PLATFORM · SECURITY

Secure by default.

Every tenant's data is fully isolated. Connections are encrypted. Access is role-based. Every action is logged. Security isn't an add-on. It's how the platform is built.

Buying for your organisation?

The security and data protection overview for buyers and procurement covers hosting, sub-processors and the controls in place today.

Trust and security
Tenant data isolation Every organisation's data is scoped at the database level. Tenant A cannot see, query, or access Tenant B's data under any circumstances. Every query includes a tenant check.
HTTPS everywhere All connections are encrypted with TLS. Custom domains are served over HTTPS with a certificate we issue for you. No exceptions, no mixed content.
Password security Passwords are hashed with bcrypt (cost factor 12). We never store plaintext passwords. Sessions are regenerated on login to prevent fixation attacks.
Role-based access Five built-in roles with defined permission sets. Users only see and do what their role allows. Org managers are scoped to their department.
SSO and SCIM provisioning Single sign-on via SAML with signature checks, so people log in with their organisation's identity provider. SCIM creates and removes their accounts from that identity provider. On Provider Plus and Group, and Enterprise and Elite for employers.
Audit logging Every significant action is logged: logins, user changes, course edits, enrolments, permission changes. Audit logs are retained and exportable.
CSRF protection Every form submission includes a CSRF token. All POST, PUT, and DELETE requests are validated. Cross-site request forgery attacks are blocked by default.
Rate limiting Login, registration, password reset, and API endpoints are rate-limited. Brute-force and credential stuffing attacks are throttled automatically.
Secure sessions Session cookies are httpOnly, secure, and SameSite=Lax. They cannot be read by JavaScript or sent to third-party sites.
Encrypted personal data Names, email addresses and other personal data are encrypted at rest with AES-256-GCM. Finding someone by email uses a keyed hash, so lookups never need the plain value.
Two-factor sign-in Standard on every plan. Time-based one-time codes (TOTP) from any authenticator app, on top of a password or single sign-on.
AI assistant connections Assistants such as Claude or ChatGPT connect through OAuth sign-in and act with only the permissions of the person who connected them. Changes that email people are previewed and confirmed first, and every change is audit logged.

Your data. Your control.

You own your data. Always. Export users, bookings and course progress as CSV at any time. If you cancel, you get 90 days to export before your data is deleted. We never sell your data, and the companies that process it on our behalf are listed on the trust page.

CSV export
90 days to export after cancelling
We never sell your data

Questions about security?

We're happy to walk through our security architecture, or send us your security questionnaire and we will complete it.