Security & Trust

Built on enterprise-grade infrastructure.
Secured by design.

AI Bytes Learning is built on infrastructure trusted by thousands of enterprises worldwide. Your staff data is protected at every layer — from authentication to storage to payments. Our controls are implemented in line with the five control areas of the UK NCSC Cyber Essentials framework.

— Infrastructure Compliance

Vercel — SOC 2 Type II

Application hosting

Provider Certified

Supabase — SOC 2 Type II

Database & authentication

Provider Certified

Stripe — PCI DSS Level 1

Payment processing

Provider Certified

UK GDPR Compliant

Data Protection Act 2018

Compliant

Data Security

Encryption at rest

All data stored in Supabase PostgreSQL is encrypted using AES-256. Backups are encrypted by default.

Encryption in transit

TLS 1.3 enforced on all connections. HTTPS is mandatory — no unencrypted traffic permitted.

Row-level security (RLS)

Database-enforced access control. Users can only ever read their own records — no application-layer bypass possible.

Data residency

Data stored in EU (West Europe) region. UK/EU organisations can request data residency confirmation.

Access & Authentication

Secure sign-in

Password sign-in with credentials screened against known breach databases at signup, plus Google and LinkedIn OAuth. Passwords are stored only as salted hashes by Supabase Auth — never in plain text.

Multi-factor authentication

MFA available for all accounts via Supabase Auth. TOTP-based authenticator app support.

Organisation access control

Admins can manage which staff have access. Seats can be provisioned, suspended, or revoked at any time.

SSO / SAML (enterprise)

Single sign-on for enterprise identity providers (Azure AD, Okta) is on our enterprise roadmap — contact us to discuss your requirements.

Application Security

Secure API architecture

All API routes are authenticated server-side. Admin routes require elevated privileges enforced at the database layer.

Input validation

User inputs validated server-side. SQL injection protections enforced via parameterised queries. XSS mitigations applied via React's built-in escaping.

Security headers

HSTS, X-Frame-Options, X-Content-Type-Options, and Referrer-Policy enforced on all responses. Content Security Policy in progress.

Dependency management

Dependencies audited regularly. High and critical severity vulnerabilities are patched within 14 days of a fix being available — typically much sooner.

Compliance & Privacy

UK GDPR compliant

Full compliance with the UK General Data Protection Regulation and Data Protection Act 2018.

Data Processing Agreement

A signed DPA is available for enterprise customers on request. Supabase sub-processor DPA provided.

Data subject rights

Staff can request access, rectification, or deletion of their data at any time via our privacy team.

Breach notification

Confirmed breaches reported to the ICO within 72 hours. Affected organisations notified without undue delay.

What we will never do with your data

These commitments apply to all customers including enterprise licence holders.

Sell or share personal data with third parties for marketing
Use staff learning data for purposes outside the platform
Store payment card details — Stripe handles all card data
Transfer data outside the UK/EU without adequate safeguards
Use AI-generated content in place of your staff's personal data
Retain data beyond agreed periods without your consent

— Enterprise Procurement Checklist

Common procurement questions

Is a Data Processing Agreement (DPA) available?

Yes — available on request for enterprise licence holders. Contact our team.

Where is data stored geographically?

EU West (Ireland) region via Supabase. UK data residency available on request.

Do you support SSO / SAML with our identity provider?

Not yet — SSO is on our enterprise roadmap. Contact us to discuss your identity provider and timelines.

What is your uptime SLA?

Platform targets 99.9% uptime. Vercel and Supabase each publish their own SLA and status pages.

Has a penetration test been conducted?

Not yet. Independent testing is planned; results will be shared under NDA with enterprise customers when available.

How are security vulnerabilities disclosed?

Responsible disclosure via security@aibyteslearning.com — machine-readable details at /.well-known/security.txt. High and critical issues are patched within 14 days, typically sooner.

Is two-factor authentication available?

Yes — TOTP-based MFA available for all accounts. Can be enforced organisation-wide for enterprise licences.

Are sub-processors listed and DPA-covered?

Yes — key sub-processors include Supabase, Vercel, Stripe, and ElevenLabs. Full list and DPAs available on request.

Have a security question?

Our team is happy to complete your organisation's security questionnaire, provide documentation, or arrange a technical call.

support@aibyteslearning.com