalation and contract authority |
Update these contacts anytime through your Ember customer success manager.
Reporting a concern
District staff and security researchers can report issues to security@ember.edu.
For procurement questions, visit Security & compliance or Contact.