Skip to main content
DSA Home

For Due Diligence Teams

Security and data protection

Everything on this page is a statement of what the platform does today. Where we have not yet done something, it says so. If you are running supplier due diligence and need something that is not here, email admin@digitalskillsassessment.co.uk and we will answer it directly rather than send you a brochure.

Where your data lives

Learner data is stored in the European Union, in Amazon Web Services' Dublin, Ireland region, through our database provider Supabase. Transactional email is sent through Mailgun's EU infrastructure. Storage within the EU is permitted under UK GDPR through the UK's adequacy arrangements with the EEA.

Our sub-processors are: Vercel (application hosting), Supabase (database and authentication, AWS Dublin), Mailgun (transactional email, EU infrastructure), Stripe (payment processing), Sentry (error monitoring) and Google Analytics (website analytics, with consent). A Data Processing Agreement is available on request.

Who can get in

  • Multi-factor authentication is enforced for administrator and organisation-admin accounts, using time-based one-time passcodes from any standard authenticator app. It is available to every other user as an option.
  • Role-based access control governs what each member of your organisation can see and do.
  • An organisation admin can suspend a member themselves, and doing so revokes that person's live sessions immediately rather than waiting for a token to expire. The action is reversible and is recorded in the audit log.
  • Organisation admins can generate, rotate and revoke API credentials without downtime. Secrets are shown once and stored hashed.

Keeping organisations separate

Every organisation's data is isolated at the database level using row-level security, and that isolation is enforced again at the API boundary rather than relying on the database alone. A request for another organisation's record returns a 404, never a response that confirms the record exists.

What we record

Every API call is logged with the key used, the endpoint, the records touched, the timestamp and the response code. Significant in-platform actions, including role changes, password resets, result exports and account suspensions, are logged too. These logs are retained for six years, which is both the security trail and the evidence trail a funding audit asks for.

Learner personal data

  • National Insurance numbers are not stored and are never returned by any endpoint.
  • No personal data appears in URLs or query strings. Records are filtered by opaque identifiers and your own learner references.
  • When an assessment record is deleted, personally identifying information is wiped while score data is retained for credit accounting.
  • Data is encrypted in transit and at rest. Webhook signing secrets are additionally encrypted at rest under a separate application key, so a database-only compromise cannot forge a delivery signature.

How the software is built

  • A software bill of materials is generated on every build, so we know exactly what third-party code ships.
  • Dependency vulnerabilities are monitored continuously and production dependencies currently report no known vulnerabilities.
  • Automated accessibility and security checks run in continuous integration on every change; a regression fails the build before release.
  • Build workflows run with least-privilege permissions and pinned action versions.

Reporting a vulnerability

We publish a vulnerability disclosure policy and a security.txt. We acknowledge reports within three working days and will not pursue legal action against good-faith security research conducted within the policy. Read the policy.

What we do not yet have

We would rather tell you this than have you discover it.

  • Cyber Essentials: not yet certified. We are working to the v3.3 requirements and intend to certify.
  • ISO 27001 / SOC 2: not held.
  • Third-party penetration test: not yet commissioned. Our current assurance is automated scanning, dependency monitoring and internal review.
  • Accessibility: we publish a WCAG 2.2 AA statement of partial conformance, with a dated remediation roadmap rather than a claim of full compliance. See our accessibility statement.
  • Uptime: we do not currently offer a contractual uptime SLA.

If any of these is a hard requirement for your organisation, tell us. It helps us prioritise, and we would rather know before you spend time on an evaluation.

For your procurement questionnaire

One-line answers to the questions supplier questionnaires usually ask. Each is expanded on above, and you are welcome to copy them straight into your paperwork.

Where is our data stored?
In the European Union: Amazon Web Services' Dublin, Ireland region, via our database provider Supabase, with transactional email sent through Mailgun's EU infrastructure.
Is our data encrypted?
Yes. Data is encrypted in transit and at rest, and webhook signing secrets are additionally encrypted at rest under a separate application key.
Who are your sub-processors?
Vercel (application hosting), Supabase (database and authentication, AWS Dublin), Mailgun (transactional email, EU infrastructure), Stripe (payment processing), Sentry (error monitoring) and Google Analytics (website analytics, with consent). A Data Processing Agreement is available on request.
Do you enforce multi-factor authentication?
Yes. MFA is enforced for administrator and organisation-admin accounts using time-based one-time passcodes, and is available as an option to every other user.
How is access revoked?
Suspending a member revokes that person's live sessions immediately and is recorded in the audit log, and API credentials can be rotated or revoked without downtime.
What is your breach notification commitment?
We operate under UK GDPR: notifiable personal data breaches are reported to the ICO within 72 hours of us becoming aware, and affected organisations are informed without undue delay.
What audit logs can we access, and for how long?
Every API call and significant in-platform action is logged, and logs are retained for six years, covering both the security trail and the evidence trail a funding audit asks for.
What happens to our data if you cease trading?
You can export your complete assessment record, including evidence PDFs, at any time through the Evidence Pack Export, without our involvement.
Do you hold Cyber Essentials?
Not yet. We are working to the Cyber Essentials v3.3 requirements and intend to certify; see the 'What we do not yet have' section of our security page.

Related reading: privacy policy, integrations, Evidence Pack Export and accessibility statement. Questions this page does not answer go to admin@digitalskillsassessment.co.uk.

Last updated: 4 August 2026

We use cookies to analyse site usage and improve our service. See our Privacy Policy for details.