Curriculum Warehouse
Curriculum Warehouse
  • Home
  • Contact Us!
  • District Portal Access
  • More
    • Home
    • Contact Us!
    • District Portal Access
  • Home
  • Contact Us!
  • District Portal Access

Curriculum Warehouse Security & Data Protection

Effective Date: August 22, 2026
Last Updated: August 23, 2026

Curriculum Warehouse, operated by NJ Data Diva LLC, is designed with security, Client separation, and responsible data handling as core Platform principles.

This Security & Data Protection Policy describes the administrative and technical practices used to protect information processed through Curriculum Warehouse.

It should be read together with the Curriculum Warehouse Terms of Service, Privacy Policy, Terms of Use, Student Data Scope, Subprocessors, and Service Level Agreement.

No online service can guarantee absolute security. Curriculum Warehouse therefore uses commercially reasonable safeguards designed to reduce risk, protect Client environments, and support timely response when security concerns arise.

1. Hosting and Infrastructure

1.1 Private Platform Infrastructure

The private Curriculum Warehouse application is built and hosted using services provided through Google Cloud Platform and Firebase, including Firebase Hosting and related Google Cloud/Firebase infrastructure.

The private Platform currently uses managed cloud infrastructure for functions that may include:

  • application hosting;
  • authentication;
  • database services;
  • file storage;
  • server-side processing;
  • backup and recovery processes; and
  • related Platform operations.

Client curriculum information and private Platform data are maintained within the Google Cloud/Firebase environment.

1.2 Public Website Hosting

The public Curriculum Warehouse marketing and legal Website at curriculumwarehouse.com is hosted and managed through GoDaddy.

The public Website is separate from the private Curriculum Warehouse application.

GoDaddy does not serve as the primary hosting environment for Client curriculum data or the private Curriculum Warehouse Platform.

1.3 United States-Based Infrastructure

Primary Curriculum Warehouse Platform data is hosted using United States-based Google Cloud infrastructure.

Applicable Platform services may operate within U.S.-based Google Cloud infrastructure according to Platform configuration and the technical requirements of the applicable Google Cloud/Firebase service.

1.4 Physical Infrastructure

Curriculum Warehouse does not independently operate physical data centers.

Physical infrastructure protections for the private Platform are provided by the applicable cloud infrastructure provider.

Google Cloud maintains physical and environmental security controls for its data-center infrastructure, including controls relating to:

  • physical access;
  • facility security;
  • monitoring;
  • restricted infrastructure access; and
  • other physical protections maintained by Google.

2. Encryption and Data Protection

2.1 Encryption in Transit

Curriculum Warehouse uses encrypted HTTPS connections to protect information transmitted between supported user browsers and Platform services.

Transport encryption is provided through industry-standard TLS protocols supported by the applicable hosting infrastructure.

2.2 Encryption at Rest

Platform information stored through applicable Google Cloud services is protected using Google Cloud's default encryption-at-rest infrastructure.

Google Cloud encrypts customer content stored at rest within applicable services, including use of AES-256 encryption at the storage layer where supported by the applicable Google Cloud service.

2.3 Encryption Key Management

Curriculum Warehouse currently relies upon Google-owned and Google-managed encryption keys associated with Google Cloud's default encryption infrastructure unless otherwise specifically configured.

Curriculum Warehouse does not represent that Clients independently control or possess the underlying cloud-provider encryption keys.

3. Authentication and Identity Management

3.1 Supported Authentication

Curriculum Warehouse may support authentication through:

  • Google Workspace;
  • Microsoft 365;
  • Firebase Authentication; and
  • other supported authentication providers as Platform functionality evolves.

3.2 Single Sign-On

Where a Client uses Google Workspace or Microsoft 365 Single Sign-On (“SSO”), authentication occurs through the applicable identity provider.

Curriculum Warehouse does not receive or store the user's Google Workspace or Microsoft 365 password.

3.3 Non-SSO Accounts

Where Firebase Authentication is used, authentication credentials are managed through the applicable authentication service.

NJ Data Diva LLC personnel do not have access to users' plain-text passwords.

3.4 Client Responsibility

Clients remain responsible for:

  • determining who should receive Platform access;
  • maintaining appropriate identity-provider settings;
  • configuring access so that only authorized professional users receive Platform access;
  • disabling or modifying access when personnel leave or change responsibilities;
  • protecting local credentials and accounts; and
  • notifying Curriculum Warehouse of suspected compromised or unauthorized access.

Students are not intended to be Authorized Users of the private Curriculum Warehouse Platform.

Additional information regarding unintended student authentication is provided in the Curriculum Warehouse Student Data Scope and Privacy Policy.

4. Role-Based Access Control and Client Separation

4.1 Role-Based Access

Curriculum Warehouse uses role-based access controls designed to limit Authorized Users to information and functions appropriate to their assigned access.

Current Client-level Platform roles include:

  • Admin;
  • Supervisor;
  • Editor; and
  • Viewer.

An account may also be placed in an Inactive state, which prevents ordinary Platform access.

A separate Corporate Admin role is reserved for authorized NJ Data Diva LLC personnel who require Provider-level access for legitimate Platform administration, configuration, support, security, maintenance, recovery, or related operational purposes.

4.2 Database-Level Access Controls

Platform access controls are designed to be enforced through backend and database security logic rather than relying solely upon what is visible within the user interface.

4.3 Client Separation

Curriculum Warehouse uses a multi-Client architecture designed to separate each Client's private Platform environment.

Ordinary Client users are not authorized to access another Client's private curriculum environment.

Access-control rules, Client identifiers, authentication information, and Platform permissions are used to restrict Platform requests to the appropriate Client environment.

4.4 Provider Administrative Access

Authorized NJ Data Diva LLC personnel with Corporate Admin or other Provider-level administrative access may access Client environments where reasonably necessary to:

  • configure Client environments;
  • provide technical support;
  • troubleshoot Platform issues;
  • maintain Platform security;
  • perform authorized migration or recovery work;
  • investigate suspected misuse or security incidents;
  • maintain system and data integrity; or
  • operate and maintain the Platform.

Provider-level access is not intended for routine evaluation of Client personnel.

5. Platform Activity, Logging, and Security Monitoring

5.1 Platform Activity and Audit Records

Curriculum Warehouse generates system and audit records associated with certain Platform activity.

Depending upon Platform functionality, these records may include:

  • authentication and login events;
  • session dates and times;
  • active session duration;
  • administrative actions;
  • curriculum changes;
  • publishing or approval activity;
  • exports or downloads;
  • security-related events; and
  • other system-generated Platform interactions.

Such information may assist with:

  • account administration;
  • session management;
  • security investigations;
  • troubleshooting;
  • identifying unauthorized activity;
  • curriculum workflow accountability;
  • operational visibility;
  • usage analysis;
  • system performance;
  • support requests; and
  • Platform improvement.

5.2 Active Session Duration

Curriculum Warehouse may track the duration of active Platform sessions.

Active session duration may be used for purposes including:

  • session management;
  • operational visibility;
  • Platform administration;
  • usage analysis;
  • troubleshooting;
  • security; and
  • Platform improvement.

Active session information is intended to describe activity within Curriculum Warehouse.

It is not designed as a payroll, attendance, or employee timekeeping system and should not be relied upon as the sole measure of an individual's:

  • attendance;
  • hours worked;
  • productivity;
  • compensation eligibility; or
  • job performance.

5.3 Client Administrative Visibility

Depending upon Platform configuration, assigned roles, and permissions, certain audit and activity records may be available to authorized Client administrators.

The Client is responsible for its use of such information in accordance with applicable law, Board policy, employment agreements, collective bargaining obligations, and internal procedures.

5.4 Provider Access to Activity Information

Authorized NJ Data Diva LLC personnel may access audit, session, and security information only where reasonably necessary to:

  • operate and secure the Platform;
  • administer Client environments;
  • troubleshoot technical issues;
  • respond to Client support requests;
  • investigate suspected security incidents or misuse;
  • maintain system integrity; or
  • satisfy applicable legal obligations.

5.5 Scope of Monitoring

Curriculum Warehouse does not monitor a user's browsing, communications, device activity, or online activity outside of the Curriculum Warehouse Platform.

Detailed information regarding Platform activity, active session duration, audit records, and their use is provided in the Curriculum Warehouse Privacy Policy.

6. Backups, Resiliency, and Recovery

6.1 Backup Processes

Curriculum Warehouse uses backup and recovery processes designed to help protect Client curriculum information against accidental deletion, corruption, Platform failure, or other data-loss events.

Backup architecture may include provider-managed cloud backup capabilities and Curriculum Warehouse-controlled backup or recovery processes.

6.2 Recovery

Where technically feasible and appropriate to the circumstances, Curriculum Warehouse may use available backups or recovery mechanisms to restore information following:

  • accidental deletion;
  • data corruption;
  • Platform failure; or
  • another recoverable data-loss event.

Depending upon the nature of the event, recovery may require Provider or developer-level administrative support.

6.3 Client-Specific Recovery

The Platform's Client-separated architecture is designed to support recovery operations that may, where technically feasible, target a particular Client, course, curriculum area, or other limited dataset without intentionally altering unrelated Client data.

6.4 Recovery Limitations

Backup and recovery systems reduce the risk of data loss but cannot guarantee that every item of information can be recovered under every circumstance.

Unless expressly stated in a Client-specific agreement, Curriculum Warehouse does not guarantee a specific:

  • recovery-point objective;
  • recovery-time objective;
  • backup-retention period; or
  • historical restoration window.

Clients should maintain copies of information they independently require for archival, records-management, or legal-retention purposes.

7. Secure Development and Platform Maintenance

7.1 Security-Oriented Development

Curriculum Warehouse incorporates security considerations into Platform development and maintenance.

Security-related development practices may include:

  • review of authentication logic;
  • role and permission testing;
  • review of database security rules;
  • Client-isolation testing;
  • dependency and configuration review;
  • investigation of reported vulnerabilities;
  • security-focused code review; and
  • remediation of identified security issues.

7.2 Platform Updates

NJ Data Diva LLC may implement security updates, configuration changes, infrastructure improvements, dependency updates, or other technical changes when reasonably necessary to protect the Platform or Clients.

Emergency security changes may be implemented without advance notice when delay could materially increase security or operational risk.

7.3 Security Assessments

Curriculum Warehouse may conduct internal reviews or use technical tools and qualified external resources to evaluate Platform security.

Unless expressly stated otherwise, Curriculum Warehouse does not represent that NJ Data Diva LLC or Curriculum Warehouse itself currently holds an independent SOC 2 or ISO certification.

8. Cloud Provider Security and Compliance

Curriculum Warehouse benefits from security and compliance controls maintained by its cloud infrastructure providers.

Google Cloud maintains independent certifications, attestations, and audit programs applicable to portions of its infrastructure and services, including programs such as:

  • SOC 2 Type II; and
  • ISO/IEC 27001.

These certifications and attestations apply to Google Cloud and the Google services within their respective audit scopes.

They should not be interpreted as independent certification of NJ Data Diva LLC or Curriculum Warehouse itself.

Additional information regarding Google Cloud security and compliance is available through Google's published security and compliance resources.

9. Security Incidents and Breach Response

9.1 Provider Response


If NJ Data Diva LLC discovers or confirms unauthorized access to Client data, Curriculum Warehouse will notify the affected Client without unreasonable delay and in accordance with applicable law.

Where applicable law requires notification immediately following discovery or establishes another notification deadline, that requirement will control. Nothing in this Policy is intended to extend a shorter notification period required by applicable law.


Initial notice may be based on the information reasonably available to Curriculum Warehouse at the time of notification. Additional information may be provided as the investigation develops.

Curriculum Warehouse will make commercially reasonable efforts to:

  • investigate the incident;
  • contain and mitigate further unauthorized access or harm;
  • identify the nature and scope of the affected information;
  • remediate identified vulnerabilities where reasonably possible; and
  • cooperate with the affected Client regarding reasonable incident-response needs.


9.2 Investigation and Mitigation


Curriculum Warehouse will make commercially reasonable efforts to:

  • investigate the incident;
  • identify the nature and scope of the affected information;
  • contain or mitigate the incident;
  • remediate identified vulnerabilities where reasonably possible; and
  • cooperate with the affected Client regarding reasonable incident-response needs.


9.3 Client Security Events


Clients should promptly notify Curriculum Warehouse if they become aware of:

  • compromised credentials;
  • unauthorized Platform access;
  • suspicious account activity;
  • compromised Client identity-provider systems;
  • unintended student authentication or unauthorized student access; or
  • another security event that may affect Curriculum Warehouse.


9.4 Protective Suspension


NJ Data Diva LLC may temporarily restrict an affected account, user, Client environment, or portion of the Platform when reasonably necessary to prevent:

  • unauthorized access;
  • malicious activity;
  • data manipulation;
  • further security harm; or
  • material interference with Platform integrity.


Where reasonably feasible, restrictions will be limited to the scope and duration reasonably necessary to address the identified risk.

10. Shared Security Responsibilities, Changes, and Contact

10.1 Shared Responsibility

Security is a shared responsibility.

Curriculum Warehouse is responsible for commercially reasonable safeguards within the Platform and Provider-controlled systems.

Clients and Authorized Users remain responsible for the security of systems and configurations outside Curriculum Warehouse's control, including:

  • local networks;
  • computers and mobile devices;
  • browsers;
  • identity-provider accounts;
  • email accounts;
  • passwords and authentication credentials;
  • Client-managed permissions;
  • SSO and access configuration; and
  • internal administrative procedures.

10.2 Security Questions and Reviews

Clients may contact NJ Data Diva LLC with reasonable security questions or requests for additional technical information.

Where appropriate, Curriculum Warehouse may provide additional security documentation to authorized Client representatives.

Sensitive information regarding:

  • detailed Platform architecture;
  • database security rules;
  • credentials;
  • administrative security configurations;
  • recovery procedures;
  • internal testing;
  • vulnerability information; or
  • other information whose disclosure could create a security risk

will not be publicly disclosed.

10.3 Related Service Providers

Third-party providers may support the operation of Curriculum Warehouse or related business services.

The current Curriculum Warehouse Subprocessors page identifies relevant providers and distinguishes between:

  • the Google Cloud/Firebase infrastructure used for the private Platform;
  • GoDaddy services used for the public Curriculum Warehouse Website;
  • applicable communication service providers; and
  • Client-selected identity providers.

10.4 Changes to This Policy

NJ Data Diva LLC may update this Security & Data Protection Policy as Platform architecture, infrastructure, security practices, technology, service providers, or applicable requirements evolve.

Updates will be published within the Curriculum Warehouse Terms & Policies center with a revised “Last Updated” date.

Material changes will not intentionally reduce the overall security protections of the Platform during an active Client term without a legitimate technical, legal, operational, or security reason.

10.5 Contact

Security questions or suspected security concerns may be directed to:

NJ Data Diva LLC
Curriculum Warehouse
Email: jackie@curriculumwarehouse.com
Website: curriculumwarehouse.com

  • Contact Us!
  • Terms & Policies

Curriculum Warehouse

Copyright © 2026 NJ Data Diva LLC - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept