Security

Your training data is sensitive. Here's how we protect it.

Encryption, EU data residency, row-level security, and full audit trails - built in from day one.

TrainedTeam encrypts all data at rest (AES-256) and in transit (TLS 1.3), stores it in EU data centres, and enforces row-level security at the database layer. Every e-signature is logged with the signer's name, timestamp, IP address, and document version. Transfer details are in our privacy policy.

Last reviewed: July 2026

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database connections are encrypted. Backups are encrypted.

EU Data Centres

Your data is stored in European Union data centres. Content you submit to AI features is processed by our AI sub-processor in the United States under UK GDPR transfer safeguards — see our privacy policy for details.

Authentication

Support for Google and Microsoft SSO. Password authentication uses bcrypt hashing with salting. Multi-factor authentication support is on our roadmap.

Row-Level Security

Database-level security ensures users can only access data belonging to their organisation. This is enforced at the database layer, not just the application layer.

Access Control

Four role levels (Owner, Manager, Content Creator, Maker) with granular permissions. Owners control who can access what. Role changes take effect immediately.

Audit Trail

Every e-signature captures the signer's legal name, timestamp, IP address, and document version. Training completions, quiz results, and acknowledgments are permanently logged.

UK GDPR Compliance

We process data in accordance with the UK GDPR and Data Protection Act 2018. We provide data processing agreements on request for Enterprise customers.

Regular Updates

Dependencies are regularly updated. Security patches are applied promptly. We monitor for vulnerabilities and follow responsible disclosure practices.

Data retention and deletion

Training records and acknowledgment data are retained for the duration of your subscription plus 6 years, in line with UK employment law retention guidelines (Limitation Act 1980).

You can delete individual content items at any time. Account deletion removes all personal data within 30 days. Compliance records (e-signatures, acknowledgments) may be retained for the statutory period.

On request, we provide a full data export in standard formats (CSV, JSON). Enterprise customers can request a data processing agreement (DPA).

Reporting a vulnerability

If you discover a security vulnerability, please report it responsibly to security@trainedteam.com. We will acknowledge receipt within 24 hours and aim to resolve confirmed vulnerabilities promptly.

Security FAQs

Is my data encrypted?

Yes. All data is encrypted at rest using AES-256 and in transit using TLS 1.3, including database connections and backups.

Where is my data stored?

In European Union data centres. Content you submit to AI features is processed by our AI sub-processor in the United States under UK GDPR transfer safeguards — see our privacy policy for details.

Is TrainedTeam UK GDPR compliant?

We process data in accordance with the UK GDPR and Data Protection Act 2018, and provide data processing agreements on request for Enterprise customers.

Does TrainedTeam support SSO?

Google and Microsoft SSO are included on every plan, including Free. SAML SSO is available on Enterprise.

How long are training records kept?

For the duration of your subscription plus 6 years, in line with UK employment law retention guidelines.

Training data you can trust

Request your invite. Encryption, audit trails, and UK GDPR compliance included on every plan.