Skip to main content
Security & Trust

Security at DeepTech

How we protect learner data, institution tenants, and the platform — encryption, identity, data residency, and a 24×7 security team.

Security pillars

Built on AWS, hardened in production

🔐

Encryption everywhere

TLS 1.2+ in transit. AES-256 at rest (RDS, S3, EBS). Customer-specific KMS keys available on Enterprise.

🛡️

AWS-native architecture

Deployed on AWS — multi-AZ RDS, private VPCs, security groups, AWS WAF, Shield Standard, GuardDuty, Config, CloudTrail audit logs.

🌐

Regional data residency

Pick your data centre — AWS Mumbai (ap-south-1), Bahrain (me-south-1), UAE (me-central-1), Cape Town (af-south-1), Singapore (ap-southeast-1), Frankfurt (eu-central-1).

🔑

SSO, SAML, SCIM

SAML 2.0 SSO with Google Workspace, Microsoft Entra (Azure AD), Okta, OneLogin, JumpCloud. SCIM 2.0 for automated provisioning and de-provisioning.

👥

Role-based access control

Granular roles for super-admin, institution admin, faculty, instructor, learner, observer, and custom roles. Per-tenant audit logs.

🧪

Tested by independent auditors

Annual third-party penetration test, quarterly internal scans, continuous dependency scanning, and a responsible-disclosure programme.

Operational security

SLAs, backups, and incident response

99.95% uptime SLA

Quarterly uptime credits on Enterprise plans. Multi-AZ failover for RDS and stateless services behind ALB.

Backups & restore

Daily encrypted backups with 30-day retention. Point-in-time recovery available within RPO 5 minutes / RTO 1 hour on Enterprise.

Incident response

24×7 on-call rotation. Severity-1 acknowledged within 15 minutes. Status page at status.lmseducation.in with post-mortems published.

Vulnerability management

Critical CVEs patched within 24 hours; high within 7 days. Dependency scanning on every PR via Dependabot + Snyk.

Secure SDLC

Mandatory code review, signed commits, branch protection, automated SAST + secret scanning, and pre-prod staging environments.

Endpoint & access controls

Hardware-key MFA enforced for all staff. Production access via just-in-time, audit-logged break-glass — no shared credentials.

Data handling

What we do with learner data

  • Personal data minimised by design — only what's required for learning delivery is collected.
  • Learner data is never sold, never used to train third-party models, and never shared without contractual basis.
  • Sub-processor list published and updated; institutions are notified before new sub-processors are engaged.
  • DSR (Data Subject Request) workflows for access, rectification, erasure, and portability — completed within 30 days.
  • Breach notification to institution admins within 72 hours of confirmed incident, in line with GDPR Article 33.
FAQ

Security questions, answered

Where is my data stored?

You choose at onboarding. Default for India is AWS Mumbai (ap-south-1). Other available regions: Bahrain, UAE, Cape Town, Singapore, Jakarta, Frankfurt, Ireland, and Virginia. Data does not leave the chosen region unless you explicitly enable cross-region replication.

Is data encrypted?

Yes. TLS 1.2+ in transit, AES-256 at rest. Customer-managed KMS keys (CMK) and bring-your-own-key (BYOK) available on Enterprise plans.

Do you support SSO?

Yes. SAML 2.0 with Google Workspace, Microsoft Entra, Okta, OneLogin, JumpCloud, plus generic OIDC. SCIM 2.0 provisioning and de-provisioning included on all institution plans.

What is your uptime SLA?

99.95% monthly uptime on Enterprise plans, with credits for breaches. Multi-AZ RDS and stateless services behind an ALB provide automatic failover.

How do you handle vulnerabilities?

Annual third-party penetration testing, continuous SAST + dependency scanning, and a public responsible-disclosure programme. Critical CVEs patched within 24 hours.

Do you have a status page?

Yes — status.lmseducation.in. Subscribe by email or RSS for incident updates and post-mortems.

How can I report a security issue?

Email security@lmseducation.in with details. PGP key available on request. Acknowledged within 24 hours; severity-1 issues within 4 hours.

Need our security pack?

Pentest reports, SOC-style overview, sub-processor list, and a completed CAIQ — available under NDA on request.