Security & trust
A defence-in-depth approach across the edge, application and data layers, explained clearly without exposing sensitive operational detail.
Protected before traffic reaches ACE
Layered controls at the web edge keep ACE available and every connection encrypted.
Public traffic passes through a managed firewall at the edge before it reaches ACE.
Attacks aimed at knocking ACE offline are absorbed at the edge, so the service stays available.
Every connection to ACE is encrypted in transit, with modern browsers held to HTTPS.
Strict browser-level policies limit what any page can load or do, reducing exposure to browser-based attacks.
A password is never the whole defence
Identity and role controls mean people reach only what their job requires.
Every account enrols a second factor, so a password on its own is never enough to get in.
Candidate, Assessor, IQA, EQA, Employer and Administrator permissions are separated, with organisation boundaries enforced throughout.
Additional protections sit around sign-in and account recovery to frustrate automated and repeated attempts.
Support access is limited by design, and privileged actions are attributed and recorded.
Protection follows the data
Encryption, separation and recovery controls protect portfolio data throughout its life.
Portfolio data and evidence files are encrypted at rest using industry-standard AES-256.
Each centre’s data is isolated from every other, enforced at the data layer rather than only in the application.
Assessment decisions and sensitive actions are time-stamped and attributed, creating a defensible record.
Backups are automated, encrypted, held separately and checked regularly so they can be relied on.
Cyber Essentials certified
ACE Portfolios holds Cyber Essentials certification, giving independent assurance that we meet the core technical controls of the UK government-backed scheme.
Security questions
Is multi-factor authentication required on ACE?
Yes, on every account. A candidate, assessor, IQA, EQA, employer or administrator cannot use ACE without setting up a second factor.
How is candidate data protected?
Data and evidence files are encrypted at rest with AES-256 and in transit with TLS 1.3. Each centre’s data is isolated from every other centre at the data layer.
Are backups taken and tested?
Yes. Backups are automated, encrypted, held separately from the live system and verified on a schedule so they can be relied on in a recovery.
Is ACE Portfolios Cyber Essentials certified?
Yes. ACE Portfolios holds Cyber Essentials certification, and the certificate is linked from the Security & Trust page.
Who owns the data in ACE?
Your organisation does. ACE acts as a data processor on your behalf, never uses your data for anything other than providing the service, and you can export it at any time.
Questions about security?
We are happy to walk your team or your awarding body through how ACE keeps data safe.
