Security Q&A
The five questions corporate security teams
The five questions corporate security teams
ask us most — answered in one place
Certification scope · data protection · vendor due diligence · uptime under load · legal risk —
the checkpoints buyers review before adopting an enterprise LMS.
Key indicators for security teams
The objective baseline TouchClass maintains.
Integrated certifications
ISMS-P & ISO 27001
Both domestic and international standards — audited annually.
Vendor assessments
Top-rated in finance
Highest-tier ratings across multiple financial-institution audits.
Data governance
100% AWS Seoul
All data is stored and processed domestically — no cross-border transfer.
Frequently asked security questions
The questions enterprise security teams raise most often during LMS evaluations.
Domestic and international information-security standards differ based on national regulations and global guidelines. By holding both Korea's top-tier ISMS-P and the global ISO/IEC 27001:2022 simultaneously, TouchClass establishes verified security governance accepted both in Korea and abroad. Annual audits ensure the management system is continuously maintained.
TouchClass applies a standard security architecture end to end — from data creation to destruction.
- Infrastructure security: Operated on AWS with a global cloud-security architecture.
- Domestic data governance: All data is stored and processed in the AWS Seoul region, with no cross-border transfer.
- Standard encryption: Applied to data both at rest and in transit.
- Access control: Least-privilege principle — only authorized personnel can access data.
- Data-loss prevention: Screen-capture prevention and watermarking prevent asset leakage.
Yes. TouchClass actively supports your review, following the security guidelines of large financial institutions and major customers.
- Structured security evidence & guidance: Drawing on our top-rated vendor-assessment track record, we provide standard evidence materials for your due diligence.
- Pre-adoption guidance: From the security pre-assessment stage, we provide practical guidelines to ease the load on your teams.
TouchClass delivers an uninterrupted learning environment backed by years of incident-free operations.
- High-performance architecture for heavy traffic: Optimal learning performance without latency, even under bursty traffic.
- Non-stop service on a high-availability architecture: AWS Multi-AZ redundancy minimizes outage risk.
- Rapid incident response and recovery: Standardized procedures restore service quickly to protect business continuity.
Korea's revised Personal Information Protection Act extends responsibility for security incidents from individual contributors up to executive management. If a breach occurs on an uncertified LMS, companies may face not only financial loss but legal and reputational risk.
- Punitive fines up to 3–10% of total turnover (Article 64-2)
- Punitive damages of up to 5× actual damage (Article 39)
- CEO / representative liability sanctions (Article 30-3)
- Administrative penalties for safety-measure violations (Articles 75 and 66)
Go deeper
Review the reasoning and evidence for each topic on its dedicated page.
Security overview
The full TouchClass security structure, organized in a 4-pillar framework.
Open hub →
Security risks
Sophisticated threats targeting LMS platforms — and how to address them.
Read more →
Security architecture
Technical and managerial controls behind our standard evidence materials.
Read more →
Security guidelines
Checklist and benchmarking data for selecting an enterprise LMS.
Read more →
AI data privacy & ethics principles
“TouchClass does not use any knowledge asset generated or provided by our customers during AI-service usage as training data for AI models.”
- Zero Data Training
(no customer data used for AI training) - Privacy-by-Design
AI architecture - Compliance with data-protection laws
and AI ethics guidelines















