Security & Certification

Security trusted by financial institutions,
verified in Korea and abroad — protecting your learning data.

TouchClass holds both ISMS-P (Korea) and ISO/IEC 27001:2022 (international) information-security certifications
and operates against the vendor security review standards used by financial institutions.

Enterprise security framework

Certification, infrastructure, technology and operations — a complete security posture, end to end.

Integrated global & domestic security certification

TouchClass holds ISMS-P (Korea) and ISO/IEC 27001:2022 (international) certifications and operates an information-security management system covering both.

  • ISMS-P — Korea's top-tier Information Security & Personal Data Protection certification (101 controls)
  • ISO/IEC 27001:2022 — global Information Security Management System certification (93 controls)
  • Continuous governance maintained through annual surveillance and renewal audits

Global cloud security architecture

A staged control framework built on AWS protects the infrastructure layer.

  • Operated in the AWS Seoul region — domestic data-governance compliance
  • Layered traffic control at every tier
  • Intelligent threat detection with real-time response
  • Dedicated networks meeting financial-industry security standards

Technical information-security controls

Rigorous data protection and access control deliver an environment you can rely on.

  • Standard encryption to preserve data integrity
  • Granular personal-data management with no blind spots
  • Role-based, tailored access permission management
  • Data-loss prevention to safeguard valuable content and data

Business continuity assured

Proven by large-scale financial-sector operations — delivering an uninterrupted learning environment.

  • Full security readiness at financial-industry level
  • Operational reliability evidenced by years of incident-free service
  • Non-stop service on a high-availability architecture
  • Consistent high performance under massive concurrent load

An enterprise LMS that holds both
domestic and international security certifications

TouchClass holds ISMS-P (Korea) and ISO/IEC 27001:2022 (international) certifications and operates against the vendor security review standards used by financial institutions.
If you entrust employee personal data to a learning platform, start verification by asking the vendor for the certificate itself — its scope and validity period.

ISMS-P certified ISO/IEC 27001:2022 certified
View enterprise security details →

Security deep dives

Explore each area in depth.

Security Q&A

The questions corporate security reviewers ask most often when evaluating an LMS.

Security standards differ by country and by global guideline. TouchClass holds ISMS-P, Korea's combined information-security and personal-data-protection certification, together with the global standard ISO/IEC 27001:2022, so its security governance is verifiable both in Korea and abroad. Both are maintained through annual review.
TouchClass applies a standard security architecture across the full data lifecycle, from creation to destruction.
  • Infrastructure security: operated on AWS with a global cloud security architecture
  • Data residency: all data is stored and processed in the AWS Seoul region, with no transfer abroad
  • Encryption: standard encryption applied both at rest and in transit
  • Access control: least-privilege access, restricted to authorised personnel
  • Leak prevention: screen-capture blocking and watermarking protect content assets
Yes. TouchClass scored 99.1 out of 100 in Samsung Life Insurance's vendor information-security review, and provides standard evidence packs based on that experience.
  • Structured security evidence: practical guidance from the pre-adoption security review onward, to reduce the reviewer's workload.
  • On-site audit support: security governance maintained to the standards required by financial institutions and large enterprises.
AWS Multi-AZ redundancy and 24/7 monitoring minimise the risk of service interruption. TouchClass has run without a service-affecting outage in the AWS Seoul region for five years (own operational records).
  • High-performance architecture: a learning environment that stays responsive under the traffic volumes of large financial institutions
  • High availability: AWS Multi-AZ redundancy minimises interruption risk
  • Rapid incident response: a standardised recovery procedure protects business continuity
Korea's amended Personal Information Protection Act extends responsibility for security incidents up to executive level. If a breach occurs on an uncertified LMS, the exposure goes beyond financial loss to legal and reputational consequences.
  • Punitive administrative fines of up to 3%–10% of total revenue (Article 64-2)
  • Punitive damages of up to five times the loss (Article 39)
  • Sanctions extending to the CEO and representatives (Article 30-3)
  • Penalties and administrative measures for breach of safeguard obligations (Articles 75 and 66)
More Q&A →

AI data privacy & ethics principles

“TouchClass does not use any knowledge asset generated or provided by our customers during AI-service usage as training data for AI models.”

  • Zero Data Training
    (no customer data used for AI training)
  • Privacy-by-Design
    AI architecture
  • Compliance with data-protection laws
    and AI ethics guidelines

Materials for procurement and security review

We provide the documents your review needs during the consultation.

Certificates

Copies of the ISMS-P and ISO/IEC 27001:2022 certificates, with their scope statements

Personal data flow

How personal data is processed and sub-processed, plus the Zero Data Training policy (your data is not used to train AI)

Infrastructure & encryption

AWS Seoul region · AES-256 at rest · TLS 1.3 in transit · Multi-AZ configuration

Incident & SLA terms

Five years of uninterrupted operation in financial services and a 15-minute initial incident-response standard

Administrator permissions

Sub-administrator separation of duties and access-control policy, designed around your operating structure

SSO / API scope

SAML, OAuth and LDAP integration, and the scope of HRIS connectivity

Add “security review pack” to your demo request and we will prepare it before we contact you.

Focus on learning — not on security risk — with an integrated security-certified
learning platform.

Talk to sales