Security and data protection
Praxel platform. Last reviewed: August 2026.
This page states what we actually do, including what we do not yet have. Where a control is listed as planned, it is not in place today. If you need evidence for any item below, or a copy of our data processing agreement, contact submissions@albacomanagement.co.uk.
Roles
- Controller
- The training provider or college that enrols the learner.
- Processor
- Praxel, acting on the controller's documented instructions.
- Data we process
- Learner identity and contact details, eligibility and enrolment information, coursework submissions, assessment decisions and feedback, IQA activity, attendance and engagement, and support records.
Where data is held
- Primary database and file storage
- Supabase, UK (London, eu-west-2). Learner data is held in the United Kingdom. Migrated from the EU (Stockholm) region on 9 August 2026.
- Application hosting
- Vercel.
- Error monitoring
- Sentry, EU region (Frankfurt).
- Transactional email
- Resend.
- AI-assisted feedback
- Anthropic. Learner work is sent for the purpose of drafting assessor feedback only, and is not used to train models.
Protecting the data
- Encrypted in transit and at rest. HTTPS only, with HSTS. Storage and database encryption at rest is provided by the hosting platform.
- Row-level isolation between organisations. Every table carrying customer data is protected by a database policy scoping it to the owning organisation. This is enforced by the database, not by application code, and is verified by an automated probe that signs in as a real learner and confirms it cannot read another organisation’s records.
- Role-based access. Learner, assessor, IQA, liaison, administrator and external provider roles each see only what their role requires.
- Multi-factor authentication is available for staff accounts.
- Additional encryption of sensitive identifiers held in the learner record.
- Uploaded files are checked for type and size, and passed to malware scanning where an operator has configured it. Scanning fails closed.
Audit trail
Assessment decisions, enrolment changes, evidence and quality-assurance activity are written to an append-only audit log. Each entry is cryptographically chained to the one before it, so any alteration or deletion of a historic record is detectable rather than merely discouraged. The chain is verified automatically and can be re-verified on demand for an external verifier.
Availability and monitoring
- Automated checks run hourly against the live platform, asserting that learner work is saving, that the evidence trail is intact, that no approved unit lacks evidence, and that scheduled jobs are running.
- Failed saves are recorded and surfaced to staff, including failures that occur in the learner’s browser and cannot reach us at the time.
- Learner work is mirrored in the browser as it is typed, so a failed save can be recovered rather than lost.
- Daily backups are retained by the database provider.
Retention
Learner records are retained for seven years after completion or withdrawal, to meet awarding-organisation and funding requirements. Disposal is a deliberate, recorded action — records are never silently deleted, and every disposal decision is written to the audit log.
Certifications
- Cyber Essentials
- Planned. Not currently held.
- ISO 27001
- Planned. Not currently held.
- Independent penetration test
- Planned. Not yet commissioned.
- UK data residency
- In place. Database and file storage are both in London (eu-west-2), since 9 August 2026.
- Accessibility
- Partially conformant with WCAG 2.2 AA — see our accessibility statement.
Reporting a problem
If you believe you have found a security vulnerability, email submissions@albacomanagement.co.uk. Please give us a reasonable period to investigate and fix before disclosing publicly. We will acknowledge your report and tell you what we find.
In the event of a personal data breach affecting a controller’s data, we will notify that controller without undue delay and within 24 hours of becoming aware of it.