Defense in depth across infrastructure, application, identity, data protection, monitoring and business continuity — with the transparency your IT, security and procurement teams need.
Your organization’s learning data is important. From employee information and training records to assessments, certifications, and proprietary learning content, we understand that your LMS needs to be more than functional — it needs to be secure, reliable, and built for enterprise requirements.
Security is embedded into the way we design, develop, operate, and support our platform. We continuously review our systems, processes, and controls to identify potential risks and strengthen our security posture.
While we do not publicly disclose security-sensitive implementation details, we provide our customers with transparency into the key controls and practices we use to protect their information.
We take a defense-in-depth approach, combining secure infrastructure, application security, access controls, monitoring, data protection, business continuity, and employee security practices.
Security considerations are incorporated throughout the product lifecycle — from architecture and development through deployment, monitoring, maintenance, and continuous improvement.
Customer information is protected using appropriate technical and organizational safeguards designed to prevent unauthorized access, alteration, disclosure, or loss.
Access to systems and information is restricted based on business requirements and appropriate authorization. Privileged access is controlled and reviewed to reduce unnecessary exposure.
Our platform and supporting infrastructure are monitored to help identify unusual activity, service degradation, and potential security events so appropriate action can be taken.
Our infrastructure and operational processes are designed with availability, backup, disaster recovery, and business continuity in mind.
Confidentiality obligations, awareness training, onboarding and offboarding controls, secure device practices and periodic access reviews.
Our LMS infrastructure is designed to provide a secure and resilient foundation for enterprise learning.
The platform is hosted on enterprise-grade cloud infrastructure (GCP) with security controls covering compute, networking, storage, identity, and access management. Our cloud environment benefits from the security capabilities and certifications provided by the underlying cloud infrastructure provider.
Our infrastructure incorporates multiple layers of network protection designed to reduce unauthorized access and help defend against common network-based threats.
Customer data is backed up according to documented operational procedures designed to support recovery from accidental deletion, system failure, or other applicable events. Backup controls include appropriate protection against unauthorized access and are subject to defined retention and recovery policies.
Default posture: daily backup frequency with a 7-day retention period.
We maintain documented business continuity and disaster recovery processes designed to support the restoration of critical services following a significant disruption. RPO is by default set at 24 hours and RTO at 5 working days.
Security is incorporated into our software development and application management processes, including design, development, testing, deployment, and maintenance.
We identify, assess, prioritize, and remediate security vulnerabilities using risk-based processes. Security testing may include:
Security vulnerabilities are assessed based on their severity and potential impact, with remediation prioritized according to established risk-management procedures.
We encourage responsible reporting of potential security vulnerabilities. Security researchers, customers, and other stakeholders can report suspected vulnerabilities through our designated security contact: security@talentrayz.com.
Enterprise learning platforms often contain sensitive employee and organizational information. Strong identity and access controls are therefore a core part of our security architecture.
The LMS can support enterprise authentication and SSO using supported industry-standard protocols such as SAML 2.0 and OAuth.
MFA can be enabled for appropriate users and administrative access, subject to the customer’s configuration and subscription.
Administrators can be assigned permissions according to their responsibilities, maintaining separation of duties and restricting access to sensitive functionality.
Privileged administrative functions are protected through controlled access mechanisms and authorization requirements.
All API access is authenticated via HS256-signed JWT bearer tokens (8-hour access, 30-day refresh), with server-side revocation enforced through a Redis-backed JTI blacklist that fails closed in production — a revoked token returns 503 rather than being allowed through if the revocation store is unreachable. Authorization is role-based across eight roles with a per-tenant RBAC layer and strict tenant isolation applied by resolver middleware on every request, supplemented by TOTP multi-factor authentication and enterprise SSO via Google OAuth 2.0, Microsoft, SAML 2.0 and LDAP.
Supporting controls include Helmet security headers, layered per-IP and per-authenticated-user rate limiting on a shared Redis store, bcrypt password hashing, AES-256-GCM encryption of OAuth tokens at rest, Joi schema validation on write paths, hash-chained audit logging, and short-lived 15-minute signed URLs for all file access.
Your data belongs to you. We do not use customer data for purposes unrelated to delivering, securing, supporting, and improving the contracted services, except where otherwise expressly permitted by the applicable agreement or law.
Customer data is logically separated between customer environments according to the platform’s architecture and security controls. Access to customer information is limited to authorized personnel and systems with a legitimate business or operational requirement.
We take privacy seriously and work to ensure that personal information is handled responsibly and in accordance with applicable privacy and data protection requirements. Our privacy practices address collection and use of personal information, data processing, retention, access, deletion, sub-processors, customer responsibilities, and data subject rights where applicable. For more information, review our Privacy Policy.
We maintain monitoring and operational processes designed to help identify and respond to security and availability events. When a potential security incident is identified, it is assessed according to established incident-response procedures. Our response framework supports:
If a security incident materially affects customer data, notification will be handled in accordance with applicable law and the terms of the applicable customer agreement.
Security and availability go hand in hand. Our platform is designed with reliability and resilience in mind, using appropriate redundancy, monitoring, capacity management, backup, and recovery mechanisms. Target availability is 99.9%, and enterprise customers can receive applicable service commitments through the relevant Service Level Agreement.
Depending on the customer’s requirements and subscription, the LMS can provide enterprise security capabilities such as:
Availability of individual features may vary by product edition, configuration, or implementation.
Enterprise organizations frequently connect their LMS with HRMS, HRIS, identity providers, payroll systems, collaboration platforms, content providers, ERPs and other business applications. Our integration architecture is designed to protect data exchanged between systems through appropriate authentication, authorization, encryption, and access controls. API access is restricted according to the capabilities and permissions provided to the integration.
We recognize that security reviews are an important part of enterprise procurement. During the evaluation or contracting process, eligible customers may request additional information such as:
Certain highly sensitive technical details may be shared only under appropriate confidentiality arrangements.
If your organization has specific security, compliance, privacy, infrastructure, or data-residency requirements, our team can work with your stakeholders to address them as part of the enterprise evaluation process.