Certified, tested, and built for security

Your data security is our top priority. From certified infrastructure to continuous penetration testing, we maintain the highest standards to protect your organisation’s information.

Built on a proactive, standards-driven approach

Our approach to security includes adhering to industry best practices, such as the OWASP Application Security Verification Standard (ASVS), implementing robust password policies, ensuring secure session management, and regularly validating system integrity. By maintaining these high standards and conducting ongoing security assessments, we ensure that your data remains safe and secure.

Rigorously tested by leading security experts

We've partnered with Cobalt, a leading provider of penetration testing, to rigorously evaluate the security of our Journeys application. We are proud to share that the application successfully meets their stringent security standards, demonstrating our commitment to providing a secure and trustworthy platform.

Cyber Plus certified

We maintain strong security standards and undergo regular assessments to ensure compliance with industry requirements. 50skills has been awarded the Cyber Essentials Plus certification, independently verified by The IASME Consortium (BlockMark Registry).

Cloud hosting backed by global standards and certifications

Our computing infrastructure is hosted in the cloud and powered by Heroku.Heroku’s physical infrastructure is hosted and managed within Amazon’s secure data centers and utilises Amazon Web Service (AWS) technology.

Amazon’s data center operations have been accredited under: ISO 27001, SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II), PCI Level 1, FISMA Moderate and Sarbanes-Oxley (SOX).

Frequently asked questions

We take a multi-layered approach to security, leveraging both our sub-processors' robust compliance frameworks and our own internal audits and testing.

If you have additional questions please contact us directly at security@50skills.com

What is the data retention policy for traveller records?

Which third-party data processors do you use, and are they GDPR-compliant?

Does OpenAI use our data for model training?

How do your AI agents work if the LLMs do not retain data?

Is traveller data isolated per customer?

Do you use encryption and other security best practices?

What encryption standarads do you use?

Do you condcut third-party security audits?