Security | Confirm

Your data security is our priority

We know trust is earned. That’s why we prioritize robust security measures to protect your business.

Our ISO27001:2022 certification number is 188806.

Third-party audited

Independently verified. Not just self-reported.

Learning Pool Limited, trading as Confirm, has completed a third-party audit of its management and data systems. The audit included a rigorous review of our technology infrastructure and operational processes and reflects our commitment to ongoing customer security.

Find out more about ISO 27001 here →

World-class data centers

Infrastructure you can trust.

Learning Pool’s physical infrastructure is hosted and managed within Amazon’s secure data centers, leveraging Amazon Web Services (AWS) and Amazon Elastic Compute Cloud (EC2) technology.

Data is physically stored on servers in the UK and US. Backups are completed daily with a retention period of 7 daily, 4 weekly, and 12 monthly database backups. For file system backups, we maintain a 14-day retention policy.

Amazon continually manages risk, undergoing regular assessments to ensure compliance with industry standards. Amazon’s data center operations are accredited under:

  • ISO 27001 and ISO 27017/8
  • SOC 1, SOC 2, and SOC 3 / SSAE 16/ISAE 3402
  • PCI DSS Level 1

AWS maintains compliance with the following regulations:

  • Sarbanes-Oxley (SOX)
  • HIPAA
  • Safe Harbor / Privacy Shield
  • FISMA
  • FEDRAMP
  • DOD SRG
  • EU Data Protection Directive (GDPR)

A complete list of Amazon’s certifications is available here →

Secure transmission

Every connection. Fully encrypted.

All communication between our servers and your browser is secured using the Transport Layer Security (TLS) standard.

  • We support the most relevant and secure level of TLS (currently 1.2 and above)
  • Connections use AES-256 CBC with SHA256 for message authentication and ECDHE RSA as the key exchange mechanism

Password security

Your passwords are yours. Only yours.

All user passwords are hashed – meaning we never have access to the original passwords, and neither does anyone else. Even in the unlikely event our databases were ever compromised, every individual password would remain secure.

Penetration and vulnerability testing

We test ourselves. So you don’t have to.

We conduct annual third-party penetration testing on all systems to validate that no technical vulnerabilities have been missed. Executive summaries are available on request – email [email protected]

GOT A SECURITY QUESTION?

Our security team is on hand.

Whether you’re in the middle of a procurement review or just
need a specific document – get in touch and we’ll respond quickly.

Email: [email protected]