# Security & Compliance

> ISMS-P and ISO/IEC 27001:2022 certified; encryption, access controls, and compliance frameworks.

- Last updated: 2026-07-29
- Canonical URL: https://www.touchclass.com/en/security
- Markdown mirror URL: https://www.touchclass.com/markdown.php/en/security.md
- Language: English
- Category: Security & compliance

## Key points

- ISMS-P and ISO/IEC 27001:2022 certified; encryption, access controls, and compliance frameworks.
- Public security pages cite ISMS-P and ISO/IEC 27001:2022.
- Security materials describe encryption at rest and in transit, role-based access control, admin security options, audit logs, high-availability architecture, and monitoring.
- Customer knowledge assets generated or provided during AI-service usage are stated as not used as AI model training data.

## Page content

*The content below is extracted from the rendered source page.*

Security & Certification

## Security trusted by financial institutions, verified in Korea and abroad — protecting your learning data.

TouchClass holds both ISMS-P (Korea) and ISO/IEC 27001:2022 (international) information-security certifications and operates against the vendor security review standards used by financial institutions.

[Talk to sales](https://www.touchclass.com/form/contact-en) View certification details

## Enterprise security framework

Certification, infrastructure, technology and operations — a complete security posture, end to end.

### Integrated global & domestic security certification

TouchClass holds ISMS-P (Korea) and ISO/IEC 27001:2022 (international) certifications and operates an information-security management system covering both.

- ISMS-P — Korea's top-tier Information Security & Personal Data Protection certification (102 controls)

- ISO/IEC 27001:2022 — global Information Security Management System certification (93 controls)

- Continuous governance maintained through annual surveillance and renewal audits

### Global cloud security architecture

A staged control framework built on AWS protects the infrastructure layer.

- Operated in the AWS Seoul region — domestic data-governance compliance

- Layered traffic control at every tier

- Intelligent threat detection with real-time response

- Dedicated networks meeting financial-industry security standards

### Technical information-security controls

Rigorous data protection and access control deliver an environment you can rely on.

- Standard encryption to preserve data integrity

- Granular personal-data management with no blind spots

- Role-based, tailored access permission management

- Data-loss prevention to safeguard valuable content and data

### Business continuity assured

Proven by large-scale financial-sector operations — delivering an uninterrupted learning environment.

- Full security readiness at financial-industry level

- Operational reliability evidenced by years of incident-free service

- Non-stop service on a high-availability architecture

- Consistent high performance under massive concurrent load

## An enterprise LMS that holds both domestic and international security certifications

TouchClass holds ISMS-P (Korea) and ISO/IEC 27001:2022 (international) certifications and operates against the vendor security review standards used by financial institutions. If you entrust employee personal data to a learning platform, start verification by asking the vendor for the certificate itself — its scope and validity period.

ISMS-P certified ISO/IEC 27001:2022 certified

[View enterprise security details →](https://www.touchclass.com/en/security-enterprise)

## Security deep dives

Explore each area in depth.

[Security risks A precise analysis of the sophisticated threats targeting LMS platforms — today's blind spot in enterprise security. Read more →](https://www.touchclass.com/en/security-risk)

[Security architecture Technical and managerial controls aligned to domestic and international standards — ensuring business continuity. Read more →](https://www.touchclass.com/en/security-detail)

[Security guidelines A security checklist and benchmarking data to help you choose the right LMS platform. Read more →](https://www.touchclass.com/en/security-enterprise)

[Security Q&A Answers to the questions corporate security leaders ask — from adoption through operations. Read more →](https://www.touchclass.com/en/security-qna)

## AI data privacy & ethics principles

“TouchClass does not use any knowledge asset generated or provided by our customers during AI-service usage as training data for AI models.”

- Zero Data Training (no customer data used for AI training)

- Privacy-by-Design AI architecture

- Compliance with data-protection laws and AI ethics guidelines

## Focus on learning — not on security risk — with an integrated security-certified learning platform.

[Talk to sales](https://www.touchclass.com/form/contact-en)

## Related resources

- [Security Risks](https://www.touchclass.com/markdown.php/en/security-risk.md): The security risks of corporate training platforms and how TouchClass addresses them.
- [Security Details](https://www.touchclass.com/markdown.php/en/security-detail.md): Security architecture — encryption, network security, access management, and incident response.
- [Enterprise Security Guide](https://www.touchclass.com/markdown.php/en/security-enterprise.md): Security evaluation guide for IT decision-makers — checklist and architecture overview.
- [Security Q&A](https://www.touchclass.com/markdown.php/en/security-qna.md): The five questions corporate security teams ask most, answered in one place.

> Source governance: https://www.touchclass.com/data/source-governance.json · Full LLM context: https://www.touchclass.com/en/llms-full.txt · Structured data: https://www.touchclass.com/data/capability-effects.json, https://www.touchclass.com/data/solution-use-cases.json
