Security Policy
Updated 2026-09-09
This policy describes how Shog Corporate Training is protected, in enough detail for a customer's IT or compliance reviewer to judge it. It also states plainly what we do not claim. It is for customer organisations, their reviewers, and anyone completing a security questionnaire about us.
Encryption
In transit. Traffic between your browser and the service is encrypted with TLS. Session and handshake cookies are marked secure in production, so they are not sent over an unencrypted connection.
At rest. Learner names, email addresses and phone numbers are encrypted with AES-256-GCM before they are stored. AES-256-GCM is an authenticated cipher, so a ciphertext that has been tampered with fails to decrypt rather than returning altered data.
Per-organisation keys. Each organisation has its own data keys. Ciphertext written for one organisation cannot be read with another organisation's key, so a key compromise is bounded by the organisation it belongs to.
Key management. Keys are managed in OCI Vault in production. Application servers obtain what they need to decrypt at runtime; long-lived key material is not stored beside the data it protects.
Searchable encrypted fields. Where an encrypted field has to be looked up, for example finding an attendee by email address, the lookup uses a keyed one-way digest rather than a plaintext copy of the value.
Database separation
There is a central platform database holding accounts and subscriptions, a shared course catalogue holding no personal data, and a separate database for each customer organisation holding that organisation's learner records.
Your learners' records are physically separated from every other customer's. This is our primary tenancy control, and it is stronger than a filter on a shared table: a query runs against your database, and your database contains only your data. A missing filter cannot leak another customer's records because another customer's records are not there to return.
Authentication
Administrators sign in with an email address and password, with an optional TOTP second factor, or with Google or Microsoft sign-in. Passwords are stored as hashes, never in a recoverable form. Where TOTP is enabled, the secret is held encrypted. We recommend enabling TOTP on every administrator account, and using an individual account per person rather than a shared one.
Learners hold no password. A learner receives a private link by email and confirms it with a one-time code sent to the same address. The absence of a learner password removes a large class of risk: there is no learner credential to reuse from another breach, and none to phish for later.
Magic links and codes expire. A magic link is issued with an expiry and stops working after it. The one-time code that confirms it is valid for minutes only. Learner portal sessions and administrator sessions are both time-limited and end on sign-out. The link stored on our side is held encrypted rather than in the clear.
OAuth handshakes are state-bound. A sign-in with Google or Microsoft, and the consent flow that connects an organisation's SharePoint, OneDrive or Google Drive, each carry a signed, short-lived, single-use state value in a cookie. A callback that does not match the request that started it is rejected, and a replayed callback connects nothing the second time.
Access control
Access to a workspace is scoped to the organisation. Administrative roles determine what an administrator can do within it.
Auditor preview access is granted by you, to a named auditor, for a limited time, and can be revoked. Every grant and revocation is recorded.
On our side, access to customer data is limited to the personnel who need it in order to run and support the service, on the principle of least privilege, and those people are bound by confidentiality obligations. Administrative actions are recorded.
Audit logging
Each organisation has its own event log, recording the actions that matter for evidence: enrolments, completions, certificate issue and revocation, storage connection changes, auditor grants and revocations, administrator sign-ins and administrative changes.
The log belongs to your organisation, lives in your organisation's database, and is included in your data export. You do not have to ask us for it.
Your files, and the storage you connect
Where you connect your own Microsoft SharePoint, OneDrive or Google Drive, certificates, identity photographs and signed declarations are written there and not to us. We hold the evidence record, never the file. That is a security property as much as a storage one: the most sensitive artefacts, including facial images, can be kept entirely inside your own tenant, under your own controls.
Connecting storage is a precondition of enrolling anyone, so there is no case in which we hold those files instead.
Access tokens for a connected storage provider are held encrypted, and the scopes we request are the minimum needed to write and read the organisation's own folder.
Payments
Payments run through Stripe. Card details are entered into Stripe and held by Stripe. We do not see, receive or store card numbers, and no card number exists on our systems.
Transactional email, which carries magic links, one-time codes, enrolment notices and reminders, is sent through Microsoft 365 Graph.
Email is the channel by which a learner reaches their training, so treat learner mailboxes accordingly: a compromised mailbox is a route to that learner's training record.
Backups
Backups are taken so that a failure does not lose your training evidence. They are retained on their own rotation and are overwritten in the ordinary course.
Data deleted from the live service can persist in a backup that has not yet aged out, and it goes when that backup expires. We do not restore individual records out of a backup to undo a deletion.
We do not publish a recovery point objective or a recovery time objective, because we have not committed to one.
Hosting
The application, the platform database, each organisation's database, the key vault and our own object storage of course material run on Oracle Cloud Infrastructure in the Middle East region.
Where you connect your own SharePoint, OneDrive or Google Drive, the location of the files written there is determined by your own tenant, not by us. Stripe processes payment data in Ireland and the United States. The Sub-processors page carries the full list.
Vulnerability reports
If you find a security issue, tell us at training@shogconsulting.com. Our Vulnerability Disclosure policy sets out scope, safe harbour and response times. Good-faith research within that scope is welcome and will not be treated as a breach of the Acceptable Use Policy.
Incidents
If we become aware of a personal data breach affecting data we process for a customer, we notify that customer's account contacts without undue delay, with what we know at the time and further detail as the investigation progresses. Notifying a supervisory authority or the affected individuals is the customer's decision as controller. The Data Processing Agreement sets out the mechanics.
Give us a dedicated security contact if you have one, and keep it current.
What we do not claim
We would rather be believed on the paragraphs above than pad this page with assurances we cannot evidence. So, plainly:
- We hold no independent security certification. We are not ISO 27001 certified. We do not hold a SOC 2 report, Type 1 or Type 2. We do not hold PCI DSS certification, and we do not need to hold card data because Stripe holds it. If we obtain a certification, this page will say so and will name the scope and the auditor. Until then, treat any claim to the contrary as wrong, wherever you saw it.
- We publish no uptime percentage and give no availability guarantee on this page. Any availability commitment is the one recorded on your order form, and none is implied here.
- We publish no penetration test cadence or report. Where your policy requires an independent test, raise it before purchase so that scope and terms can be agreed and recorded on your order form.
- We publish no insurance position. If cyber or professional indemnity cover is relevant to your procurement, ask, and any position agreed will be recorded on your order form.
- We publish no headcount, staffing model or internal training statistics.
- UAE data protection regulation is incomplete. Federal Decree-Law No. 45 of 2021 is in force, but its Executive Regulations have still not been issued, so the compliance clock in Article 29 has not started and several operational requirements are not yet defined in binding text. We describe what we do rather than claim compliance with rules that do not yet exist. Customers in DIFC or ADGM are under different regimes with their own supervisors.
Questions and security questionnaires
Send security questions, and questionnaires, to training@shogconsulting.com. We will answer what we can, and where the honest answer is that a control is not in place, we will say so rather than tick the box.
Shog Corporate Training is operated by Shog Consulting (FZC), licence SC242038101, STRIP Block C VL07-017, Sharjah, United Arab Emirates.
This document is published in English. Published by Shog Consulting (FZC), licence SC242038101. Questions go to training@shogconsulting.com.
