Security & privacy

    Your employees' data is safe with us

    The data we process in Learned is stored according to the highest security regulations, in Germany on the Google Cloud Platform. We work from the Netherlands and are ISO27001 certified, AVG compliant and perform a penetration test on our platform at least once a year.

    Beveiliging & privacy

    Trusted by leading companies

    EmixaFellowmindConclusionBerenschotSiersIntratuin
    EmixaFellowmindConclusionBerenschotSiersIntratuin

    General information

    ISO27001

    Learned is ISO27001 certified by TUV Netherlands. Our ISO certificate and declaration of applicability are available upon request.

    AVG/GDPR compliant

    We comply with the AVG. Our data and server is stored in Germany at Google Cloud. More information can be found in our SLA and Processor Agreement.

    99.99% uptime

    Our software platform is almost always available. We perform any updates outside business hours.

    AI Impact Assessment

    Our AI features are covered by the EU AI Act; we have prepared an AIIA for this purpose. Data in Learned is not used to train AI models and is not processed outside the EU.

    Security

    Communication

    All communication with Learned (via chat or email) is always encrypted with the latest version of TLS.

    Encryption

    TLS and authentication (SCRAM) are a standard part of Google Cloud. Data sent to the database (in transit) is encrypted with TLS. Encryption for data in rest is automated via Google Cloud Platform transparent disk encryption, which uses Advanced Encryption Standards (AES-256).

    Pen test

    At least once a year, an external party performs a pen test on the Learned platform.

    Single-Sign-On (SSO)

    To log in easily and securely, we offer SSO from Microsoft Azure and Google.

    (Forced) MFA

    You can choose additional verification with MFA. Can also be made mandatory company-wide.

    Authorization, rights and roles

    Set up access to Learned manually or automatically through integration with your human resources system.

    Learned infrastructure

    The data is stored at Google Cloud in Germany with a MongoDB database. See our processor agreement for more information about our IT landscape.

    Back-ups

    Google Cloud automatically saves backups for us. A backup is restoreable by the minute (for point-in-time restore), is stored encrypted and stored up to 7 days back.

    Need to know

    All knowledge and access to systems within Learned are set up on a "Need to Know" basis.

    Security awareness

    All of our colleagues must go through training on information security. We also attend additional training several times a year.

    Incidents

    All information incidents are logged. We resolve incidents according to urgency and impact. More info can be found in our SLA.

    Support

    All Learned users can chat real-time with our support team for questions and/or incidents. See our SLA for more information.

    Data export

    Customers can always export their data from the platform to CSV or PDF without Learned's intervention. Part of our SLA is an exit procedure.