§ 03 · Operational practice
How we actually operate, in the language a CAIQ or SIG Lite questionnaire expects.
Short answer. AES-256 encryption at rest, TLS 1.3 in transit, role-based access with SAML 2.0 and OIDC SSO, 24/7 incident response with a one-hour critical-severity ack SLA, and quarterly third-party penetration tests. Below: the detail.
Cryptography & key management
All customer data is encrypted at rest using AES-256, with AWS KMS-managed customer master keys. Per-tenant data encryption keys are rotated at least every 12 months and on any personnel change affecting key custodians. Data in transit uses TLS 1.3 with modern cipher suites only; HTTP/2 and HTTP/3 supported. Certificate management is automated through ACM with external monitoring of expiry.
Identity, authentication & authorisation
Role-based access control with the principle of least privilege, scoped to the learner, the L&D admin, and the platform operator personas. SAML 2.0 and OpenID Connect single sign-on are supported with any IdP that implements the standards (Okta, Microsoft Entra ID, Google Workspace, Ping). Privileged access to production is gated by hardware-backed MFA and just-in-time elevation through a PAM workflow with full session capture.
Network & infrastructure
Production runs on AWS in isolated VPCs with private subnets for data planes. Edge traffic terminates at AWS WAF and CloudFront with managed rule sets and custom rules for application-layer threats. Infrastructure is defined as code (Terraform), with peer-reviewed change control and automated drift detection. CIS Benchmark-hardened AMIs are rebuilt every 30 days.
Vulnerability management & pen testing
Authenticated vulnerability scans run weekly against the full external attack surface and daily against container images. A CREST-accredited third party performs an external penetration test annually, with a web-application focus. Findings are triaged within five business days and tracked to closure in our risk register with executive-level visibility. A public bug-bounty programme is operated via a major platform with responsible-disclosure terms published.
Incident response & business continuity
A documented incident-response plan is tested at least twice per year (tabletop + live drill). Critical-severity incidents are acknowledged within one hour, with status-page updates within two hours of confirmation. RTO is 4 hours; RPO is 1 hour for the production data plane, validated through quarterly game-day failover exercises.
People & governance
All employees and contractors undergo background screening appropriate to their role, sign confidentiality and acceptable-use agreements, and complete annual security and privacy training with comprehension checks. The Trust & Security Office reports to the CTO and has a direct line to the Audit Committee of the Board.
A redacted CAIQ v4 and SIG Lite are available under NDA. Request both via the Trust Portal linked below.