TrainSec 

Security & Compliance

TrainSec is committed to protecting the information of our students and enterprise customers. This page summarizes the security and compliance practices we maintain.

Security Infrastructure

  • Encryption: Data is encrypted in transit over HTTPS, and our platform providers encrypt stored data at rest using industry-standard encryption.
  • Payments: Payments are processed by Stripe, a PCI DSS certified payment provider. TrainSec does not store card numbers.
  • Course platform: Courses and student accounts are delivered through Podia. Each customer account is logically separated, so one customer cannot access another customer’s data.
  • Backups: Business data is backed up automatically, and backups are tested at least annually.
  • Vulnerability management: Systems are kept up to date, scanned for vulnerabilities, and patched on a regular schedule. Anti-malware protection is enforced on company systems.

Access & Authentication

  • Multi-factor authentication (MFA) is required for access to company systems and administrative accounts.
  • Access follows a least-privilege, need-to-know model and is reviewed at least annually.
  • Remote and mobile work is governed by a secure remote work policy.

Internal Governance & Employee Security

  • Security leadership: Pavel Yosifovich is the designated Information Security Lead.
  • All employees, contractors and partners sign confidentiality agreements (NDAs).
  • Background screening is performed on all employees.
  • All staff complete security awareness and data protection training.
  • Security guidelines and access policies are reviewed annually.

Data Protection & Privacy

  • We honor data subject rights under GDPR and CCPA (access, correction, export and deletion). Requests: [email protected].
  • Third-party providers are vetted before use and bound by Data Processing Agreements (DPAs).
  • We maintain documented procedures for detecting, handling and reporting security incidents and personal data breaches.
  • See our Privacy Policy for details.

Business Continuity & Disaster Recovery

  • Our services rely on highly available cloud platforms.
  • Automated backups and a documented contingency and disaster recovery plan support continuity of service during unexpected disruptions.

Ethics & Compliance

  • We comply with applicable labor laws and core labor standards, including non-discrimination and a zero tolerance policy for harassment, forced labor and child labor.
  • We are not listed on any national or international sanctions list, and we maintain anti-corruption and anti-bribery standards.
  • We cooperate with reasonable customer risk and integrity assessments.

Contact

Security and compliance questions: [email protected]. Privacy requests: [email protected].

blue depth