Trainiq
PlatformWho it is forQuinn AITrainiq ConnectPricingBlog 085 071 1114 Free demo Nederlands

Security

Version 1.0 · Last updated: 11 May 2026

This English version is provided for convenience. The Dutch version is the binding one.

Trainiq processes participant data, invoice data and certificates: information you don't hand to just any supplier. This page explains which technical and organisational measures we take to protect the availability, integrity and confidentiality of that data.

This page is a public summary of our internal information security policy. Working on an audit or a supplier assessment and need the full document? Request it through info@trainiq.nl.
EU onlyAll data within the European Economic Area
No passwordsLog in with a magic link or passkey
Fully encryptedTLS 1.2+ in transit, encrypted at rest
Audit logEvery admin action can be traced

1. Authentication

Trainiq works without passwords. All portals (administrators, client companies, instructors and participants) use passwordless authentication:

  • Magic link by e-mail: a one-time login link that expires within 15 minutes and is consumed the moment it is used
  • Passkey (WebAuthn): optional for administrators who want a faster login, biometric or with a hardware key
  • No password database. No password database means no password database leak.
  • No zombie sessions: API tokens for the mobile app expire when you re-authenticate on the same device

On internal accounts (GitHub, Coolify, Docker Hub, Hetzner, Brevo, payment providers, AWS, domain registrar) two-factor authentication is mandatory.

2. Encryption

In transit

  • All external communication goes over HTTPS / TLS 1.2 or higher
  • HTTP traffic is redirected to HTTPS automatically at proxy level
  • HSTS header on all public endpoints, so browsers know "always HTTPS"

At rest

  • Production databases run on encrypted volumes
  • Backups are stored encrypted on a separate host
  • Private files (signatures, signed contracts) live on an isolated volume, reachable only through authenticated routes; never through an open URL
  • No passwords or API keys in the source code; all credentials come from managed environment variables

3. Access control

  • Role-based authorisation within the platform: planner, employee, administrator, instructor. Each role only sees what it is supposed to see.
  • Isolation per training provider: every training provider runs in its own environment with its own database, optionally on its own domain. Data of different training providers never touches.
  • Least privilege: database users per resource (no super-user from the application); API keys for sub-processors are scoped per training provider.
  • No shared accounts. Every employee has an individual account tied to their e-mail address, with a personal audit trail.

Access by support

What does support see of my data? No god-mode admin access. Our support staff have no permanent impersonation rights on customer environments. What they see in a support conversation is what you actively show them: a shared screenshot, an exported example, or temporary delegated access that you grant and revoke yourself in the admin portal.

If solving a complex problem does require administrative access, that only happens with your prior consent and every action is recorded in the audit trail of your environment. We never share customer data with third parties for support purposes without a data processing agreement.

4. Audit log

Significant changes (bookings, certificates, invoices, user changes, integrations) are logged with actor, timestamp, before and after values. The audit log can be viewed at /admin/audit-log and is kept for at least 2 years. For training providers that fall under NRTO requirements (the Dutch trade association for training providers), or client companies that receive an audit question, this is the primary evidence.

5. Backup and recovery

  • Daily automated database snapshot, 30-day retention, stored on a separate host
  • Volumes (where private files such as signatures live) are part of the same daily snapshot
  • Quarterly restore test: a random snapshot is restored into a disposable environment and verified
  • Configuration and environment variables are exported at every significant change

6. Data breach procedure

A suspected or confirmed data breach follows this timeline:

  • Within 4 hours: block the vector (disable the endpoint, rotate leaked keys, isolate the affected customer instance)
  • Within 24 hours: establish the scope (which data, which data subjects, which period)
  • Within 48 hours: notify the customer with all the information needed for their own reporting duty
  • Within 72 hours: if reportable, notification to the Dutch Data Protection Authority (formally your duty; we supply the material)
  • Within 14 days after the incident: written post-mortem (what went wrong, how we prevent a repeat)

The full procedure is in article 26 of the terms and conditions.

7. Vulnerability management

  • Dependency scans at every deploy; high and critical vulnerabilities are handled within 7 days, medium within 30 days
  • Container base images are rebuilt at least every quarter to pick up OS patches
  • Automated CI/CD checks before every production deploy; a failing test suite blocks deployment
  • Rolling deploys: version-tagged images can be rolled back with one click
  • External penetration test scheduled yearly

8. Sub-processor management

All third parties we use (hosting through Hetzner, e-mail through Brevo, AI through Mistral AI (France), domain registration through TransIP, container registry through Docker Inc.) are within the EEA. Exception: Docker Inc. falls under standard contractual clauses, and no customer data passes through there. The overview including certifications is at trainiq.nl/en/subverwerkers.

We review every sub-processor at least yearly on certification status, breach history, location and service level. Changes are announced 30 days in advance.

9. Continuity

Source code is mirrored in several places (self-hosted Forgejo + GitHub as fallback). In case the owner is unavailable for a long period, access procedures are documented, so customers can receive their data export in line with article 31 of the terms and conditions.

10. Endpoint security and staff

  • Full disk encryption on workstations
  • Automatic screen lock after 5 minutes of inactivity
  • OS updates within 7 days of release; security patches within 48 hours
  • Confidentiality obligation laid down contractually for everyone who processes personal data
  • No customer data stored locally other than temporary debug output on generated test data
  • No customer data in public AI prompts outside our own Mistral chain with the PII detector and model training switched off

Questions, or an audit?

Questions about our security, or working on a supplier assessment and need more detail? E-mail info@trainiq.nl. We gladly share the full internal security policy, certifications where applicable, and (for enterprise customers) a SOC 2 type report under NDA when available.

Trainiq

The platform for training providers

PlatformAll featuresPortalsPricingTrainiq ConnectQuinn
Who it is forBHV training providersVCA providersCode 95 trainersHealthcare trainingDog training schoolsCourse administration
SupportBlogLegalPrivacySecurityContact

© 2026 Trainiq B.V. · Einsteinlaan 28, 2289 CC Rijswijk, the Netherlands · Chamber of Commerce 42053044 · +31 85 071 1114