Ungated · no form

Security and compliance pack

Data residency options, PDPL and GDPR posture, certification status (claimed vs not claimed), penetration-test cadence, DPA outline, and sub-processor classes — downloadable here.

A serious LMS security pack for Gulf procurement states hosting geography (including in-Kingdom options when required), whether logs and backups leave that region, PDPL/GDPR processor duties, encryption and RBAC, independent-testing cadence, a DPA outline, and a sub-processor list. Innovito publishes the posture without a form and does not invent certificate serials or CVE lists on this page.

Export this pack · No gate. No nurture sequence. Downloads are generated in your browser.

Data residency options

  • Saudi Arabia (in-Kingdom)

    Published here

    In-Kingdom hosting is scoped with IT and procurement when the tender requires learner PII and training records to remain in KSA. Confirm primary region, logs, backups, and subprocessors in the written matrix — do not assume a single global cloud.

  • United Arab Emirates

    Published here

    UAE-region or in-country options are available to evaluate against your residency policy. Multi-emirate programmes still need a single matrix for backups and support tooling.

  • Egypt

    Published here

    Egypt hosting is a documented option for programmes that require local or regional constraint. Cross-border analytics must be called out if they leave the chosen region.

  • Regional MENA hub

    Published here

    Multi-country NGOs and enterprises may accept a documented regional hub with subprocessors listed. Government and bank tenders often require a stricter country pin.

PDPL and GDPR posture

  • Saudi PDPL posture

    Published here

    Treat LMS identity, progress, assessments, certificates, and support tickets as personal data. Processor terms, retention, export/delete, and admin audit logs belong in the contract. “We are GDPR-aligned” is not a PDPL answer.

  • GDPR posture (when EU data is in scope)

    Published here

    If EU personal data is processed, GDPR processor duties apply in addition to Gulf regimes. Transfer tools, DPA, and sub-processor notice follow the lawful basis you name — we do not claim a one-page “GDPR certified LMS” badge.

  • DPA / processor terms (template)

    Published here

    A model processor-terms outline is in this pack (roles, categories of data, security measures, sub-processor notice, breach timelines, audit, exit). Counsel must adapt it. It is not a signed agreement.

Certifications and status

  • Stevie® Awards — Innovation in Education or Training Apps

    Published here

    Public, dated recognition: Stevie® Gold for Innovito Evolve (2024 and 2025). This is an award, not an information-security certification.

  • EdTech Digest / Edtech Awards recognition

    Published here

    Public finalist/leadership recognition as published on innovito.net. Not a security control.

  • ISO/IEC 27001

    Not claimed

    Not claimed on this public page. If a current certificate is in force for the relevant entity and scope, it is issued as an evaluator file against your tender reference — we do not publish rotating serials on a marketing URL.

  • SOC 2 Type II

    Not claimed

    Not claimed on this page. Ask for the current independent-assessment inventory in the evaluator pack.

Security controls and penetration testing

  • Encryption in transit and at rest

    Published here

    TLS for traffic; encryption at rest for stored learner and platform data in the contracted cloud class. Cipher and key-management detail is mapped to your questionnaire.

  • Admin RBAC & audit logs

    Published here

    Role-based administration, least-privilege patterns, and admin audit logs for privileged actions. Exact retention of logs is set in the contract.

  • Vulnerability management

    Published here

    Documented intake, severity, and patch cadence for the Evolve application class. Emergency windows for critical issues are agreed in the SLA annex.

  • Independent penetration test — executive summary

    Evaluator file — no form

    Cadence: at least annually and before major regulated go-lives. Scope: web application and API in the contracted environment. Method: OWASP-aligned. Public page does not list CVEs. A dated executive summary is an evaluator file (tender reference, no marketing form). Findings that block go-live are remediated before production cutover for regulated programmes.

  • Backup and restore tests

    Published here

    Backups follow the residency matrix (including whether restore copies leave the pin). Restore tests are part of operational evidence, not a slogan.

  • Incident notification

    Published here

    Notification timelines are contractual. Public marketing copy does not invent a statutory hour-count that belongs in the DPA and local law.

Sub-processor list (classes)

  • Cloud infrastructure / hosting

    Primary hosting provider is named in the residency matrix for your lot (region pin). Not a global default assumed on this page.

  • Transactional email

    Used for invitations, resets, and notifications. Confirm whether message content or logs leave the residency pin.

  • DNS / edge

    Public DNS and edge routing. Typically not learner-record storage; still listed for completeness.

  • Support tooling

    Ticketing may contain personal data. Access limited to authorised support roles; location disclosed in the matrix.

  • Optional AI inference (Studio / Coach add-ons)

    Only if the lot includes AI features. Training-data use and region of inference are scoped — not silently enabled.

DPA template outline

  1. 1. Roles

    Buyer is controller (or as named in local law). Innovito is processor for learner and admin personal data in Evolve. Sub-processors are authorised as listed and updated.

  2. 2. Categories of data

    Identity, organisation, progress, assessment results, certificates, support tickets, technical logs. Special-category data only if the buyer stores it in the LMS.

  3. 3. Security measures

    Encryption, access control, logging, vulnerability process, restore tests — mapped to this pack and the questionnaire.

  4. 4. Sub-processor notice

    Material changes notified per contract. Buyer may object on reasonable privacy/security grounds.

  5. 5. Personal data breach

    Notify the buyer without undue delay and as required by PDPL/GDPR/local law and the contract — not a marketing SLA invented here.

  6. 6. Audit

    Reasonable audit rights, questionnaires, and independent-test summaries. On-site audits by agreement.

  7. 7. Return / deletion

    Export then delete or return within the contracted window after termination, except data retained under law.

Why is there no download form?

Evaluators should not have to join a nurture list to read residency and PDPL posture. Dated serials still go to the procuring entity with a tender reference.

Can learner data stay in Saudi Arabia?

Yes when the lot requires it. Scope the matrix (primary, logs, backups, subprocessors) with IT before scoring. Innovito does not assume a single global cloud.

Educational and evidentiary material for procurement and IT evaluators. Adapt with your legal, privacy, and information-security counsel. Commercial terms, SLAs, and certificate serials are confirmed in the bid — not invented on this page. · Information security and privacy reviewers