Trust centre
A security vendor that passes its own review
Two independent isolation layers, encryption everywhere, and the certifications your procurement team asks for — documented here so your questionnaire takes an afternoon instead of a fortnight.
Architecture
Two enforcement layers, not one
Multi-tenancy is where SaaS platforms leak. SafeLoop scopes every query in the application and then makes the database refuse anything that slips through.
Isolation
A bug in the app is not a data breach
Organisation scope is bound to the execution context when a request is authenticated, and applied at the repository layer rather than passed around as an argument that a developer can forget. Postgres row-level security then enforces the same boundary independently.
- Scope applied below the query builder, not in each handler
- Row-level security policies on every tenant-owned table
- Cross-tenant access by SafeLoop staff is audited and time-boxed
How we protect your data
Security by design, in specifics
No vague assurances. These are the controls, and what each one actually prevents.
Encrypted in transit and at rest
TLS 1.2+ on every connection, encrypted storage and snapshots, secrets held in a managed vault with rotation — never in code, config or logs.
- TLS 1.2+ enforced
- Envelope encryption at rest
- No secrets in application logs
We never store submitted passwords
When someone types a password into a simulated login page, the event is recorded and the person is coached. The characters are discarded at the collector before anything is written.
- Event recorded, credential discarded
- Enforced in code, not policy
- Verified in penetration testing
SSO, MFA and least privilege
SAML and OIDC single sign-on, enforced MFA for every admin role, and role-based access control checked on every action rather than every page.
- Enforced admin MFA
- RBAC per action
- Session and device revocation
Access ends when employment does
SCIM and directory sync deprovision in the same cycle your IdP does, so a leaver cannot log in after their last day.
- 15-minute sync interval
- Immediate deprovision on IdP removal
- Orphaned-account report
Immutable audit log
Every administrative and security-relevant action is appended to a tamper-evident log, exportable for your auditors and streamable to your SIEM.
- Append-only
- Signed webhook stream
- 13-month default retention
You choose the region
EU (Ireland), UK (London) or US (Virginia), selected per tenant at provisioning. Data does not cross the boundary for processing or backup.
- Regional isolation
- Region-local backups
- Published subprocessor list per region
Trust & compliance
Audited, certified, and mapped
The frameworks SafeLoop is assessed against — and the ones your academy content is mapped to for your own audit.
SafeLoop is audited against
Your training evidence is mapped to
- NIST CSF 2.0PR.AT
- HIPAA§164.308(a)(5)
- PCI DSS v4.012.6.3
- GDPRArt. 39
- ISO 27001A.6.3
- SOC 2CC2.2
Controls
Programme controls in detail
| Control area | Implementation | Evidence available |
|---|---|---|
| Penetration testing | Annual third-party test plus targeted tests on major releases | Executive summary under NDA |
| Vulnerability management | Continuous dependency and image scanning; critical patched within 7 days | Policy + remediation SLAs |
| Secure development | Mandatory review, CI security gates, no direct production access | SDLC policy |
| Business continuity | Multi-AZ deployment, automated backups, documented restore testing | BCP/DR summary + RTO/RPO |
| Incident response | 24/7 on-call, documented severity model, customer notification commitments in the DPA | IR policy |
| Personnel | Background checks where lawful, annual security training, least-privilege access reviews | HR security policy |
| Subprocessors | Published list, assessed before onboarding, notified in advance of changes | Live subprocessor register |
Full policy documents and the SOC 2 Type II report are available under NDA through the trust centre.
Documentation
Everything for your review
What we can send you today, and how to ask for it.
Need something for your questionnaire?
Tell us which framework you assess against and we will send the mapped evidence pack — usually the same working day.