NewAcadle AI is here.Try the demo
Trust & compliance

Security and compliance
at Acadle

We place a high priority on protecting the security and privacy of your data. Acadle runs on AWS and Microsoft Azure, encrypts data at rest and in transit, enforces role-based access control across every academy, and is tested regularly by independent, certified security specialists.

Compliance at a glance

  • SOC 2 alignedSOC 2Aligned controls and monitoring
  • ISO 27001 alignedISO 27001Information security practices
  • GDPR readyGDPRPrivacy-ready data handling
At rest
AES encryption
In transit
SSL/TLS
Access
RBAC + MFA
Testing
Third-party VAPT

How we protect your academy

Eight control areas cover the questions enterprise security, IT and procurement teams ask before rolling out a learning platform.

Data encryption

Encrypted at rest and in transit

All sensitive data is encrypted with AES at rest, and every request between your learners and our servers travels over SSL/TLS. User passwords are hashed with a one-way algorithm and are never stored in plain text — not by us, and not in backups.

  • AES encryption for data at rest, including database backups
  • SSL/TLS encryption for all data in transit
  • Passwords salted and hashed — never stored or logged in plain text
  • Encrypted object storage for course media and learner uploads
Access control

Least privilege, enforced with MFA

Access to production infrastructure requires multi-factor authentication and is restricted to named, authorised personnel. Access to customer data is limited to the employees who need it to provide support or troubleshoot on your behalf, and every grant is reviewed.

  • MFA required for all production and administrative access
  • Role-scoped internal access, reviewed on a recurring basis
  • Access revoked immediately as part of offboarding
  • Administrative actions logged for accountability
Application access

Role-based access control inside your academy

Acadle uses a role-based access control (RBAC) model, so each user only sees the data they are entitled to. Academies are logically isolated: users can never view data belonging to an organisation other than their own.

  • RBAC for admins, instructors, managers and learners
  • Strict tenant isolation between academies
  • Segmentation so departments, regions and partners see only their tracks
  • SSO with Active Directory or LinkedIn, plus your own app credentials
Secured infrastructure

Built on AWS and Microsoft Azure

Acadle's infrastructure runs on AWS and Microsoft Azure. Both platforms operate physical infrastructure accredited under SOC 2, ISO 27001, PCI DSS Level 1 and FISMA Moderate, giving your academy enterprise-grade hosting, redundancy and physical security by default.

  • Hardened cloud infrastructure on AWS and Azure
  • Provider infrastructure accredited under SOC 2, ISO 27001, PCI L1, FISMA Moderate
  • Network segmentation and firewalling between tiers
  • Automated backups with monitored restore procedures
Penetration testing

Independently tested, continuously verified

We commission regular penetration tests through an independent, certified third-party VAPT provider to validate our security posture and surface potential weaknesses before attackers can. Findings are triaged, owned and tracked to closure.

  • Regular third-party VAPT engagements
  • Findings triaged by severity with tracked remediation
  • Secure development practices and peer code review
  • Continuous monitoring of production systems
Vulnerability management

Patched within defined SLAs

Third-party software and services are reviewed periodically and patched on a schedule. When a vulnerability is disclosed, we assess exposure and apply fixes within pre-defined SLAs based on severity.

  • Periodic review of third-party dependencies and services
  • Severity-based patching SLAs
  • Dependency and configuration monitoring
  • Change management for production releases
Security training

Every employee trained for a cloud-first setup

All Acadle personnel complete security and data-protection training designed specifically for a cloud-hosted environment. The programme targets the everyday mistakes — phishing, credential reuse, mishandled files — that cause most real-world incidents.

  • Mandatory security awareness training for all personnel
  • Phishing and social-engineering awareness
  • Confidentiality obligations in every employment agreement
  • Documented internal security policies
Privacy & GDPR

Privacy-respecting by design

We collect only the learner data an academy needs to run, and we process it on your behalf as your data processor. Acadle follows GDPR-ready practices for consent, data-subject requests, retention and deletion.

  • GDPR-ready data handling and data-subject request support
  • Data minimisation across learner profiles and analytics
  • Defined retention and deletion practices
  • Data processing agreements available on request

Shared responsibility

Security works when both sides know their part. Here is how responsibility is split between our cloud providers, Acadle and your team.

Cloud providers

AWS and Microsoft Azure secure the physical data centres, hardware and hypervisor layer, under SOC 2, ISO 27001, PCI DSS Level 1 and FISMA Moderate accredited programmes.

Acadle

We secure the application, tenant isolation, encryption, patching, monitoring, internal access control, employee training and independent penetration testing.

Your team

You manage academy roles and permissions, decide what learner data you collect, configure SSO and password policy in your identity provider, and offboard your own users.

This page describes Acadle's current security practices and the accreditations held by our hosting providers. It is maintained by Acadle to answer common security and privacy questions and is not an independent certification or audit report. For current attestations, provider reports or a data processing agreement, contact support@acadle.com.

Responsible disclosure

The security of our system is of utmost importance to us. If you believe you have found a security issue in Acadle, email us with the details and steps to reproduce. We acknowledge reports, investigate promptly, and fix and update at the earliest opportunity. Please do not publicly disclose an issue before we have had a chance to respond.

support@acadle.com

Security reports are treated as priority.

Security & compliance FAQ

Is Acadle SOC 2 and ISO 27001 compliant?

Acadle follows SOC 2 and ISO 27001 aligned security practices, and our hosting providers (AWS and Microsoft Azure) operate infrastructure accredited under SOC 2, ISO 27001, PCI DSS Level 1 and FISMA Moderate. For the current status of our own attestations and copies of provider reports, contact support@acadle.com.

How is my academy data encrypted?

Sensitive data is encrypted with AES at rest, including backups, and all traffic between learners and our servers is encrypted in transit with SSL/TLS. Passwords are hashed and never stored in plain text.

Who inside Acadle can access customer data?

Only employees who need access to provide support or troubleshooting. Production access requires multi-factor authentication, is limited to authorised personnel, and is revoked as part of offboarding.

Can learners from one academy see another organisation's data?

No. Acadle enforces role-based access control with strict tenant isolation, so users can only see data belonging to their own organisation and only the content their role permits.

Do you carry out penetration testing?

Yes. We run regular penetration tests with an independent, certified third-party VAPT provider, and remediate findings according to severity-based SLAs.

Is Acadle GDPR ready, and can I sign a DPA?

Yes. Acadle follows GDPR-ready practices for consent, data-subject requests, retention and deletion, and acts as your data processor. Data processing agreements are available — email support@acadle.com.

Does Acadle support SSO and enterprise identity providers?

Yes. Learners can sign in with SSO via Active Directory or LinkedIn, or with your product's existing credentials, so you keep identity and password policy in your own systems.

How do I report a security vulnerability?

Email support@acadle.com with the details. We treat reports as a priority, confirm receipt, investigate, and fix and update as early as possible.

Ready for a security review?

Send us your security questionnaire or vendor assessment and our team will walk you through Acadle's controls, hosting model and data handling.