Security & Trust
How we protect your data.
We know your training and competency records support safety-critical decisions. This page summarises how DriftCore protects your data. For processing details, see our Privacy Policy and Data Processing Agreement.
Access control & authentication
- •Role-based access control across six roles (Super Admin, Company Admin, Site Admin, Trainer, Supervisor, Employee).
- •Least-privilege access — users only see data appropriate to their role and site.
- •Passwords stored using strong one-way hashing (bcrypt); we never store plaintext passwords.
- •Session tokens with server-side revocation, so access can be cut off immediately.
- •Rate limiting to defend against brute-force login attempts.
Multi-tenant isolation
Every company's data is logically isolated and scoped by company and site. Access controls are enforced on every request, so one customer can never reach another customer's data — even by tampering with requests.
Encryption
Data is encrypted in transit (TLS/HTTPS) and at rest within our cloud infrastructure.
Backups & disaster recovery
- •Automated snapshots every 6 hours, plus daily, weekly and monthly full backups.
- •Backups are stored separately from the live database.
- •Optional immutable, write-once (WORM) off-site mirror using AWS S3 Object Lock.
- •Regular integrity checks and automated test-restores prove backups are recoverable.
- •A documented disaster-recovery runbook with defined recovery-point and recovery-time targets.
Auditability
Security-relevant actions — logins, permission and password changes, and record changes — are recorded in audit logs to support investigation and provide compliance evidence.
Segregation of secrets
Infrastructure credentials and secrets remain on the backend and are never exposed to the browser or to platform users.
Responsible disclosure
Found a security issue? Please email security@driftcore-lms.com with details. We investigate all good-faith reports and ask that you avoid accessing or modifying other users' data while testing.
Ongoing improvement
We continually improve our security posture. Enterprise customers can request our current security overview; formal third-party attestations (such as SOC 2) are on our roadmap.