Security and trust, written for the reviewer with a checklist
Deployment models, data residency, certifications, access control and incident response. Facts your reviewer can check against their own checklist.
Five deployment models, and what changes in each
| Model | Where it runs | Who operates it |
|---|---|---|
| Shared cloud | MobiLearn multi-tenant environment | MobiLearn |
| Dedicated cloud | A MobiLearn environment reserved for you | MobiLearn |
| Customer cloud | Your own cloud account | Joint, scoped at implementation |
| Private VPC | Isolated network inside your cloud | Joint, scoped at implementation |
| On-premise | Your data centre | Your team, with our support |
Customer-hosted environments include a separately scoped deployment and operations component. The platform licence itself does not change.
Data residency, retention and deletion
- Residency
- India region available for customers who require data to remain in country.
- In transit
- TLS on every connection.
- At rest
- Encrypted storage.
- Backups
- Scheduled backups with a defined retention window, confirmed per deployment model.
- Deletion
- Documented deletion process on contract termination, including learner records and generated content.
Certifications: current status, stated plainly
| Standard | Status |
|---|---|
| VAPT | In place — certificate date and scope to follow |
| ISO 27001 | In place — certificate date and scope to follow |
| SOC 2 Type 2 | In place — certificate date and scope to follow |
| DPDPA (India) | In place — certificate date and scope to follow |
| GDPR | In place — certificate date and scope to follow |
MobiLearn has confirmed these certifications are in place. The certificate dates and the audited scope are still to be supplied and will replace the status column above — a reviewer needs the scope and the date, not the name alone, so this table is not finished until they are here. Ask for the security pack in the meantime and we will send the certificates directly.
Access and operations: controls in day-to-day use
- Authentication
- Single sign-on through your identity provider, with HRMS synchronisation for joiners and leavers.
- Authorisation
- Role-based permissions across learner, manager, administrator and leadership views.
- Audit trail
- Administrative actions and learning records are logged and exportable.
- Incident response
- Defined notification process and timelines, confirmed contractually.
- Support model
- Standard support included; premium SLA available as a scoped service.
Security questions
Can we keep our learning data inside India?
Yes. An India region is available, and customer-hosted models let you keep data inside infrastructure you control entirely.
Do you support single sign-on and HRMS sync?
Yes. Single sign-on through your identity provider, plus HRMS synchronisation so joiners and leavers flow through without manual administration.
What happens to our data if we leave?
There is a documented deletion process covering learner records and generated content, and your data is exportable before termination so nothing is stranded.
Send us your security questionnaire
We answer vendor security questionnaires as part of evaluation. Send yours and we will return it completed, along with the current certification evidence.