Training Core LabSign in

Security, privacy engineering and standards

Last reviewed: 24 August 2026. This statement explains Training Core Lab’s security approach without publishing operational secrets. It is not a penetration-test report, contractual security schedule or claim of certification.

Responsibility and scope

Focus Training Centre is responsible for its use of Training Core Lab and the personal data entered into its organisation workspace. Platform hosting and authorised support are operated under controlled access. Every customer organisation is logically separated and users must work within an active organisation context.

Identity and access control

Data protection controls

Application and change security

AI security boundary

Training Core AI is read-only. Its governed tools use the active organisation, role and enabled modules. It blocks credentials and personal-data disclosure requests, exposes aggregate or minimal approved evidence, and records tool traces without unrestricted database rows. Published How-To retrieval follows the same tenant, role and module controls.

Monitoring, backups and incident response

Production launch requires monitored application and server logs, tested encrypted backups, restore exercises, scheduler/queue monitoring, mail and connector alerting, documented incident ownership and a breach-assessment process. Suspected incidents are triaged, contained, preserved for investigation and assessed for notification obligations under applicable data-protection law.

Standards position

The control baseline is mapped against UK GDPR and the Data Protection Act 2018, OWASP application-security practices and relevant UK NCSC guidance. Accessibility is addressed separately against WCAG 2.2 AA. Training Core Lab does not currently claim ISO 27001, Cyber Essentials, SOC 2 or PCI DSS certification. Any certification will be stated only after independent award and with its exact scope.

Known launch boundaries

Responsible disclosure

Report a suspected vulnerability to info@focustrainingcentre.co.uk with the affected URL, observed behaviour, time and safe reproduction steps. Do not access another person’s data, persist access, disrupt service, use destructive testing or publish the issue before remediation coordination.

Review

This statement is reviewed after material architectural or security changes and at least annually. Organisation-specific contractual, processor and retention terms will be provided separately before commercial launch.