Security and data protection

Learn about the measures in place to protect sensitive data, including encryption, compliance with privacy laws, user role management, and secure data storage practices.


Implement a secure backup and recovery process for learner records and content

We perform daily SQL database backups and store them on our server for seven days. Data can also be exported via SFTP to your server, where you can retain it for as long as needed.


Is data archived? How long is data maintained

Yes, Moodle allows data archiving through backups. Course and user data can be archived manually or automatically using scheduled backups. The duration of data maintenance depends on your organization’s retention policies, as Moodle provides the flexibility to configure and manage data retention as per your needs.


How do you protect our data? Please detail the security provided by your hosting environment

We use BuyVM.net for hosting, which provides robust security measures, including Tier 4 certified data centers with 24/7 on-site security, DDoS protection, Full Disk Encryption (FDE) for data at rest, and private networking for secure internal data transfer. Regular backups and snapshot capabilities further ensure data integrity and recovery, protecting your data with comprehensive security at every level.


Describe your backup procedures

Our backup procedures include regular backups of course data, stored for 10 years, and virtualization snapshots to mitigate data loss. Backups are tested specifically for restore scenarios. Data is stored in a secure facility with multi-layer access controls, monitored by FranTech, our hosting provider.


Do you have a disaster recovery plan

Yes, our disaster recovery plan includes maintaining separate production and quality assurance servers, using virtualization snapshots to mitigate data loss, and testing for backup restoration scenarios. Our hosting provider, FranTech, ensures infrastructure resilience with multi-homed data centers, robust security measures, and a proven record of disaster recovery.

Team notes

Taken this from Ferantech or buyvm.net.


Does your organization engage executive oversight for cybersecurity? If yes, describe your organization’s information security governance structure

Yes, our organization engages executive oversight for cybersecurity.


Does your organization have a designated Information Security Officer? If not, who has primary responsibility for your organization’s information security program

No, our organization does not have a designated Information Security Officer. The primary responsibility for our information security program rests with the Vice President and the Web Developer.


Does your organization have defined, documented information security standards, policies, and supporting procedures? If yes, identify the foundational framework (NIST, ISO, et. al.) in use

Yes, our organization maintains a documented information security policy and procedures aligned with NIST 800-53 and ISO/IEC 27001 frameworks. This policy covers access control, data classification, encryption standards, incident response, backup and disaster recovery, personnel security, vendor management, and regulatory compliance. We also comply with PCI DSS through quarterly third-party audits, and our platform delivery follows SOC 2 Type 2 controls.


Does your organization engage in information security audits and/or risk assessments? If yes, how often are they performed? Are these engagements performed in-house or outsourced to third parties

Yes, our organization conducts information security audits. We use third-party PCI audits for customer payment information, performed quarterly.


Does your organization outsource - in whole or in part - cybersecurity functions to third party service providers? If yes, identify the outsourced functions and those performed in-house

Yes, our organization outsources cybersecurity functions in part. PCI audits are performed by a third party, while all other cybersecurity functions are handled in-house.


Is your proposed product or service considered a medical device subject to regulation by the Food and Drug Administration? If yes, provide a Manufacturer Disclosure Statement for Medical Device Security (MDS2) for each proposed product/service

No, our proposed service is not considered a medical device subject to regulation by the Food and Drug Administration.


Does your proposed product or service require access to customer confidential data? If yes, please identify the necessary data elements. “Confidential data” refers to Protected Health Information (HIPAA), Cardholder Data (PCI), or other data intended for restricted access or use

No, our proposed service does not require access to or use of customer confidential data, including Protected Health Information (HIPAA) or Cardholder Data (PCI).


Is a formal software development process in place that includes application security requirements

Yes, we follow a Secure Software Development Lifecycle (SDLC) that includes application security requirements.


Are security reviews and regression testing performed on application source code

Yes, security reviews and regression testing are performed on Moodle’s application source code. Regular security audits and automated regression tests are conducted to ensure security and functionality.


Is the proposed product or service subject to industry certifications? If yes, please describe. If your product or service is subject to SOC 2 requirements, please provide your most recent report

Yes, our proposed product Moodle is developed and delivered in accordance with industry-recognized security standards. Moodle U.S. has achieved SOC 2 Type 2 and SOC 3 compliance, as verified by an independent audit. You can read more about this achievement in the official Moodle news release.

While the Moodle platform and our managed services are compatible with SOC 2 requirements, please note that individual client Moodle instances are not automatically certified at the time of installation. If a client requires SOC 2 certification for their specific instance, this can be pursued as a separate process, but it is not included in the standard offering or price. Additionally, Moodle relies on its hosting providers for other certifications such as ISO/IEC 27001, SOC 2 (via AWS), and GDPR compliance.


Does your organization staff its data centers? If not, identify your data center service provider. Identify the number and location of your data centers

We use BuyVM as our data center provider. Their data centers are located in Las Vegas and New York.


Are any of your organizations’ data centers located outside of the United States? If yes, please identify the locations of these “offshore” data centers

No, all our data is stored within the United States, specifically in the data centers located in Las Vegas and New York.


If offshore data centers are in use, are they staffed by your organizations’ workforce or outsourced to third-parties? If outsourced, please confirm that staff agreements cover appropriate data confidentiality requirements

No, all of our data centers are located within the United States. We do not utilize offshore data centers.


Are periodic vulnerability scans performed on information technology systems, networks and supporting security systems

The PCI audit is conducted by a third party on a quarterly basis. This includes vulnerability scans of our IT systems, networks, and supporting security systems to ensure compliance with PCI standards.


Does your organization conduct penetration testing of internal and external data environments? If yes, is the testing performed in-house or outsourced to third parties? How often is penetration testing performed

Penetration testing is part of the quarterly PCI audit and is conducted by a third party.


Does your organization maintain a cybersecurity incident response plan? If yes, how often is the plan tested and updated? What manner of testing is used

Yes, we maintain a cybersecurity incident response plan. The plan is tested annually through simulated exercises to ensure readiness. It is updated regularly based on lessons learned, emerging threats, and any organizational changes.


Secure files transfer

Provides secure file transfer capabilities through encrypted protocols for uploading, downloading, and managing files. Files uploaded to the platform are stored securely on the server, and administrators can set permissions to control who can access, download, or modify files. Moodle supports SSL encryption for secure data transmission and allows restricted access to sensitive content based on user roles.


Does your system provide an approval workflow, including notifications that inform learners and supervisors of enrollments that require approval, new enrollments for themselves and direct reports, and enrollment cancellations

Moodle does not have built-in approval workflows, but this can be achieved by installing plugins like “Enrolment upon approval” or “Course Request Approval”. Notifications can be configured through Moodle’s messaging system.


Does your system include regular automated data backups and disaster recovery measures

Moodle supports automated backups of courses, user data, and configurations, and includes disaster recovery options for system restoration in case of failures.