Security Q&A

The five questions corporate security teams
ask us most — answered in one place

Certification scope · data protection · vendor due diligence · uptime under load · legal risk —
the checkpoints buyers review before adopting an enterprise LMS.

Key indicators for security teams

The objective baseline TouchClass maintains.

Integrated certifications ISMS-P & ISO 27001 Both domestic and international standards — audited annually.
Vendor assessments Top-rated in finance Highest-tier ratings across multiple financial-institution audits.
Data governance 100% AWS Seoul All data is stored and processed domestically — no cross-border transfer.

Frequently asked security questions

The questions enterprise security teams raise most often during LMS evaluations.

Domestic and international information-security standards differ based on national regulations and global guidelines. By holding both Korea's top-tier ISMS-P and the global ISO/IEC 27001:2022 simultaneously, TouchClass establishes a verified security governance accepted both at home and abroad. Annual audits ensure the management system is continuously maintained.
TouchClass applies a standard security architecture end to end — from data creation to destruction.
  • Infrastructure security: Operated on AWS with a global cloud-security architecture.
  • Domestic data governance: All data is stored and processed in the AWS Seoul region, with no cross-border transfer.
  • Standard encryption: Applied to data both at rest and in transit.
  • Access control: Least-privilege principle — only authorized personnel can access data.
  • Data-loss prevention: Screen-capture prevention and watermarking prevent asset leakage.
Yes. TouchClass actively supports your review, following the security guidelines of large financial institutions and major customers.
  • Structured security evidence & guidance: Drawing on our top-rated vendor-assessment track record, we provide standard evidence materials for your due diligence.
  • Pre-adoption guidance: From the security pre-assessment stage, we provide practical guidelines to ease the load on your teams.
TouchClass delivers an uninterrupted learning environment backed by years of incident-free operations.
  • High-performance architecture for heavy traffic: Optimal learning performance without latency, even under bursty traffic.
  • Non-stop service on a high-availability architecture: AWS Multi-AZ redundancy minimizes outage risk.
  • Rapid incident response and recovery: Standardized procedures restore service quickly to protect business continuity.
Korea's revised Personal Information Protection Act extends responsibility for security incidents from individual contributors up to executive management. If a breach occurs on an uncertified LMS, companies may face not only financial loss but legal and reputational risk.
  • Punitive fines up to 3–10% of total turnover (Article 64-2)
  • Punitive damages of up to 5× actual damage (Article 39)
  • CEO / representative liability sanctions (Article 30-3)
  • Administrative penalties for safety-measure violations (Articles 75 and 66)

See LMS security risks in detail →

Go deeper

Review the reasoning and evidence for each topic on its dedicated page.

AI data privacy & ethics principle

“TouchClass does not use any knowledge asset generated or provided by our customers during AI-service usage as training data for AI models.”

  • Zero Data Training
    (no customer data used for AI training)
  • Privacy-by-Design
    AI architecture
  • Compliance with data-protection laws
    and AI ethics guidelines

Need evidence for a security review?
Standard evidence materials and pre-adoption guides are ready to share.

Talk to sales