Security, privacy engineering and standards
Last reviewed: 24 August 2026. This statement explains Training Core Lab’s security approach without publishing operational secrets. It is not a penetration-test report, contractual security schedule or claim of certification.
Responsibility and scope
Focus Training Centre is responsible for its use of Training Core Lab and the personal data entered into its organisation workspace. Platform hosting and authorised support are operated under controlled access. Every customer organisation is logically separated and users must work within an active organisation context.
Identity and access control
- Authenticated access with role-based permissions and least-privilege roles.
- Organisation scoping applied to operational models, queries, routes, reports, Help content, AI evidence and print connectors.
- Platform Support View is explicit, audited and limited to the selected organisation.
- Connector credentials are random, revocable and stored as one-way hashes; secrets are not displayed after creation.
- Administrative and production actions require authorised write roles and CSRF-protected requests.
- Custom hostnames require DNS ownership verification and must receive separate TLS/reverse-proxy approval.
Data protection controls
- TLS is required for production traffic. Database, backup and storage protection are configured at the hosting layer.
- Passwords use Laravel’s configured one-way password hashing; integration passwords are encrypted before storage.
- Public card and diploma validation uses long random references rather than sequential record identifiers.
- Public verification displays credential-safe information only and excludes DOB, address, telephone, email, documents, notes and administration links.
- Print jobs and generated diplomas retain immutable template/data snapshots for audit; the Windows print connector removes successful local spool jobs.
- Retention, archiving and deletion are controlled by record type and legal/operational need rather than indiscriminate deletion.
Application and change security
- Input validation, output escaping, CSRF protection, parameterised database access and controlled file validation are used throughout the Laravel application.
- Rich email and How-To HTML is sanitised before storage.
- Module entitlements are enforced beyond navigation, including routes, evidence tools and connected workflows.
- Releases are versioned, reviewed in UAT, migrated through controlled deployment and checked for PHP/Blade/route errors before promotion.
- Dependencies and framework security updates are reviewed as part of maintenance. Unsupported components must not be promoted to production.
- Security logs avoid intentionally recording passwords, access tokens or unrestricted personal records.
AI security boundary
Training Core AI is read-only. Its governed tools use the active organisation, role and enabled modules. It blocks credentials and personal-data disclosure requests, exposes aggregate or minimal approved evidence, and records tool traces without unrestricted database rows. Published How-To retrieval follows the same tenant, role and module controls.
Monitoring, backups and incident response
Production launch requires monitored application and server logs, tested encrypted backups, restore exercises, scheduler/queue monitoring, mail and connector alerting, documented incident ownership and a breach-assessment process. Suspected incidents are triaged, contained, preserved for investigation and assessed for notification obligations under applicable data-protection law.
Standards position
The control baseline is mapped against UK GDPR and the Data Protection Act 2018, OWASP application-security practices and relevant UK NCSC guidance. Accessibility is addressed separately against WCAG 2.2 AA. Training Core Lab does not currently claim ISO 27001, Cyber Essentials, SOC 2 or PCI DSS certification. Any certification will be stated only after independent award and with its exact scope.
Known launch boundaries
- UAT contains anonymised test data and is not approved for live personal data.
- The Evolis connector is simulator-ready; physical printing requires the signed adapter and on-device calibration.
- Custom-domain verification does not itself provision DNS, reverse proxy or TLS.
- Independent penetration testing, final privacy approval and production recovery testing remain launch gates.
Responsible disclosure
Report a suspected vulnerability to info@focustrainingcentre.co.uk with the affected URL, observed behaviour, time and safe reproduction steps. Do not access another person’s data, persist access, disrupt service, use destructive testing or publish the issue before remediation coordination.
Review
This statement is reviewed after material architectural or security changes and at least annually. Organisation-specific contractual, processor and retention terms will be provided separately before commercial launch.