Skip to content
CBT Nuggets

Trust Center

Security, privacy, and compliance at CBT Nuggets

How we handle hosting, encryption, authentication, privacy, accessibility, and pen testing — and where to find every signed artifact your procurement team needs. Built for IT teams in healthcare, banking, government, and other compliance-sensitive industries.

Last reviewed: April 2026 · authored by the CBT Nuggets legal & security team

At a glance

The top procurement questions, answered on one page

Encryption, hosting, authentication, compliance frameworks, and incident response — without an account, without a sales call.

Hosting

AWS US-East-1, replicated across multiple availability zones

Encryption at rest

AES-256 (SSE-KMS on S3 buckets storing PII)

Encryption in transit

TLS between end-user devices, internal services, and public networks

Authentication (customer)

SAML 2.0 SSO via Microsoft Entra or Okta

Authentication (internal)

12+ char passwords with MFA across all admin access

Penetration testing

Annual third-party engagement; reports under NDA

PCI DSS

Compliant; latest Attestation of Compliance dated August 2025

Personal-data minimization

Platform: name, business email, IP. Marketing & billing: per Privacy Policy

Sub-processor disclosure

Categories listed in our Privacy Policy; specific list under NDA

Data residency

United States (AWS), with documented EU/UK transfer safeguards

Accessibility

WCAG 2.2 Level A/AA commitment; VPAT v2.5 available

Incident response

24/7 monitoring; defined detection → classification → containment → eradication → review pipeline

FAQ

Security

Hosting, encryption, authentication, SDLC, pen testing, change management, and incident response.

FAQ

Data privacy

GDPR, CCPA / CPRA, EU-US Data Privacy Framework, sub-processors, DPAs, SCCs, and data residency.

FAQ

Compliance & audits

PCI DSS, GDPR / UK GDPR, CCPA / CPRA, EU-US DPF, U.S. government contractor status, change control, and entity / tax information.

FAQ

Accessibility

WCAG 2.2 conformance, VPAT availability, and Section 508 / EN 301 549 documentation.

Governance & ethics

Business conduct and corporate responsibility

Our public Code of Conduct covers the standards we hold ourselves, our vendors, and our business partners to — equal employment, human rights, anti-corruption, conflict minerals, environmental sustainability, ethical AI use, and the UK Modern Slavery Act statement.

Sub-processors

Categories of third-party processors

The specific named-vendor list is provided under NDA via the gated Trust Center; the categories below are disclosed publicly per our Privacy Policy.

Website Hosting

Data storage centers, database solutions, and internal development tools.

Administration Services

Billing, accounting, payment processing, CRM, data enrichment, customer-account maintenance, and internal/external communications.

Service Delivery

Practice exams, virtual labs, certifications of completion, video encoding, content delivery, and customer-service tools.

Mailing List

Email marketing as opted into by customers and other necessary transactional communications.

Website Interaction Technologies

Cookies, web beacons, tracking pixels, and similar website interaction technologies.

Contractor Services

Software engineering, video and written content creation and design, and other sales and marketing services.

Need the named-vendor list? Request the full sub-processor list.

Document library

Signed artifacts and policies

All documents below are available via the gated Adept Trust Center for active customers, or by request from cold prospects. We do not enable anonymous downloads — every distribution is attributable for audit purposes.

Security

Compliance

Privacy

Accessibility

Business Continuity

Procurement

Advanced review

Need pen-test reports, architecture diagrams, or a legal conversation?

These artifacts are restricted under NDA due to our U.S. government contractor status. Active customers can request them via the gated Trust Center; prospects can route the request through their account team.

Trusted by 23,000+ organizations

See how CBT Nuggets fits your team's compliance posture

Procurement-friendly. Built for IT Directors managing teams in healthcare, banking, government, and other compliance-sensitive industries.