# Security Details

> Security architecture — encryption, network security, access management, and incident response.

- Last updated: 2026-08-27
- Canonical URL: https://www.touchclass.com/en/security-detail
- Markdown mirror URL: https://www.touchclass.com/markdown.php/en/security-detail.md
- Language: English
- Category: Security & compliance

## Key points

- Security architecture — encryption, network security, access management, and incident response.
- Public security pages cite ISMS-P and ISO/IEC 27001:2022.
- Security materials describe encryption at rest and in transit, role-based access control, admin security options, audit logs, high-availability architecture, and monitoring.
- Customer knowledge assets generated or provided during AI-service usage are stated as not used as AI model training data.

## Page content

*The content below is extracted from the rendered source page.*

Security Architecture

## Enterprise-Grade Security Architecture

AWS infrastructure, encryption, access control, and compliance. Layered design based on dual ISMS-P + ISO 27001 certification.

[← Security Overview](https://www.touchclass.com/en/security)

## Infrastructure Security

Hosted in the AWS Seoul Region with multi-layered defense from network to server.

### AWS Seoul Region Domestic Data Sovereignty

All data stored and processed within Korea with no overseas transfers.

Seoul Region (ap-northeast-2)

Domestic storage & processing

No overseas transfer

### VPC Network Isolation External Access Blocked

Logical network separation per client. Subnets, security groups and NACLs block external access outside the permitted paths.

Network Layer Defense

VPC

Isolation

SG

Sec Group

NACL

Block

### WAF + Shield Automated DDoS Protection

AWS WAF blocks OWASP-based web attacks while AWS Shield provides automated DDoS mitigation.

WAF

Web Attack Blocking

Shield

DDoS Defense

### Direct Connect Dedicated Line

Financial clients connect via Direct Connect dedicated lines, bypassing the public internet.

Public InternetExposure Risk

Direct ConnectDedicated Line

## Data Security

Protecting data throughout its entire lifecycle — from storage to transit to disposal.

### AES-256 Encryption Data-at-Rest Protection

Database, file storage, and backups are all encrypted with AES-256.

Encryption Coverage

DatabaseAES-256

File StorageAES-256

BackupAES-256

### TLS 1.3 Transit Encryption MITM Prevention

Client-server communication encrypted with TLS 1.3. Lower versions are disabled.

Client

TLS 1.3 Encrypted

Server

MITM Attacks Fully Prevented

### Automatic PII Masking Full Access Logging

Sensitive data is automatically masked. Full audit logs capture who accessed what data and when.

Name K*H

Phone 010-****-5678

Log Retention Minimum 1 year

### Data Disposal Secure Deletion Procedure

At service termination, data is permanently destroyed using secure deletion methods that prevent recovery.

Request

Received

Delete

Full Destruction

Confirm

Certificate Issued

## Operational Security

People and process-level access controls to prevent even internal threats.

### RBAC Granular Access Control

Least privilege principle applied per role: system admin, client admin, sub-admin, learner.

System Admin Full Access

Client Admin Training Mgmt

Learner Learn Only

### SSO · SAML 2.0 Two-Factor Auth (2FA)

Integrates with enterprise authentication (AD, Okta, Azure AD). Admin accounts require additional OTP two-factor authentication.

SSO

Single Sign-On

SAML

2.0 Integration

OTP

2FA Auth

### IP Whitelist Admin Access Restriction

Admin pages accessible only from whitelisted IP ranges. Non-whitelisted IPs are automatically blocked.

10.0.1.0/24 Allowed

192.168.0.0/16 Allowed

Other IPs Block

### Vulnerability Patching Critical: Within 24 Hours

Critical vulnerabilities patched within 24 hours, High within 72 hours, Medium within 7 days.

Critical 24 Hours

High 72 Hours

Medium 7 Days

## Compliance

Meeting compliance requirements, from mandatory training to financial and public sector regulations.

### 5 Mandatory Training Courses Auto-Managed In-Platform

Automatically manages workplace safety, harassment prevention, disability awareness, privacy protection, and anti-bullying training.

Workplace Anti-Bullying

Harassment Prevention

Privacy Protection

Anti-bullying +2 more

### Financial Regulations Vendor Audits · AML

Supports electronic financial supervision vendor security audits and provides legal evidence for financial consumer protection training completion.

Vendor Audit 99.1 Points

FCPA Proof Automated

AML Training Records Automated

### Public Sector Compliance Audit Trail for Inspections

Provides security audit trails for government inspections. ISMS-P certification verifies the platform's security.

Board of Audit

Audit Trail

Parliamentary Audit

Fully Prepared

### Personal Data Processing Safety Verification

ISMS-P certification provides objective evidence that personal data is processed securely.

ISMS-P

3 domains · 101 controls 100% Compliance

## Operational Reliability

Enterprise-level reliability and incident-response systems in operation.

Multi-AZ AWS Redundancy Seoul Region multi-AZ architecture

15 min Recovery Target Initial response and recovery

24/7 Real-time Monitoring 24/7 by dedicated operations team

5 Years Incident-Free Operation Major insurer, consecutive years

## Operational stability indicators

Multi-AZ redundancy, a 15-minute initial-response target, 24/7 monitoring and 5+ years of maintained certification underpin operational stability.

### Key stability indicators

Multi-AZ High availability on AWS Multi-AZ redundancy in the Seoul region

15 min Technical security control Target for initial response to a critical incident

24/7 Business continuity Continuous integrated monitoring by a dedicated team

5+ yrs Legal conformance ISMS-P and ISO 27001 certification maintained

High availability on AWS

Multi-AZ redundancy keeps the service running even if an availability zone in the Seoul region fails

Technical security controls

Encryption, access control and vulnerability management operated continuously

Business continuity

Integrated 24/7 monitoring by a dedicated team, with rapid incident response

Legal conformance

Continuously maintained ISMS-P and ISO 27001 certification evidences statutory security requirements

## See TouchClass Security Architecture firsthand and how it protects your data.

[Talk to sales](https://www.touchclass.com/form/contact-en)

## Related resources

- [Security & Compliance](https://www.touchclass.com/markdown.php/en/security.md): ISMS-P and ISO/IEC 27001:2022 certified; encryption, access controls, and compliance frameworks.
- [Security Risks](https://www.touchclass.com/markdown.php/en/security-risk.md): The security risks of corporate training platforms and how TouchClass addresses them.
- [Enterprise Security Guide](https://www.touchclass.com/markdown.php/en/security-enterprise.md): Security evaluation guide for IT decision-makers — checklist and architecture overview.
- [Security Q&A](https://www.touchclass.com/markdown.php/en/security-qna.md): The five questions corporate security teams ask most, answered in one place.

> Source governance: https://www.touchclass.com/data/source-governance.json · Full LLM context: https://www.touchclass.com/en/llms-full.txt · Structured data: https://www.touchclass.com/data/capability-effects.json, https://www.touchclass.com/data/solution-use-cases.json
