Skip to content
Edukatic edukatic Enterprise Edition Book a 30-min demo →

Security & Compliance · Trust Document

Security & compliance, written like an audit report.

Edukatic is engineered for procurement-grade review. We hold a current SOC 2 Type II report and an active ISO 27001 certification, both renewed annually. Our GDPR posture is documented under a customer-signed DPA, and our data-handling boundaries are modelled on the CIS Critical Security Controls.

This page is the index an IT, security, or procurement reviewer needs before a conversation with sales: every attested control, every audit cadence, and every artefact you can request under NDA.

Document v2025.03 · Owner: Trust & Security Office · Audit window: Oct 2024 – Sep 2025 · Reviewed by an independent Big Four firm.

§ 01 · Index of attested controls

Every certification, framework, and standard in one scannable list.

Procurement and IT security teams told us they wanted one place to see exactly what is documented below. This is that place. Each line links to the detailed section, the audit artefact available under NDA, and the cadence at which it is re-attested.

  1. SOC 2 Type II

    Independent audit of Security, Availability, Processing Integrity, Confidentiality, and Privacy Trust Services Criteria. Renewed annually; current report covers Oct 2024 – Sep 2025.

  2. ISO/IEC 27001:2022

    Certified Information Security Management System (ISMS) covering the platform, corporate IT, and supporting infrastructure. Re-certification audit every 12 months; surveillance audits every 6 months.

  3. GDPR & UK GDPR

    Data Processing Agreement executed per customer; Standard Contractual Clauses (2021/914) for EEA transfers; UK International Data Transfer Addendum in place. Data Protection Officer appointed under Art. 37.

  4. xAPI 1.0.3 & SCORM 2004 4th Edition

    Open, native ingest and export of learner experience data. No proprietary lock-in. One-click migration from legacy LMS exports; full statement of conformance available on request.

  5. Annual third-party penetration testing

    External network, web application, and cloud configuration tests performed by an independent CREST-accredited firm. Executive summary redacted and shareable under NDA.

  6. CIS Critical Security Controls v8

    Internal control framework aligned to the CIS Implementation Group 1 (IG1) baseline as a minimum, with IG2 controls applied to production data planes.

§ 02 · Pillar-by-pillar evidence

The five controls a security review will actually dig into.

Each pillar below is written as a labelled, auditable claim: scope, cadence, evidence, and the named artefact a CISO or IT procurement lead can request.

Pillar 01

SOC 2 Type II — full TSC coverage

Report scope: production SaaS platform hosted on AWS Frankfurt and AWS Ireland, supporting corporate IT in Lisbon, and the customer-success tooling used to operate the service. Trust Services Criteria covered: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Audit window: a continuous 12-month period, renewed annually. Auditor: a Big Four firm engaged directly by Edukatic, with no management influence over the test programme.

Cadence
Annual re-attestation
Artefact
SOC 2 Type II report
Access
Under NDA, via the Trust Portal

Pillar 02

ISO 27001 ISMS

Certified ISMS scoped to the platform, the corporate environment, and the people operating them. Statement of Applicability covers 93 Annex A controls.

Cadence
12-month re-cert + 6-month surveillance
Artefact
ISO 27001 certificate & SoA

Pillar 03

GDPR & data-subject rights

Customer-signed DPA with SCCs (2021/914) and the UK Addendum. Documented runbooks for access, rectification, erasure, portability, and objection within 30 days.

Cadence
Continuous; DPIA on every new feature
Artefact
DPA + Privacy Notice

Pillar 04

Regional data residency

Customer choice of EU (Frankfurt, Ireland), US (Virginia, Oregon), or UK (London) processing region at contract signature. Pinning enforced at the tenant layer; cross-region replication disabled by default.

Cadence
Set at provisioning; audited quarterly
Artefact
Region pinning attestation

Pillar 05

Open xAPI & SCORM-2004 — no lock-in

Native ingest and export of learner experience data via xAPI 1.0.3 and SCORM 2004 4th Edition. Statement of Conformance and one-click migration tooling from legacy LMS exports (Cornerstone, SuccessFactors, Workday Learning, SAP Litmos) available on request. Customers retain full ownership of their learning records; export is a documented feature, not a professional-services engagement.

Cadence
Version-locked; refreshed on standards updates
Artefact
SoC + sample LRS export
Migration
One-click from legacy LMS

§ 03 · Operational practice

How we actually operate, in the language a CAIQ or SIG Lite questionnaire expects.

Short answer. AES-256 encryption at rest, TLS 1.3 in transit, role-based access with SAML 2.0 and OIDC SSO, 24/7 incident response with a one-hour critical-severity ack SLA, and quarterly third-party penetration tests. Below: the detail.

Cryptography & key management

All customer data is encrypted at rest using AES-256, with AWS KMS-managed customer master keys. Per-tenant data encryption keys are rotated at least every 12 months and on any personnel change affecting key custodians. Data in transit uses TLS 1.3 with modern cipher suites only; HTTP/2 and HTTP/3 supported. Certificate management is automated through ACM with external monitoring of expiry.

Identity, authentication & authorisation

Role-based access control with the principle of least privilege, scoped to the learner, the L&D admin, and the platform operator personas. SAML 2.0 and OpenID Connect single sign-on are supported with any IdP that implements the standards (Okta, Microsoft Entra ID, Google Workspace, Ping). Privileged access to production is gated by hardware-backed MFA and just-in-time elevation through a PAM workflow with full session capture.

Network & infrastructure

Production runs on AWS in isolated VPCs with private subnets for data planes. Edge traffic terminates at AWS WAF and CloudFront with managed rule sets and custom rules for application-layer threats. Infrastructure is defined as code (Terraform), with peer-reviewed change control and automated drift detection. CIS Benchmark-hardened AMIs are rebuilt every 30 days.

Vulnerability management & pen testing

Authenticated vulnerability scans run weekly against the full external attack surface and daily against container images. A CREST-accredited third party performs an external penetration test annually, with a web-application focus. Findings are triaged within five business days and tracked to closure in our risk register with executive-level visibility. A public bug-bounty programme is operated via a major platform with responsible-disclosure terms published.

Incident response & business continuity

A documented incident-response plan is tested at least twice per year (tabletop + live drill). Critical-severity incidents are acknowledged within one hour, with status-page updates within two hours of confirmation. RTO is 4 hours; RPO is 1 hour for the production data plane, validated through quarterly game-day failover exercises.

People & governance

All employees and contractors undergo background screening appropriate to their role, sign confidentiality and acceptable-use agreements, and complete annual security and privacy training with comprehension checks. The Trust & Security Office reports to the CTO and has a direct line to the Audit Committee of the Board.

A redacted CAIQ v4 and SIG Lite are available under NDA. Request both via the Trust Portal linked below.

§ 04 · Third-party validation

Abstract certifications, translated into recognition a CFO or CISO will already know.

2024 Forrester Wave™ for Learning Experience Platforms

Named a Leader. Personalization score: 4.7 / 5.

Brandon Hall Group, 2023 Excellence Award

Winner — Best Advance in Learning Technology.

Customer NPS, Q1 2025

67, measured across the enterprise book of business.

Inc. 5000 Europe — 2022, 2023, 2024

Three consecutive years on Europe's fastest-growing list.

Independent audits and analyst recognition are not marketing. They are records. We are happy to send each artefact, in full and under NDA, before a contract is signed.

Step 01 · Pull the audit pack

Request the audit & compliance pack.

Send the SOC 2 Type II report, ISO 27001 certificate and Statement of Applicability, the executed DPA with SCCs, the latest pen-test executive summary, and the CAIQ v4 / SIG Lite — together, under a single NDA. Delivered by a named contact in the Trust & Security Office, usually within one business day.

Request the audit pack →

[email protected] · +351 21 098 4421 · Trust Portal (NDA-gated)

Step 02 · See it in your context

Book a 30-min demo.

Walk through the platform with a solutions engineer who has run enterprise rollouts for 500 to 20,000 employees. Bring your security questionnaire live — we will answer on the call or escalate to the Trust & Security Office the same day.

Book a 30-min demo →

No-cost · No-obligation · NDA available on request before the call.