Site policies

Acceptable Use Policy

What a workspace may not be used for, including sitting an assessment for somebody else.

Updated 2026-09-09

This policy sets out what a workspace on Shog Corporate Training may and may not be used for. It applies to the customer organisation that holds the account, to its administrators, to its learners and to any auditor it grants access to. Breaking it can cost a certificate, an account, or both.

Why this policy is short and specific

A training certificate is only worth something if the record behind it is honest. Most of the rules below exist to protect that. If a certificate from this platform can be obtained by someone who did not do the training, then every certificate on the platform is worth less, including yours.

Integrity of training and assessment

These are the rules that matter most here.

Do not share a magic link. A learner's access link is emailed privately and confirmed with a one-time code. It identifies that learner. Forwarding it, posting it, or handing your device to somebody else while it is open means the record no longer says what it appears to say. Treat a magic link the way you would treat a password.

Do not sit an assessment for another person. Taking a course, answering questions or completing an identity step on somebody else's behalf is impersonation. So is asking somebody to do it for you, and so is instructing a member of staff to do it for a colleague.

Do not try to obtain a certificate without completing the course. That includes skipping content by manipulating the player, tampering with progress or completion data, automating answers, calling the platform's internal endpoints directly to mark progress, or any other route to a completion record that does not reflect a person who actually did the work.

Do not falsify identity evidence. The completion photograph must be of the person named on the enrolment, taken at the time it is requested. A signed identity declaration must be signed by that person. Substituting a photograph of somebody else, presenting an image of an image, or signing for a colleague makes the evidence worthless and the certificate revocable.

Do not alter or forge a certificate. Do not edit a certificate document, reproduce it in a way that misstates what it says, or present a certificate as covering a course, a person, a date or a scope that it does not cover. Use the verification page to prove a certificate instead.

Do not share assessment content. Do not copy, record, publish or circulate assessment questions or answers, whether inside your organisation or outside it.

Personal data

Do not upload personal data beyond what the training requires. The platform needs a learner's name, work email address and, if you choose, a phone number and job details. It does not need Emirates ID numbers, passport scans, health records, salary information, family details or anything else that arrives because it happened to be in a spreadsheet you already had. Do not paste such information into free-text fields, attendee notes or support messages.

Enrol only people you are entitled to enrol. You are the controller of your learners' data. Enrol your own staff, and people you have a lawful basis to train and to record. Tell them what is happening; our Learner Privacy Notice is written so you can hand it to them unchanged.

Grant auditor access deliberately. Preview access exposes real people's training records. Grant it to a named auditor for as long as it is needed, and revoke it when the work is done.

Verification endpoint

Public certificate verification exists so that a client, a regulator or a prospective employer can check one certificate. It takes no account by design.

Do not scrape it. Do not enumerate certificate numbers, run bulk or automated queries against it, or build a service on top of it. Automated and high-volume access will be rate limited and may be blocked at network level.

Legitimate bulk verification exists: if you need to confirm many certificates, export your own data, or ask us at training@shogconsulting.com.

The platform itself

Do not:

  • attempt to access another organisation's workspace, data or files, or a workspace you have not been granted access to;
  • probe, scan or test the security of the service other than under our Vulnerability Disclosure policy;
  • interfere with the service, its availability or its integrity, including through denial of service, excessive automated requests or resource abuse;
  • reverse engineer, decompile or attempt to extract the source of the service, except to the extent that this cannot lawfully be prohibited;
  • copy, redistribute, resell or republish course content. Courses are our intellectual property and are licensed for your staff to take, not for you to distribute;
  • share administrator credentials between people. Give each administrator their own account, and enable TOTP where you can;
  • use the platform to store or send unlawful material, malware, or content that infringes somebody else's rights;
  • use the platform to harass anyone, or to send messages that have nothing to do with training;
  • misrepresent the platform, for example by presenting it as accredited or as a licence issuer. See the Certificates and Verification policy for what a certificate does and does not assert.

What you must do

  • Keep your administrator list current, and remove people who have left.
  • Keep your billing and security contact addresses current, because that is where notices go.
  • Tell us promptly at training@shogconsulting.com if you believe an account has been compromised, a magic link has been misused, or a certificate has been obtained dishonestly.
  • Comply with the laws that apply to you when you use the platform, including data protection law and your own regulator's rules.

Consequences

We would rather fix a problem than close an account. What we do depends on what happened.

  • We may contact you. For most issues, the first step is a message to your administrators asking you to put it right.
  • We may suspend a learner's access. Where a magic link has been shared or an assessment appears to have been taken by somebody else.
  • We may revoke a certificate. Where a certificate was obtained without the course being completed, or where the identity evidence behind it is false. A revoked certificate shows as revoked on the public verification page. The grounds are set out in the Certificates and Verification policy.
  • We may suspend a workspace. Where the conduct is serious, is repeated, or puts other customers or the service at risk.
  • We may terminate the subscription. For a material breach that is not fixed within a reasonable period after we tell you about it, and immediately where the breach cannot be fixed or where continuing would expose us or your learners to legal risk. The Subscription and Billing Terms set out what happens to your data and to already-issued certificates in that case.
  • We may report it. Where we are legally required to, or where a serious offence appears to have been committed.

Suspension is not deletion. Your data is not deleted because of a suspension, and the retention and export rules in the Data Retention and Deletion policy continue to apply.

Reporting a problem

To report misuse, a suspected forged certificate, or an account you believe has been compromised, write to training@shogconsulting.com. Tell us the organisation, the certificate number if there is one, and what you saw.

To report a security vulnerability, use the Vulnerability Disclosure policy instead. Testing done inside its scope and in good faith is not a breach of this policy.

This document is published in English. Published by Shog Consulting (FZC), licence SC242038101. Questions go to training@shogconsulting.com.