Enterprise-ready learning management
Trusted by global organizations to deliver performance-ready people
A secure and scalable learning platform
Our learning platform serves hundreds of enterprises and millions of users across the globe. Built on leading microservices architecture, our platform securely stores and utilizes millions of data points every day to support our customers 24×7, 365 days a year.
Learning Pool is committed to protecting your data
We follow information security best practices and continuously seek new ways to mitigate new security risks. And we are proud to hold multiple information security certifications.
What policies and certifications do we hold?
Our ISO27001:2013 certification number is 188806
- Commitment to Security Policy
- ISO 27001 (view a copy of our certificate)
- Cyber Essentials – Learning Pool, OnScreen
- SOC2 TYPE2 (report available on request)
What does this mean for our customers?
- Our customers – especially those with a large portion of learners working with confidential information on a daily basis – know that their data is safe and secure.
- Our customers are assured of standardized security levels and practices independently verified by a third-party auditor.
- Our customers benefit from the freedom to grow and innovate our solutions that sound information security management has given Learning Pool.
To contact our Information Security team, email [email protected].
Your data security is our priority
Third-party audits
Learning Pool has completed an independent third-party audit of its management and data systems. This audit involves a rigorous review of our technology infrastructure and operational processes, and reflects our commitment to ongoing customer security. More information on ISO 27001 is available here.
World-class data centers
Learning Pool’s physical infrastructure is hosted and managed within Amazon’s secure data centers and leverages Amazon Web Services (AWS) and Amazon Elastic Compute Cloud (EC2) technology. The data is physically stored on servers in the UK and US and backups are completed every day with a retention period of 7 daily, 4 weekly and 12 monthly database backups. For file system backups, we have a 14 day retention policy.
Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon’s data center operations have been accredited under:
- ISO 27001 and ISO 27017/8
- SOC 1, SOC 2 and SOC 3 / SSAE 16/ISAE 3402 (previously SAS 70 Type II)
- PCI DSS LEVEL 1
AWS also has given special attention in the USA and EU to comply with any new or changing regulations, such as:
- Sarbanes-Oxley (SOX)
- HIPAA
- Safe Harbor / Privacy Shield
- FISMA
- FEDRAMP
- DOD SRG
- EU Data Protection Directive (GDPR)
A full list of Amazon’s certifications is available here.
Secure transmission
All communication between Learning Pool servers and the client browser is secured using the Transport Layer Security (TLS) standard.
-
- Learning Pool supports the most relevant and secure level of TLS (currently 1.2 and above).
- The connection supports encryption using AES-256 CBC with SHA256 for message authentication and ECDHE RSA as the key exchange mechanism.
Password storage
All user passwords are hashed. “Hashing” passwords means we don’t have access to the original passwords, nor does anyone else. So even if our databases were ever compromised, every individual password would remain secure.
Penetration and vulnerability security
Learning Pool conducts annual third-party penetration testing on its systems to validate that no technical vulnerabilities have been missed. Executive summaries are available on request.
Customer stories
Customer Story
Cargill
Taking compliance to the next level by reducing seat time by 30%.
Read more
Customer Story
AXA
How one visionary company is transforming its people with the power of a skills development platform.
Read more
Customer Story
InterContinental Hotels Group
Delivering a Massive Open Online Course (MOOC) to 3,000 of IHG’s first-level leaders across the globe using Learning Pool Platform
Read more
Have a question for our security team?
Get in touch to discover how we can help