ExamLense

Security and privacy

Most of the protection is data that never exists

The cheapest way to keep candidate data safe is not to collect it. Where collection is unavoidable, here is exactly what happens to it, and the frameworks we hold ourselves to.

Compliance

The frameworks we build and operate against

ExamLense strictly follows the compliance guidelines set out in SOC 2, the GDPR, Ghana's Data Protection Act, and the equivalent data protection laws of every market our institutions operate in. Where a market adds a requirement, we meet the stricter of the two rather than the more convenient.

  • SOC 2 Security, availability and confidentiality controls across the platform
  • GDPR Lawful basis, data subject rights, and minimisation by default
  • Ghana Data Protection Act Act 843, covering processing and retention in our home market
  • Equivalent laws worldwide Local data protection regimes in every market an institution operates in

Controls

What that means in practice

Each of these is something you can hold us to during a procurement review or a security questionnaire.

Where data lives

  • Data is held on managed infrastructure inside the European Union, encrypted at rest and in transit
  • Recorded media is never publicly reachable and is served only through short-lived, signed links that expire
  • Media never travels through the application interface, so an interface flaw cannot expose a recording
  • Session state expires on a timer rather than lingering until somebody remembers to clear it
  • Residency in another region is available where a contract requires it

Tenant isolation

  • Every institution is a separate tenant on shared infrastructure
  • Records and stored files are partitioned by institution at the storage layer
  • The tenant is derived from a validated credential in shared middleware, never from anything the browser sends
  • No interface accepts a tenant identifier from the client as the basis for reading data

Access and identity

  • Staff accounts require multi-factor authentication
  • Candidates never hold accounts. They carry a short-lived credential scoped to one exam
  • Internal services authenticate with rotating machine identities, never stored passwords
  • Least privilege is applied per service, so a compromise is contained to that service

Separation of duties

  • Reviewers cannot modify exams, exam rules, or licences
  • Administrators cannot modify a review determination
  • Crediting a licence pool requires a second operator to approve it
  • The separation is enforced in the interfaces and behind them, not by policy alone

Candidate privacy

  • On the Lite tier the checks happen live and nothing is written down. No biometric media is retained
  • The tier system exists so an exam is never recorded more heavily than it warrants
  • No government ID registry is ever contacted, in any market
  • Retention periods are yours to set, and deletion actually happens on them
  • Candidate data is never sold, never shared for advertising, and never used to train anything

Engineering practice

  • Infrastructure is defined as code. Every change shows its effect before it is applied
  • Deployment uses short-lived federated credentials. There are no long-lived cloud keys anywhere
  • Dependency and infrastructure scanning run on every change
  • A new high-severity finding blocks the release
  • The audit record is append only. Reviewer decisions, administrator actions and result changes are written once and never edited

In practice

What the controls protect

Due diligence

What we will put in writing

This page states the guarantees. It deliberately does not name the products and services behind them, because that detail helps an attacker and a competitor more than it helps a buyer.

Under an NDA we go much further: the architecture, the sub-processor list, data flow diagrams, the retention schedule, incident response commitments, and completed answers to whichever questionnaire your institution uses. Ask early rather than at the end of a procurement cycle, and you will get a straight answer about what exists today.

Send us your security questionnaire

We would rather answer it now than at the end of a procurement cycle.