Software & Data Security

At Certify Assessment Solutions, we understand the importance of security and data privacy when it comes to our assessment platforms. That’s why we’ve implemented robust hosting solutions and built-in security systems to ensure your data is protected at all times. Our Smartest Suite of assessment platforms includes Smartest Examiner, Smartest Invigilate and Smartest Nexus, all of which are designed to comply with the European Union’s General Data Protection Regulation (GDPR).

The SmarTest Nexus platform is hosted on Amazon Web Services (AWS) utilising  AWS’s Elastic Compute Cloud (EC2) server units. It employs unique IP addresses for each EC2. The platform’s access and permission infrastructure feature predefined roles and permissions for users and groups, with a hierarchical access system allowing only authorised users to access specific data.

The SmarTest Examiner platform is hosted on Azure (provided by Microsoft) cloud services, which provide privacy and security for data in transit and at rest. With Azure’s Access control (IAM) and role-based access control (RBAC), we uphold the highest standards of data protection, privacy and control for all users who are accessing the data. Also, Microsoft Defender is active for cloud protection. Custom firewall rules protect the database and don’t allow external access unless required. Our storage is protected and requires secure transfer for REST API operations.

 

We are constantly monitoring our product’s health by checking Failure Anomalies with our custom Smart Detector Alert Rules, Network Watcher, Application Insights (with Smart Detection as well) and Log Analytics to provide 100% uptime and prevent any data loss.

 

Transport Layer Security (TLS 1.3) and SSL ensure secure and encrypted communication for the Examiner’s users and candidates along with customised Network Security Groups. Our application uses a Virtual Network and DNS servers work with Azure-provided DNS service. Examiner’s access and permission infrastructure includes predefined roles and responsibilities for users, with a hierarchical access system that ensures only authorised users can access specific data. Test takers are token users, and once the exams are over, their token expires, and they can no longer access the exam.

Our remote proctoring platform, SmarTest Invigilate, is powered by Amazon Web Services (AWS) infrastructure. We are utilising AWS’s Elastic Container Service (ECS) with AWS Fargate for recording and streaming the test-taker and proctor activities during the session. Invigilate creates a Fargate task/process for each test-taker along with customised VPC (Virtual Private Cloud) settings, which increases security.

 

We are using:

 

  • AWS Route53 is in use for DNS management.
  • AWS DynamoDB is in use for database records and doesn’t allow any external access and only communicates via our secure API.
  • AWS S3 for storage. Sessions are recorded and securely stored on S3 for post-exam review and audit purposes.
  • AWS API Gateway with HTTP and WebSocket protocols for internal and external purposes and customised OAuth 2.0 (and applying 2.1) helps secure communications and integrations.
  • Customised OAuth 2.0 for Authentication instead of AWS Cognito to utilise higher security and region support.
  • With AWS IAM for access control and encryption, we uphold the highest standards of data protection, privacy and control for all users who are accessing the data.
  • TLS 1.3 and automatically and regularly updated SSL for all the users of the platform for data protection.

We are dedicated to monitoring and improving our security and data privacy measures to ensure the highest level of protection for our clients’ data and compliance with GDPR regulations. We audit regularly our systems and procedures to ensure that we are providing the highest level of security and compliance for our clients. Trust that your data is safe with us at Certify Assessment Solutions.

Universal Square
Main Building, 3rd Floor
Devonshire St. North
Manchester
M12 6JH
United Kingdom

© 2018 - 2024 Certify Assessment Solutions Ltd