Security & Trust Center

SOC 2 Type II • ISO/IEC 27001 • HIPAA-ready • GDPR & DPF compliant.

Learnly is built and operated by BrainCert, Inc. Security and compliance are top priorities for Learnly because they are fundamental to your experience with the product. This Trust Center summarizes the controls that protect your data and the certifications and attestations you can rely on.

Certifications and attestations

SOC 2 Type II Certified with annual audits covering all five Trust Services Criteria.

ISO/IEC 27001:2022 Certified — globally recognized information security management system.

GDPR Compliant — see our GDPR commitment page for data subject rights we support on behalf of our customers.

HIPAA Available — a Business Associate Agreement (BAA) is available so healthcare customers can process Protected Health Information (PHI) under HIPAA.

EU-U.S. Data Privacy Framework Certified — see our DPF notice for the EU, UK Extension, and Swiss-U.S. DPF commitments.

Engineering controls you can rely on

All information Learnly receives and transmits is fully encrypted using TLS 1.2 and TLS 1.3 with strong ciphers. Customer data is encrypted at rest using FIPS 140-2 validated HSMs (AWS KMS) and AES-256 symmetric encryption.

Learnly is hosted on AWS infrastructure that aligns with SOC 1/2/3, ISO/IEC 27001, PCI DSS Level 1, and FedRAMP/FISMA reports and certifications. Customers on supported plans can opt into region-specific hosting (United States, European Union, or Canada).

Administrative actions, authentication events, configuration changes, and data access events are captured in tamper-evident audit logs retained for 12 months. Customers can stream audit events into their SIEM via xAPI / LRS or the REST API.