Third Party Index

Snapshot 21411

Document
Trust center
URL
https://adeption.io/trust-center
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
215864 bytes
SHA-256 (raw)
d2c5e879d600650a3072b405ce9431d932a007fec4ac0992861c786046beb857
SHA-256 (normalized text)
7cb5b3d1b2bd6799b479d02d9f37fc6180dad505490225bcf960a28f2031b44e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
How we're securing and protecting
your information
Trust Center
How we're securing and protecting
your information
Security is more than just secure software.
Intertek has certified Adeption’s conformity with ISO/IEC 27OO1:2O22, recognizing that we manage data securely across every level of our organization. From our technical infrastructure to our internal decision-making, we follow global best practices to keep your information safe.
Our Trust Center outlines how we do this.

Data security
We respect and protect your personal data

Product security
We provide a secure platform environment
s
Infrastructure security
Safeguarding your data

Use of AI
We use AI in a considered way
We respect and protect your personal data
At Adeption, we understand the significance and value of the data entrusted to us by our clients and stakeholders. Our commitment to safeguarding this data is unwavering and is at the very heart of our operations. Recognizing the rapidly evolving digital landscape and the complexities of modern cyber threats, we have implemented robust measures that encompass application security, identity protection, infrastructure security, and rigorous adherence to compliance and industry standards. This document serves to outline our comprehensive data security policies, reflecting our dedication to ensuring that our digital environments are resilient, secure, and trustworthy. Our approach to data security is not just about protecting our business; it's about preserving the trust and confidence our clients have placed in us, and we are steadfast in our commitment to uphold and reinforce this trust every day.
Adeption’s information security policy is available here.
For Security Documentation and Frequently Asked Questions, visit our Security FAQ’s page here.
Last updated September 2O26.
We provide a secure platform environment
We are dedicated to giving our customers a highly secure and dependable environment since we know they want us to protect their data to the greatest standards. Our security model and controls are based on international standards and industry best practices, such as ISO/IEC 27OO1:2O22, and OWASP Top 1O.
Application Security
Security is embedded throughout our software development lifecycle. We apply secure design and coding practices from the earliest stages of development and integrate automated security checks, static code analysis, unit testing and end-to-end testing into our controlled CI/CD process.
We also have ongoing application security testing and periodic penetration testing to identify and remediate vulnerabilities that may not be detected during development. You can read more about Adeption’s application security processes here
Identity Protection
Adeption uses Azure AD (Active Directory) for identity management. Azure AD's identity management capabilities improve security, simplify user access, and reduce the reliance on passwords, ultimately enhancing the overall security posture.
Single Sign-On (SSO): Azure AD enables users to sign in once and access multiple applications and services without the need for separate passwords. This enhances convenience and productivity while reducing the risk of weak or reused passwords.
Password Protection: Azure AD Password Protection helps prevent the use of weak or easily guessable passwords by enforcing custom password policies and blocking common password patterns. It helps protect against brute force attacks and significantly strengthens the security of user credentials.
Multi-Factor Authentication (MFA): Azure AD supports MFA, which adds an extra layer of security by requiring users to provide additional verification factors (such as a mobile app notification, SMS code, or biometric data) during the sign-in process. MFA significantly reduces the risk of unauthorised access even if passwords are compromised.
We safeguard your data
Infrastructure security is crucial for maintaining the confidentiality, integrity, and availability of data and systems. We’ve partnered with Microsoft Azure, taking full advantage of their Cloud services. These services allow us to capture, process and store data securely while respecting data sovereignty.
Data Hosting and Storage
Adeption services and data are hosted across multiple Availability Zones in Microsoft Azure facilities in Dublin, Ireland (north-eu). We have also established a disaster recovery site in Amsterdam, Netherlands (west-eu). This allows us to provide a reliable service and keeps your data available whenever you need it. These data centres employ leading physical and environmental security measures, resulting in highly resilient infrastructure. Further information is available here.
Data Encryption
Adeption encrypts all data both in transit and at rest:
Traffic is encrypted using TLS 1.2 with a modern cipher suite
Customer data is encrypted at rest using industry-standard AES-256 encryption.
Credentials are hashed and salted using a modern hash function
Additional Infrastructure Security
Our infrastructure is protected using multiple layers of defence mechanisms, including:
A web application firewall (WAF) for content-based dynamic attack blocking
DDoS mitigation
Comprehensive logging of network traffic, both internal and edge
Endpoint Security
Adeption enforces endpoint security for all devices that access its networks and systems. Adeption uses Sophos XDR and MDM to protect devices and to ensure they are free of security threats and applies policies to devices to reduce risk of data loss and unauthorized access.
Failover and DR
Adeption was built with disaster recovery in mind. All of our infrastructure and data are spread across 2 Azure datacenters and will continue to work should any one of those data centres fail.
Our latest Disaster Recovery (DR) plan is available here.
Data Retention
Adeption complies with the internationally recognized standards for data protection and security (including GDPR requirements). A client or end user can request at any time to have their data removed or deleted from the platform and Adeption will do this.
Note: If user data is deleted from the platform, users cannot reactivate this data. Adeption recommends that users maintain their account even after completing an experience so that this data is available for a future experience that they may engage in.
Adeption users have access to an independent arbitrator (AAA-ICDR) should they have any data protection concerns.
External Certification, Security Audits and Penetration Tests
Adeption is ISO/IEC 27OO1:2O22 certified with Intertek UKAS across all of its entities and regions.
Click here for Adeption’s ISO certificate.
Adeption regularly engages an independent third-party organization to assess and evaluate the effectiveness of our security controls, practices, and policies, providing an objective perspective and validating the robustness of the data security measures in place. Adeption engages reputable independent security specialists to conduct annual penetration testing of both its application and supporting infrastructure.
The latest security Certificates and Test Results can be retrieved from our Security Documentation Page here.
Subprocessors
Adeption engages Subprocessors to power its platform and run the business. These partners maintain industry standards related to information security and data protection. Below is a full list of Adeption’s Subprocessors and how they use the data shared with them. Adeption Sub Processors
What personal data we collect and how use it
Adeption requires name and email address as mandatory information. This is the only mandatory personal identifiable information (PII) Adeption stores. Optional PII includes a user’s position, title and phone number. Adeption also stores non-personal information including: written responses to questions, photos or videos as a part of their coaching experience. Further information about the information that Adeption uses is shown in the section below - The Data Adeption Processes.
Security controls
Click the link for a downloadable summary of Adeption’s Information Security Controls.
What data we process
The Adeption platform distinguishes between three distinct types of data:
Customer Data
Resultant Data
System Data
Data Definitions
"Customer Data" means information, data and other content, in any form or medium, that is uploaded or inputted by the Customer (including its participants) into the Platform, including personal information and confidential information.
“Resultant Data” means any data derived from or generated by the Platform, in aggregated and anonymised form, from data inputted into the Platform including the Customer Data. Such Resultant Data shall not identify any individual or otherwise include any personal information.
“System Data” means all data automatically generated, collected, or derived by the Platform in connection with the provision or use of the Platform, including, without limitation, usage statistics, performance metrics, and other metadata pertaining to the operation of the Platform. For the avoidance of doubt, System Data does not include any Customer Data or other information capable of identifying an individual.
Data Ownership and Usage
Customer Data is owned entirely by the Customer. Adeption uses Customer Data exclusively to provide, maintain, and deliver the Services to the Customer and its designated users in accordance with our service agreements.
Resultant Data is owned entirely by Adeption and is not related to any one person or Customer. Because this data is non-identifiable and structurally separated from any personal or organization-specific records, Adeption may use Resultant Data to develop generic insights and improve the services and the Platform.
System Data is owned entirely by Adeption. As this is automatically generated data that relates solely to platform activity of all users, Adeption may use System Data to guide Platform development and improve performance of its services and the Platform.
For more information on the types of Data Adeption processes - refer to our FAQs here.
We use AI in a considered way
Adeption applies innovative technology to engage users in coaching experiences leveraging the principles behavioral science. One such technology is Artificial Intelligence (AI) which Adeption applies in several ways:
Tool and insight prediction
Leadership mindset indication
AI questions and responses in coaching workouts
Adeption has developed its own Proprietary AI (algorithms) to provide these features and range of leadership development solutions. Adeption’s AI is not open source and does not share any data outside of our client environments. Adeption uses non-identifiable aggregated data to improve its accuracy of AI features and does not use personal information for any training.
Additional security measures
Employee training
All our employees undergo thorough information security awareness training during onboarding. Further security training and awareness programs are provided on a regular basis.
Security policies
Adeption has developed a comprehensive set of information security management system policies that are aligned with ISO27OO1 standards. These policies are updated frequently and shared with all employees.
Employee vetting
Adeption performs background checks on all new employees in accordance with local laws. The background check includes verification and criminal checks.
Employee confidentiality
All employee contracts and contractor agreements include a confidentiality agreement. Additionally all employees with privileged access need to agree to additional system administrator confidentiality terms.
If you would like any further information,
please get in touch
CONTACT US