Legal
Security at SkillsCredX
How we protect your professional identity, learning records and credentials — from encryption to responsible disclosure.
Last updated: 24 July 2026
Please note
This document is provided as a general template and starting point. It is not legal advice. SkillsCred Private Limited recommends that it be reviewed and adapted by qualified legal counsel to reflect current law and the company's specific practices before it is relied upon.
Our approach to security
Security is central to how we build and run SkillsCredX. As a platform that holds students' professional identities, learning records and credentials, we take a defence-in-depth approach — combining people, processes and technology to protect your data. This page summarises the measures we have in place. It is a general description rather than an exhaustive specification.
Infrastructure and encryption
- Data is transmitted over encrypted connections using industry-standard TLS;
- Sensitive data is encrypted at rest using strong, widely adopted algorithms;
- We host on reputable cloud infrastructure with physical and network security controls;
- Environments are segmented so that production data is isolated and access is restricted.
Access controls
- Access to systems and data follows the principle of least privilege — people can reach only what their role requires;
- Administrative access requires strong authentication, and we support multi-factor authentication for accounts;
- Access is logged and reviewed, and is removed promptly when no longer needed.
Application security
- We follow secure development practices and review code before it ships;
- We use automated and manual testing to find and fix vulnerabilities;
- Third-party components are monitored and kept up to date;
- We apply safeguards against common web threats such as injection and cross-site scripting.
Assessment and proctoring integrity
For proctored assessments, monitoring data is collected only with your consent, only for the assessment you take, and is protected with the same care as other sensitive data. It is used to uphold the integrity of credentials and is handled in line with our Privacy Policy and User Agreement.
Standards and certifications
Our practices are designed to align with recognised information-security standards, including the principles of the ISO/IEC 27001 information security management framework. We continually review our controls as the platform and the threat landscape evolve.
A note on standards
Where we reference standards such as ISO/IEC 27001, we describe alignment with their principles. Current certification status can be confirmed with our team on request.
Backups and resilience
- We take regular backups so that data can be recovered if something goes wrong;
- We monitor availability and performance, and maintain plans to respond to incidents;
- We aim to detect, contain and remediate issues quickly and to notify affected users where required.
Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in the SkillsCredX platform, please report it privately to security@skillscredx.com and give us a reasonable opportunity to investigate and fix it before any public disclosure. Please do not access or modify data that is not yours, and act in good faith to avoid harming users or the service.
Your role in security
Security is a shared responsibility. You can help protect your account by:
- Choosing a strong, unique password and enabling multi-factor authentication;
- Keeping your login details private and signing out on shared devices;
- Being alert to phishing and only entering your credentials on skillscredx.com;
- Reporting anything suspicious to us promptly.
Contact us
Questions about this policy?
We are happy to help. Write to us and a member of the team will respond.
support@skillscredx.comSkillsCred Private Limited · Anna University Campus, Chennai, Tamil Nadu, India