# Security Q&A

> The five questions corporate security teams ask most, answered in one place.

- Last updated: 2026-07-27
- Canonical URL: https://www.touchclass.com/en/security-qna
- Markdown mirror URL: https://www.touchclass.com/markdown.php/en/security-qna.md
- Language: English
- Category: Security & compliance

## Key points

- The five questions corporate security teams ask most, answered in one place.
- Public security pages cite ISMS-P and ISO/IEC 27001:2022.
- Security materials describe encryption at rest and in transit, role-based access control, admin security options, audit logs, high-availability architecture, and monitoring.
- Customer knowledge assets generated or provided during AI-service usage are stated as not used as AI model training data.

## Page content

*The content below is extracted from the rendered source page.*

Security Q&A

## The five questions corporate security teams ask us most — answered in one place

Certification scope · data protection · vendor due diligence · uptime under load · legal risk — the checkpoints buyers review before adopting an enterprise LMS.

[Talk to sales](https://www.touchclass.com/form/contact-en) [Security overview](https://www.touchclass.com/en/security)

## Key indicators for security teams

The objective baseline TouchClass maintains.

Integrated certifications ISMS-P & ISO 27001 Both domestic and international standards — audited annually.

Vendor assessments Top-rated in finance Highest-tier ratings across multiple financial-institution audits.

Data governance 100% AWS Seoul All data is stored and processed domestically — no cross-border transfer.

## Frequently asked security questions

The questions enterprise security teams raise most often during LMS evaluations.

**Q1.**Why does it matter that TouchClass holds both domestic and international security certifications?

Domestic and international information-security standards differ based on national regulations and global guidelines. By holding both Korea's top-tier **ISMS-P** and the global **ISO/IEC 27001:2022** simultaneously, TouchClass establishes verified security governance accepted both in Korea and abroad. Annual audits ensure the management system is continuously maintained.

**Q2.**How is technical data protection and leak prevention structured?

TouchClass applies a standard security architecture end to end — from data creation to destruction.

- **Infrastructure security:** Operated on AWS with a global cloud-security architecture.

- **Domestic data governance:** All data is stored and processed in the AWS Seoul region, with no cross-border transfer.

- **Standard encryption:** Applied to data both at rest and in transit.

- **Access control:** Least-privilege principle — only authorized personnel can access data.

- **Data-loss prevention:** Screen-capture prevention and watermarking prevent asset leakage.

**Q3.**Do you support adoption-time security due diligence and ongoing vendor audits?

Yes. TouchClass actively supports your review, following the security guidelines of large financial institutions and major customers.

- **Structured security evidence & guidance:** Drawing on our top-rated vendor-assessment track record, we provide standard evidence materials for your due diligence.

- **Pre-adoption guidance:** From the security pre-assessment stage, we provide practical guidelines to ease the load on your teams.

**Q4.**How is service stability maintained under massive concurrent load or in incident scenarios?

TouchClass delivers an uninterrupted learning environment backed by years of incident-free operations.

- **High-performance architecture for heavy traffic:** Optimal learning performance without latency, even under bursty traffic.

- **Non-stop service on a high-availability architecture:** AWS Multi-AZ redundancy minimizes outage risk.

- **Rapid incident response and recovery:** Standardized procedures restore service quickly to protect business continuity.

**Q5.**What legal risks does a company face when an incident occurs on an uncertified LMS?

Korea's revised Personal Information Protection Act extends responsibility for security incidents from individual contributors up to executive management. If a breach occurs on an uncertified LMS, companies may face not only financial loss but legal and reputational risk.

- Punitive fines up to 3–10% of total turnover (Article 64-2)

- Punitive damages of up to 5× actual damage (Article 39)

- CEO / representative liability sanctions (Article 30-3)

- Administrative penalties for safety-measure violations (Articles 75 and 66)

[See LMS security risks in detail →](https://www.touchclass.com/en/security-risk)

## Go deeper

Review the reasoning and evidence for each topic on its dedicated page.

[Security overview The full TouchClass security structure, organized in a 4-pillar framework. Open hub →](https://www.touchclass.com/en/security)

[Security risks Sophisticated threats targeting LMS platforms — and how to address them. Read more →](https://www.touchclass.com/en/security-risk)

[Security architecture Technical and managerial controls behind our standard evidence materials. Read more →](https://www.touchclass.com/en/security-detail)

[Security guidelines Checklist and benchmarking data for selecting an enterprise LMS. Read more →](https://www.touchclass.com/en/security-enterprise)

## AI data privacy & ethics principles

“TouchClass does not use any knowledge asset generated or provided by our customers during AI-service usage as training data for AI models.”

- Zero Data Training (no customer data used for AI training)

- Privacy-by-Design AI architecture

- Compliance with data-protection laws and AI ethics guidelines

## Need evidence for a security review? Standard evidence materials and pre-adoption guides are ready to share.

[Talk to sales](https://www.touchclass.com/form/contact-en)

## Related resources

- [Security & Compliance](https://www.touchclass.com/markdown.php/en/security.md): ISMS-P and ISO/IEC 27001:2022 certified; encryption, access controls, and compliance frameworks.
- [Security Risks](https://www.touchclass.com/markdown.php/en/security-risk.md): The security risks of corporate training platforms and how TouchClass addresses them.
- [Security Details](https://www.touchclass.com/markdown.php/en/security-detail.md): Security architecture — encryption, network security, access management, and incident response.
- [Enterprise Security Guide](https://www.touchclass.com/markdown.php/en/security-enterprise.md): Security evaluation guide for IT decision-makers — checklist and architecture overview.

> Source governance: https://www.touchclass.com/data/source-governance.json · Full LLM context: https://www.touchclass.com/en/llms-full.txt · Structured data: https://www.touchclass.com/data/capability-effects.json, https://www.touchclass.com/data/solution-use-cases.json
