Skip to main content

ON THIS PAGE:

1. Cloud Security Statement

2. Information Security Policy

Cloud Security Statement

Inspera Assessment is a cloud-based Software as a Service (SaaS) solution for educational assessments hosted entirely on Amazon Web Services (AWS). Amazon, which is ISO27001 certified, is responsible for the security of its physical data centres and the AWS cloud. Inspera is responsible for monitoring, managing, and securing the Inspera Assessment Cloud. More information about how Amazon secure AWS can be found here.

Facilities

AWS manages secure data centres that host the Inspera Assessment Cloud. Further information on security can be found here.

All Inspera Assessment Cloud data is hosted within the European Union for technical, security, and privacy reasons.

Certification

Inspera is certified (PDF) as Cyber Essentials Plus according to the UK National Cyber Security Centre (NCSC) certification scheme.

AWS is responsible for managing the security of the cloud service provided. AWS is certified by third-party organisations and operates a number of compliance programmes to comply with applicable laws and regulations. A list of such certifications and compliance statements can be found here.

AWS has a public SOC 3 report on Security, Availability & Confidentiality (PDF) as well as an ISO 27001 certification (PDF).

People and Access

Within Inspera, only a few trusted members of our DevOps Team have access to the production environment for the purposes of maintaining our cloud services and assisting our customers. Additionally, we audit and monitor all access to the Inspera Assessment cloud.

Customers are responsible for maintaining the security of their own login information and permissions.

Data Storage and Retention

Data at rest in the Inspera Assessment cloud is encrypted following the industry standards. Additionally, all communications with the Inspera Assessment cloud are protected with HTTPS using TLS and within the cloud through AWS VPC. Backend services are only available through SSH connections from pre-approved locations through a bastion server.

Inspera Assessment has a multi-tenant model where some components, services, and codebases are shared between customers. Each customer’s data is logically separated from all other customers’ data. This means that each customer can only access their own data.

Data Transfer

Inspera does not transfer data outside the AWS cloud.

Security Tests

Inspera Assessment cloud services are tested regularly by external parties, such as third parties conducting penetration tests and regular audits.

Backup and Disaster Recovery

Assessment data is backed up (at least) once a day and is encrypted following industry standards. Backup lifetime is 7 days and is only used for disaster recovery.

The Inspera DevOps team has a disaster recovery process in place which is tested on a regular basis.

Privacy

Inspera understands the importance of privacy and is committed to protecting your personally identifiable information. The Inspera Assessment is built from the ground up on privacy by design with extensive use of encryption, access control, audit logging and especially pseudonymisation of identities. If an external authentication provider is configured and Single-Sign-On (SSO) is used, Inspera Assessment can be used completely without Inspera knowing the actual identity of test taker.

For more information, please see our privacy notice.

 

Information Security Policy

At Inspera, we are committed to maintaining the highest standards of information security to protect the data, systems, and digital experiences relied upon by our customers, learners, examiners, and partners. As a leading digital assessment provider, we understand that trust in our platforms depends on the confidentiality, integrity, and availability of the information we manage.

We recognise that information is a critical asset and maintaining its security is essential to earning and preserving the trust of our users, examiners, and employees. Our Information Security Policy governs how we manage and safeguard data across all operations, services, and platforms.

To underpin this commitment, we have established and continue to maintain an Information Security Management System (ISMS) aligned with the requirements of ISO/IEC 27001:2022- the internationally recognised standard for information security management. This provides a systematic and risk-based approach to identifying, managing, and continually improving our information security practices.


Our key commitments include:

1. Protecting Confidentiality, Integrity, and Availability: We ensure that all information assets whether related to learners, content, platforms, or internal systems are protected against unauthorised access, loss, misuse, or compromise.

2. Embedding Security into EdTech services: Security is integrated throughout the lifecycle of our products and services from design and development through to delivery and maintenance ensuring safe and trusted learning experience for all users.

3. Access and Identity Management: Strong controls are in place to ensure that only authorised individuals can access our systems and data, based on the principle of least privilege.

4. Security Awareness and Culture: All employees and contractors receive ongoing training and awareness on information security best practices, fostering a strong culture of security within our organisation.

5. Business Continuity and Resilience: Our ISMS includes comprehensive business continuity and incident response capabilities to ensure uninterrupted learning services and timely recovery from any security event.

6. Risk-Based Approach: We proactively identify and manage information security risks, applying proportionate controls to safeguard our technology infrastructure and services.

7. Continuous Improvement and Governance: Our ISMS is regularly reviewed and enhanced through internal audits, external assessments, and a governance structure that ensures accountability at all levels.

At Inspera, we believe that strong information security is essential to delivering fair, reliable, and innovative digital assessment experiences. Through our commitment to ISO/IEC 27001:2022 and a culture of continuous improvement, we ensure that trust and integrity remain at the core of everything we do.