Security overview.
How we protect the platform and the people whose data it holds. This is a high-level overview for evaluation — we don't publish sensitive implementation detail.
Data protection
- Encryption in transit. All traffic is served over HTTPS/TLS.
- Data minimisation. We collect only what's needed to deliver the service and retain it no longer than necessary.
- Managed data storage. Data is held on managed cloud infrastructure with backup and recovery practices.
- No sale of personal data. We never sell personal data, and we don't use learner data for advertising.
Access control
- Authenticated access. Secure, server-side sessions; passwords are hashed with an industry-standard algorithm and never stored in plain text.
- Role-based permissions. Access is scoped by role so people only see what they should.
- Least-privilege administration. Administrative functions are restricted and role-gated.
- Audit logging. Security-relevant and administrative actions are logged.
Infrastructure & operations
- Reputable managed cloud. Hosted on managed, reputable cloud infrastructure with routine patching.
- Environment separation. Configuration and secrets are managed outside of application code.
- Trusted sub-processors. Third parties (e.g. AI model, email and payment providers) act as sub-processors under data-protection terms. A current list is available on request.
AI safety
AI supports human decisions — it does not make automated hiring or pass/fail decisions about individuals. Content used to generate interviews and feedback is processed by trusted AI providers under contractual data-protection terms, and is used to deliver results, not to train advertising or sell data.
Responsible disclosure
If you believe you've found a security issue, please email hello@missiora.com with details (a dedicated security@missiora.com inbox is being set up). We welcome responsible disclosure and will respond promptly.
Formal certifications (e.g. Cyber Essentials, ISO 27001, SOC 2) and independent penetration testing are on our roadmap as we scale. We're happy to share our current security posture and complete a security questionnaire during evaluation.
Security questions?
Ask us anything — we'll respond openly, and can complete your security questionnaire.