Trust & Security

How Ludus protects your people's data, what we have in place today, and where our certifications are headed.

Last updated 14 June 2026

Architecture & isolation

Every enterprise client runs on a dedicated deployment, not a shared multi-tenant pool.

Encryption

Authentication & access

Application hardening & operations

Privacy & GDPR

For client account data we are the controller; for your learners' data we act as your processor.

Subprocessors

SubprocessorPurposeRegion
Fly.ioApplication hosting & storageEU (Amsterdam)
StripeSubscription paymentsEU / US (DPF)
ZenboxTransactional emailEU (Poland)
Google / Anthropic / OpenAIAI course assistant (only if the client enables it)EU / US (DPF)

Certifications & attestations

We are not yet certified. Our controls are being aligned to the standards below, and we can share a self-assessment today.

Security questionnaire (CAIQ-aligned)

Is customer data isolated between clients?

Yes. Each client runs on a dedicated deployment with its own application, database, storage volume and credentials. There is no shared multi-tenant data store.

Is data encrypted in transit and at rest?

In transit via enforced HTTPS/TLS with HSTS. At rest on encrypted infrastructure volumes. Passwords are PBKDF2-HMAC-SHA256 (200k iterations).

How do you handle user provisioning and offboarding?

Enterprise SSO via OIDC and automated provisioning/deprovisioning via SCIM 2.0. Deactivating a user at the identity provider revokes access immediately, including live sessions.

Do you store payment card data?

No. Payments run through Stripe and Tpay (PCI-DSS Level 1). Ludus never receives card numbers and is out of PCI scope.

Where is data hosted and who are your subprocessors?

Hosted in the EU (Amsterdam) on Fly.io. Subprocessors are listed in the table above; international transfers rely on the EU-US Data Privacy Framework or SCCs.

How do you test your security?

An automated security audit runs weekly (and after any auth/payment change), covering authorization, security headers, cookie flags, path traversal, webhook verification, secret leakage and brute-force throttling. Findings are remediated and logged.

How do we report a vulnerability?

Email hello@luduslms.com. We acknowledge responsible disclosures and respond promptly.