
LMS Security
Secure LMS technology to protect your data, users, and learning environments
LMS Security
Enterprise-grade security designed to protect your learning environment and data.
Organizations depend on their learning management system to store important user information, training records, course activity, and compliance data. LMS Portals incorporates multiple layers of application, server, and database security to help protect this information and provide organizations with a secure environment for delivering online training.
​
Our security approach combines data isolation, encryption, access controls, secure development practices, database protection, and ongoing backup procedures to reduce risk and protect the integrity of each LMS environment.
​
Secure, Isolated LMS Environments
LMS Portals is designed to support organizations that manage training across employees, customers, partners, members, contractors, and other learning audiences.
​
Each LMS portal is supported by a dedicated database, helping separate portal data rather than combining every customer and learning environment within a single database.
This architecture provides greater data isolation while supporting the flexibility of the LMS Portals multi-tenant platform.
​
Dedicated Database Architecture
A dedicated database is created for each new LMS portal.
This approach helps LMS Portals:
-
Maintain separation between portal data
-
Reduce exposure between learning environments
-
Improve database management and troubleshooting
-
Support system performance
-
Reduce the potential impact of a database-level security incident
Organizations can therefore create and manage multiple branded learning environments while maintaining logical separation of their training data.
​
Data Encryption and Credential Protection
LMS Portals uses encryption and secure credential-management practices to help protect sensitive information.
​
Sensitive information stored within the database is encrypted, while passwords and other credentials are protected rather than stored in easily readable formats.
Security measures include strong cryptographic hashing for passwords, encrypted storage of sensitive credentials, and protection of encryption keys, API keys, client IDs, passwords, and other confidential information.
These controls help reduce the risk of sensitive information being exposed if application or database information is accessed improperly.
​
Strong Password Controls
Strong passwords are an important component of account security.
​
LMS Portals applies password validation requirements designed to make passwords more difficult to predict or compromise.
Password requirements include a minimum of eight characters and a combination of uppercase and lowercase letters, numbers, and special characters.
These controls provide an additional layer of protection for administrators and LMS users.
​
Application Security
LMS Portals incorporates secure application-development practices designed to reduce exposure to common web application vulnerabilities.
​
User-supplied information is validated and sanitized before it is processed or displayed, and database queries use techniques designed to protect against SQL injection attacks.
Application security controls are designed to help prevent unauthorized manipulation of LMS data and reduce the risk associated with malicious input.
​
Server Hardening and Access Controls
Access to the infrastructure supporting LMS Portals is restricted using server-security measures designed to prevent unauthorized access.
​
Server protection measures include limiting repeated failed access attempts and using secure SSH connections that require security-key authentication.
Administrative and database access is also restricted so that sensitive systems are not openly accessible from the public internet.
These controls help limit access to authorized systems and personnel.
​
Restricted Administrative Access
Administrative database applications are protected from direct public access.
​
Attempts to access restricted administrative URLs without authorization are blocked, and database administration access can be limited to specifically authorized IP addresses.
Database credentials are also protected so users do not have direct access to dedicated database authentication information.
This helps create another layer of separation between the public-facing LMS application and the systems used to manage its underlying data.
​
Secure Database Design
Database security goes beyond restricting access.
​
LMS Portals incorporates database controls and architecture designed to maintain data integrity and reduce unnecessary exposure.
These practices include database indexing, relational constraints, controlled cascading of related records, dedicated database credentials, and structured database management.
The platform also follows a data-minimization approach by avoiding the storage of confidential information that is not required for operation of the LMS.
When information is no longer required, it can be removed rather than unnecessarily retained.
​
Protection Against SQL Injection
SQL injection is a common application-security risk in which malicious database commands are introduced through application inputs.
​
LMS Portals uses structured query-building and input-handling techniques designed to prevent unauthorized SQL commands from being executed through the LMS application.
These protections help maintain the integrity of LMS databases and reduce the risk of unauthorized data access or modification.
​
Daily Database Backups
Data availability is an important component of platform security.
​
LMS Portals maintains a process for backing up databases every day. Backups provide an additional layer of protection against potential data loss resulting from hardware failures, corruption, security incidents, or other unexpected events.
Maintaining separate backups helps support recovery of critical LMS information when necessary.
​
Data Minimization
An effective security strategy includes protecting the information an organization maintains as well as limiting unnecessary information in the first place.
​
LMS Portals minimizes the amount of confidential information stored within its databases whenever possible.
Information that is no longer needed can be removed, while information that must be retained for compliance or operational purposes can be managed according to appropriate retention requirements.
This approach helps reduce the amount of sensitive data potentially exposed in the event of a security incident.
​
Security for Multi-Tenant Learning
Organizations frequently use LMS Portals to create separate learning environments for different departments, customers, partners, locations, brands, or business units.
​
The LMS Portals architecture combines centralized administration with dedicated portal environments and database separation, helping organizations scale their learning programs while maintaining appropriate boundaries between different audiences.
Administrators gain the efficiency of managing learning through one LMS platform without requiring every audience to operate within the same shared learning environment.
​
A Secure Foundation for Online Training
​Security is essential whether an organization is delivering employee training, compliance programs, customer education, partner training, association learning, or extended enterprise training.
​
LMS Portals provides a secure cloud-based LMS architecture designed to protect training environments while giving organizations the flexibility to create and manage multiple branded portals from one centralized platform.
Build secure learning environments for every audience with LMS Portals.