DRIFTCORE
Competency at the Core
Legal

Security & Trust

How we protect your data.

Last updated: June 2026

We know your training and competency records support safety-critical decisions. This page summarises how DriftCore protects your data. For processing details, see our Privacy Policy and Data Processing Agreement.

Access control & authentication

  • •Role-based access control across six roles (Super Admin, Company Admin, Site Admin, Trainer, Supervisor, Employee).
  • •Least-privilege access — users only see data appropriate to their role and site.
  • •Passwords stored using strong one-way hashing (bcrypt); we never store plaintext passwords.
  • •Session tokens with server-side revocation, so access can be cut off immediately.
  • •Rate limiting to defend against brute-force login attempts.

Multi-tenant isolation

Every company's data is logically isolated and scoped by company and site. Access controls are enforced on every request, so one customer can never reach another customer's data — even by tampering with requests.

Encryption

Data is encrypted in transit (TLS/HTTPS) and at rest within our cloud infrastructure.

Backups & disaster recovery

  • •Automated snapshots every 6 hours, plus daily, weekly and monthly full backups.
  • •Backups are stored separately from the live database.
  • •Optional immutable, write-once (WORM) off-site mirror using AWS S3 Object Lock.
  • •Regular integrity checks and automated test-restores prove backups are recoverable.
  • •A documented disaster-recovery runbook with defined recovery-point and recovery-time targets.

Auditability

Security-relevant actions — logins, permission and password changes, and record changes — are recorded in audit logs to support investigation and provide compliance evidence.

Segregation of secrets

Infrastructure credentials and secrets remain on the backend and are never exposed to the browser or to platform users.

Responsible disclosure

Found a security issue? Please email security@driftcore-lms.com with details. We investigate all good-faith reports and ask that you avoid accessing or modifying other users' data while testing.

Ongoing improvement

We continually improve our security posture. Enterprise customers can request our current security overview; formal third-party attestations (such as SOC 2) are on our roadmap.

Security is a shared responsibility: DriftCore secures the platform; Customers are responsible for managing their users, roles and credentials appropriately.