Your data security is our priority
We know trust is earned. That’s why we prioritize robust security measures to protect your business.
Our ISO27001:2022 certification number is 188806.
- Commitment to Security Policy →
- ISO 27001 Certificate →
- Cyber Essentials Certificate →
- SOC2 TYPE2 (report available on request – email [email protected])
Third-party audited
Independently verified. Not just self-reported.
Learning Pool Limited, trading as Confirm, has completed a third-party audit of its management and data systems. The audit included a rigorous review of our technology infrastructure and operational processes and reflects our commitment to ongoing customer security.
World-class data centers
Infrastructure you can trust.
Learning Pool’s physical infrastructure is hosted and managed within Amazon’s secure data centers, leveraging Amazon Web Services (AWS) and Amazon Elastic Compute Cloud (EC2) technology.
Data is physically stored on servers in the UK and US. Backups are completed daily with a retention period of 7 daily, 4 weekly, and 12 monthly database backups. For file system backups, we maintain a 14-day retention policy.
Amazon continually manages risk, undergoing regular assessments to ensure compliance with industry standards. Amazon’s data center operations are accredited under:
- ISO 27001 and ISO 27017/8
- SOC 1, SOC 2, and SOC 3 / SSAE 16/ISAE 3402
- PCI DSS Level 1
AWS maintains compliance with the following regulations:
- Sarbanes-Oxley (SOX)
- HIPAA
- Safe Harbor / Privacy Shield
- FISMA
- FEDRAMP
- DOD SRG
- EU Data Protection Directive (GDPR)
A complete list of Amazon’s certifications is available here →
Secure transmission
Every connection. Fully encrypted.
All communication between our servers and your browser is secured using the Transport Layer Security (TLS) standard.
- We support the most relevant and secure level of TLS (currently 1.2 and above)
- Connections use AES-256 CBC with SHA256 for message authentication and ECDHE RSA as the key exchange mechanism
Password security
Your passwords are yours. Only yours.
All user passwords are hashed – meaning we never have access to the original passwords, and neither does anyone else. Even in the unlikely event our databases were ever compromised, every individual password would remain secure.
Penetration and vulnerability testing
We test ourselves. So you don’t have to.
We conduct annual third-party penetration testing on all systems to validate that no technical vulnerabilities have been missed. Executive summaries are available on request – email [email protected]