Encrisoft
Confiança

Security at Encrisoft

Our approach to protecting platform, customer, and learner data.

Última atualização: 17 September 2026

Este documento jurídico está atualmente disponível apenas em inglês enquanto são revistas traduções profissionais.

Security at Encrisoft

Security informs how Encrisoft designs, operates, and improves services that handle organisational, administrator, and learner information. This page describes our approach without claiming unverified certifications.

Secure product development

Security considerations are incorporated into product design, code review, dependency management, testing, and change processes. Findings are assessed and prioritised according to risk.

Data protection and encryption

Encrisoft uses safeguards intended to protect data in transit and at rest where supported by the relevant platform and service configuration. Access is limited according to operational need.

Identity and access management

Account and administrative controls support controlled access to organisation and learner records. Customers are responsible for choosing appropriate administrators, protecting credentials, and promptly removing access that is no longer required.

Infrastructure security

Infrastructure is managed with access controls, configuration practices, updates, backups, and service-provider controls appropriate to the system. Specific contractual requirements should be confirmed during procurement.

Logging, monitoring and vulnerability management

Operational records help investigate service health and security events. Potential vulnerabilities are reviewed and addressed according to assessed impact and available mitigations.

AI security

Encrisoft AI assists selected workflows, including phishing-simulation content creation. Those features are considered within access control, data minimisation, prompt and output handling, operational logging, abuse prevention, provider review, vulnerability management and incident response. Exact provider retention, model-training settings and processing locations depend on the configured service and require Security, Privacy and Legal confirmation.

Incident response and continuity

Encrisoft maintains processes for assessing and responding to suspected security incidents and restoring service following disruption. Notification obligations depend on the event, applicable law, and customer agreements.

Customer responsibilities

Customers remain responsible for authorised simulations, user administration, suitable programme communications, endpoint security, and their own legal and compliance obligations. Product reporting may support evidence collection but does not itself guarantee compliance.

Responsible disclosure

If you believe you have identified a security issue, use the Encrisoft contact page and clearly mark the request as a security report. A dedicated public disclosure address has not yet been approved.

Compliance and audit support

Encrisoft features can help organisations maintain structured training, simulation, certificate, and learner records that support internal or external review. Customers should assess their own framework and regulatory requirements.

Dúvidas?

Contacte o Encrisoft para mais informações.

Contactar o Encrisoft