
ISO 27001
Information security management system framework.
Product Ecosystem
Custom digital training contentOrganization-specific digital learning content — from scenario to delivery
Corporate learning platformManage your training operations from a single hub
Personalized learning experienceEvery employee gets their own learning experience and skill map
Ready digital course catalogStart without waiting: a ready library from five providers
Content development toolsProduce content in-house, fast and with your own team
Learning solutions structured around your goals, industry and skill map.
Talk to an ExpertContent
BlogCurrent perspectives on corporate learning, technology and content designWebinarsExpert sessions with live events and recordingsPodcastConversations and field experiences from the learning worldReference & Explore
L&D GlossaryLMS, LXP, SCORM, xAPI and key concepts A–ZNewsletterNew content and updates in your inboxRead our comparative article to help you decide on the right learning technology.
Read the ArticleAcross industries and scales, the same goal: learning turning into business outcomes.
View StoriesYour partner combining content, technology and consulting under one roof.
Get to Know RespongoWe explain the controls we use to protect your corporate data, the standards we are audited against, and how we act in the event of an incident.
This page summarizes the information security approach applied to the delivery of Respongo products and services. Commitments made under a specific customer contract are defined in the applicable contract and its annexes.
The standards applied at the product and infrastructure layers (such as ISO 27001 and SOC 2 Type II), and whether they belong to Respongo or to an infrastructure/business partner provider, are shared in writing upon request.
Audit reports may be shared with our enterprise customers and prospects, subject to the signing of a confidentiality agreement.
Respongo does not make any certification or compliance claims that cannot be verified.
Periodic vulnerability scans and independent penetration tests (VAPT) are conducted at the application and infrastructure layers. Identified findings are prioritized by severity and remediated within defined timelines.
A defined incident response process is operated for the detection, classification, response to, and reporting of security incidents. In the event of a personal data breach, the notification obligations required by applicable law are fulfilled.
Redundancy, disaster recovery, and business continuity plans are defined to ensure service continuity. Recovery time objective (RTO) and recovery point objective (RPO) values are specified in the service level commitments.
Hosting and infrastructure providers involved in the delivery of the service are engaged under contractual security and data protection obligations. The current subprocessor list is shared upon request.
If you believe you have identified a security vulnerability, please notify us through our contact channels. We review reports and respond within the framework of responsible disclosure principles.
Last updated: July 1, 2026 · For questions, please use our contact page.

Information security management system framework.

Independent audit of the effectiveness of controls over a defined period.

Processing approach compliant with data protection legislation.

Periodic vulnerability scanning and penetration testing.
Contact our team about legal texts, data protection, and security topics.