Security & Data Sovereignty in Opigno Enterprise

Closing the gap between the capabilities your organisation needs and the training it delivers means running AI over data about your employees. For a pharmaceutical group, a bank, or any employer under close data protection scrutiny, that is the point at which most learning platforms stop being deployable.

Opigno Enterprise puts that decision in your hands rather than in a contract clause. The tenant environment is the system of record for learner data, and by default the central backoffice holds none of it — users are referenced there only by pseudonymous identifiers. What the backoffice holds is your configuration choice, not ours. The model that processes learning data is likewise yours to choose, running in the jurisdiction you require.

The platform is compliant with ISO 27001 (information security management) and SOC 2 Type 2 (operational controls), and built to meet our obligations as a processor under GDPR.

Data residency, deployment and model choice

All learner personal data is stored locally within the tenant environment, not in a shared central database. Each tenant is a fully isolated data scope: data from one organisation or business unit is never co-mingled with another at the storage level.

Hosting options for the tenant environments include:

  • Private cloud: Dedicated cloud environment managed by Opigno's team, hosted in your required geographic region to satisfy data residency requirements
  • On-premise (learner portal): The tenant environment, which holds all learner personal data, can be deployed inside your own data centre. The central backoffice remains hosted by Opigno, and by default holds no learner names, credentials or learning history.
  • Your own models: Learning data can be processed by a commercial API, an open-weight model hosted in your environment, or a model you already operate internally. No customer learning data is used to train external models, and prompts and completions carry the same access controls, audit logging and retention rules as the rest of the platform.
Encrypted per-tenant data storage in Opigno Enterprise

Zero User Data in the Central Layer: How Opigno's UUID Architecture Works

Most SaaS LMS platforms store all user data — names, emails, roles, learning history — in a central database shared across the platform. This creates a single point of risk: a breach at the central layer exposes every customer's user data simultaneously.

Opigno Enterprise's architecture inverts this model. The central backoffice — which manages content publishing, tenant configuration, platform analytics, and administrative functions — stores zero user personal data. Users are referenced at the central level only by pseudonymous Universally Unique Identifiers (UUIDs). The user profile, credentials and learning history live within the local tenant environment, under your direct control. Some administrative operations are simpler if selected fields, such as display names, are shared with the backoffice — that is your configuration decision, and it is reversible.

What this means in practice:

  • A security incident at the central platform layer cannot expose learner personal data — there is none to expose
  • Cross-tenant data correlation at the user level is architecturally impossible 
  • GDPR data subject obligations are fulfilled entirely within the tenant environment

The separation is built into the architecture and on by default: data minimisation you can verify, rather than a policy you have to trust.

Opigno Enterprise separation between tenant and central backoffice

ISO 27001 and SOC 2 Type 2 — what they cover, and where we stand

Opigno Enterprise is compliant with the two security standards most often required in enterprise software procurement. Current reports, policies and the full control set are available in our Trust Center.

ISO 27001

The international standard for Information Security Management Systems, covering security policy, risk management, access control, incident response and continuous improvement.

SOC 2 Type 2

An AICPA attestation verifying that operational security controls have been applied consistently over a defined audit period, typically 6 to 12 months.
 

Platform controls

Role-based access control, TLS in transit, AES-256 at rest, SAML 2.0 and OAuth 2.0 SSO, MFA, comprehensive audit logging, and configurable data retention policies.

ISO 27001 information security management standard

Skills data is not performance data

A platform that measures capability invites a fair question: will this be used to judge people? Our commitment is explicit. Capability and skills data is never an input to performance management, compensation or promotion decisions.

The individual sees their own capability profile first, and it is theirs to work from. Views available to the organisation are aggregated. This is a product commitment rather than a configuration option — which is what makes it answerable to a data protection officer instead of negotiable per deployment.

The platform's multi-tenant architecture also scales compliance horizontally: as new subsidiaries or regions are added, each tenant environment inherits the same privacy architecture and controls automatically — without a separate security review for each deployment.

A learner viewing their own capability profile in Opigno Enterprise

Explore our FAQs

 Find quick answers to commonly asked questions about Opigno Enterprise

How secure is Opigno Enterprise and is it GDPR compliant?
Where is learner data stored in Opigno Enterprise?
Does Opigno Enterprise use customer data to train AI models?