How we protect your academy
Eight control areas cover the questions enterprise security, IT and procurement teams ask before rolling out a learning platform.
Data encryption
Encrypted at rest and in transit
All sensitive data is encrypted with AES at rest, and every request between your learners and our servers travels over SSL/TLS. User passwords are hashed with a one-way algorithm and are never stored in plain text — not by us, and not in backups.
- ✓AES encryption for data at rest, including database backups
- ✓SSL/TLS encryption for all data in transit
- ✓Passwords salted and hashed — never stored or logged in plain text
- ✓Encrypted object storage for course media and learner uploads
Access control
Least privilege, enforced with MFA
Access to production infrastructure requires multi-factor authentication and is restricted to named, authorised personnel. Access to customer data is limited to the employees who need it to provide support or troubleshoot on your behalf, and every grant is reviewed.
- ✓MFA required for all production and administrative access
- ✓Role-scoped internal access, reviewed on a recurring basis
- ✓Access revoked immediately as part of offboarding
- ✓Administrative actions logged for accountability
Application access
Role-based access control inside your academy
Acadle uses a role-based access control (RBAC) model, so each user only sees the data they are entitled to. Academies are logically isolated: users can never view data belonging to an organisation other than their own.
- ✓RBAC for admins, instructors, managers and learners
- ✓Strict tenant isolation between academies
- ✓Segmentation so departments, regions and partners see only their tracks
- ✓SSO with Active Directory or LinkedIn, plus your own app credentials
Secured infrastructure
Built on AWS and Microsoft Azure
Acadle's infrastructure runs on AWS and Microsoft Azure. Both platforms operate physical infrastructure accredited under SOC 2, ISO 27001, PCI DSS Level 1 and FISMA Moderate, giving your academy enterprise-grade hosting, redundancy and physical security by default.
- ✓Hardened cloud infrastructure on AWS and Azure
- ✓Provider infrastructure accredited under SOC 2, ISO 27001, PCI L1, FISMA Moderate
- ✓Network segmentation and firewalling between tiers
- ✓Automated backups with monitored restore procedures
Penetration testing
Independently tested, continuously verified
We commission regular penetration tests through an independent, certified third-party VAPT provider to validate our security posture and surface potential weaknesses before attackers can. Findings are triaged, owned and tracked to closure.
- ✓Regular third-party VAPT engagements
- ✓Findings triaged by severity with tracked remediation
- ✓Secure development practices and peer code review
- ✓Continuous monitoring of production systems
Vulnerability management
Patched within defined SLAs
Third-party software and services are reviewed periodically and patched on a schedule. When a vulnerability is disclosed, we assess exposure and apply fixes within pre-defined SLAs based on severity.
- ✓Periodic review of third-party dependencies and services
- ✓Severity-based patching SLAs
- ✓Dependency and configuration monitoring
- ✓Change management for production releases
Security training
Every employee trained for a cloud-first setup
All Acadle personnel complete security and data-protection training designed specifically for a cloud-hosted environment. The programme targets the everyday mistakes — phishing, credential reuse, mishandled files — that cause most real-world incidents.
- ✓Mandatory security awareness training for all personnel
- ✓Phishing and social-engineering awareness
- ✓Confidentiality obligations in every employment agreement
- ✓Documented internal security policies
Privacy & GDPR
Privacy-respecting by design
We collect only the learner data an academy needs to run, and we process it on your behalf as your data processor. Acadle follows GDPR-ready practices for consent, data-subject requests, retention and deletion.
- ✓GDPR-ready data handling and data-subject request support
- ✓Data minimisation across learner profiles and analytics
- ✓Defined retention and deletion practices
- ✓Data processing agreements available on request