ACE Assessor Crafted E-portfolios
ACE Assessor Crafted E-portfolios

Security & trust

A defence-in-depth approach across the edge, application and data layers, explained clearly without exposing sensitive operational detail.

EDGE & TRANSPORT

Protected before traffic reaches ACE

Layered controls at the web edge keep ACE available and every connection encrypted.

Web application firewall

Public traffic passes through a managed firewall at the edge before it reaches ACE.

Denial-of-service protection

Attacks aimed at knocking ACE offline are absorbed at the edge, so the service stays available.

Encrypted connections

Every connection to ACE is encrypted in transit, with modern browsers held to HTTPS.

Hardened in the browser

Strict browser-level policies limit what any page can load or do, reducing exposure to browser-based attacks.

IDENTITY & ACCESS

A password is never the whole defence

Identity and role controls mean people reach only what their job requires.

Multi-factor authentication

Every account enrols a second factor, so a password on its own is never enough to get in.

Role-based access

Candidate, Assessor, IQA, EQA, Employer and Administrator permissions are separated, with organisation boundaries enforced throughout.

Sign-in safeguards

Additional protections sit around sign-in and account recovery to frustrate automated and repeated attempts.

Restricted support access

Support access is limited by design, and privileged actions are attributed and recorded.

DATA & RESILIENCE

Protection follows the data

Encryption, separation and recovery controls protect portfolio data throughout its life.

Encrypted at rest

Portfolio data and evidence files are encrypted at rest using industry-standard AES-256.

Separated by organisation

Each centre’s data is isolated from every other, enforced at the data layer rather than only in the application.

Tamper-evident audit history

Assessment decisions and sensitive actions are time-stamped and attributed, creating a defensible record.

Verified backups

Backups are automated, encrypted, held separately and checked regularly so they can be relied on.

INDEPENDENTLY CERTIFIED

Cyber Essentials certified

ACE Portfolios holds Cyber Essentials certification, giving independent assurance that we meet the core technical controls of the UK government-backed scheme.

ICO registeredUK companyDesigned to support UK GDPR obligations

Security questions

Is multi-factor authentication required on ACE?

Yes, on every account. A candidate, assessor, IQA, EQA, employer or administrator cannot use ACE without setting up a second factor.

How is candidate data protected?

Data and evidence files are encrypted at rest with AES-256 and in transit with TLS 1.3. Each centre’s data is isolated from every other centre at the data layer.

Are backups taken and tested?

Yes. Backups are automated, encrypted, held separately from the live system and verified on a schedule so they can be relied on in a recovery.

Is ACE Portfolios Cyber Essentials certified?

Yes. ACE Portfolios holds Cyber Essentials certification, and the certificate is linked from the Security & Trust page.

Who owns the data in ACE?

Your organisation does. ACE acts as a data processor on your behalf, never uses your data for anything other than providing the service, and you can export it at any time.

Questions about security?

We are happy to walk your team or your awarding body through how ACE keeps data safe.