SOFTWARE & DATA SECURITY

Last updated: [11/2025]

At Certify Assessment Solutions (CAS), we take platform security, data protection and service reliability extremely seriously. All CAS platforms(SmarTest Examiner, SmarTestInvigilate, and SmarTest Nexus) are built on secure, modern cloud infrastructure and follow strict technical and organisational controls aligned with UK GDPR, EU GDPR, and ISO/IEC 27001 principles.

Below is a summary of how each platform handles data protection, hosting, encryption, access control and operational security.

1. SmarTest Nexus – Hosting & Security

Hosting:
Nexus is hosted on Amazon Web Services (AWS) using:

• Amazon EC2 for compute
• Private IP addressing
• Customised Virtual Private Cloud (VPC) isolation

Security Controls:

• Enforced role-based access controls
• Hierarchical permission system for centres, clients and admin roles
• Predefined roles and granular permissions
• Multi-layer firewall and network segmentation
• Continuous system monitoring

Purpose:
Nexus centralises operational data, permissions and site management with controlled access for authorised users only.

2. SmarTest Examiner – Hosting & Security

Hosting:
Examiner is hosted on Microsoft Azure (EU data centres), using:

• Azure App Services
• Azure SQL Database
• Azure Storage accounts
• Azure Security Center
• Azure Access Control (IAM/RBAC)

Security Controls:

• Microsoft Defender threat protection
• Custom firewall rules and network security groups
• Encrypted storage at rest and in transit
• Secure REST API communication (TLS 1.3 minimum)
• Virtual Network (VNet) integration with private DNS

Access Management:

• Predefined roles and responsibilities
• Only authorised users may access sensitive assessment data
• Log Analytics and Application Insights for monitoring
• Continuous uptime monitoring and failover protections

 

3. SmarTest Invigilate – Remote Proctoring Security

Hosting:
Invigilate runs on AWS using:

• AWS Fargate (ECS) for isolated proctoring sessions
• Custom VPC configuration
• Route53 DNS
• DynamoDB for metadata storage
• S3 for secure session storage
• API Gateway (HTTPS / WebSocket)
• Custom OAuth 2.0 authentication

 

Security Controls:

• Every test-taker receives an isolated compute environment
• No external access to DynamoDB
• All session recordings encrypted and stored on S3
• IAM-based access control for proctors and administrators
• TLS 1.3 enforced for all data in transit
• Automated monitoring and health checks for infrastructure

 

Data Protection:

• Sessions stored only for the period required for audit / review
• Strict access controls—only authorised reviewers and audit staff
• AI-supported anomaly detection used (advisory only), with human review always required
 

4. Encryption & Network Security

All CAS platforms enforce:

• TLS 1.3 for encrypted data in transit
• AES-256 encryption for data at rest (AWS & Azure defaults)
• Strict firewall rules and VPC segmentation
• No publicly exposed databases
• Isolation between client tenants

 

5. Access Control & Identity Management

• Role-based access control (RBAC) across all platforms
• Multi-factor authentication where required
• Least-privilege access model
• Logged and audited administrative actions
• Regular user access reviews
 

6. Monitoring, Logging & Audit

• Automated alerts (Failures, anomalies, network health, suspicious events)
• Server and workload monitoring via AWS CloudWatch and Azure Monitor
• Internal audit reviews and quality checks
• DVR/video review processes for proctored sessions
• Application-level logging and audit trails

 

7. Data Locations & Compliance

All infrastructures used by CAS are hosted within the European Union.

Data is never stored outside the UK/EU unless explicitly required and protected by:

• Standard Contractual Clauses (SCCs)
• UK IDTA / Addendum
• Adequacy decisions
• Transfer Risk Assessments (TRAs)
 

8. Business Continuity & Disaster Recovery

• Geo-redundant cloud storage
• High-availability design
• Regular testing of failover and recovery procedures
• Backup and retention aligned with Data Retention & Disposal Policy

 

9. AI Use (CAS)

CAS uses AI within Invigilate only for anomaly flagging, never for decisions.

• No automated decisions
• No AI-based scoring
• Human review is always required
• AI output is advisory and cannot trigger sanctions

Full details are available in our Use of AI page.

10. Related Policies

This page should link to:

• Privacy Policy
• GDPR & Security Overview
• Use of AI Statement
• Cookie Notice
• Candidate & Client Privacy Notice

Request more information

popup-certify-assessment-solutions-2

Contact us to learn more about Certify exam proctoring service and online assessment tools