This page describes the security approach applied to webschool.org and its associated corporate email environment. It is intentionally limited to the corporate website and does not describe the infrastructure, controls or contractual commitments of Webschool LMS platforms or customer services.
1. Hosting and architecture
The corporate website and corporate email are hosted by DonDominio (Soluciones Corporativas IP, S.L.), a provider established in Spain (European Union). webschool.org is designed as a lightweight corporate site with no public user accounts, no website database, no contact form and no newsletter subscription.
2. Security principles
- HTTPS/TLS is used to protect data in transit.
- Administrative access is restricted to authorised personnel.
- Administrative credentials and access permissions are managed according to role and operational need.
- Backups and recovery processes are maintained as appropriate to the corporate website environment.
- Software, hosting components and dependencies are kept under maintenance and security updates are applied as appropriate.
- Technical logging and monitoring are used for operational and security purposes.
- Security incidents are assessed, contained, remediated and documented according to their nature and impact.
- Relevant suppliers are reviewed from a security and data-protection perspective.
- Development and publication workflows are managed so that changes can be reviewed before being introduced into the public website.
- Stronger authentication and two-factor authentication are introduced for administrative access where supported and appropriate.
3. Data minimisation
Reducing the amount of data processed by the corporate website is itself a security control. webschool.org does not require visitors to create accounts and, in its current configuration, does not use a contact form, newsletter database or behavioural analytics.
4. Continuous improvement
Our security framework is continuously reviewed and improved. Controls may evolve as technologies, threats, suppliers and legal requirements change.
5. Responsible disclosure
If you believe you have identified a security vulnerability affecting webschool.org, please report it responsibly to security@webschool.org. Include enough information to help us reproduce and assess the issue, but do not access, modify, copy or disclose data beyond what is necessary to demonstrate the vulnerability.
Reporting a vulnerability does not create an entitlement to compensation or a bug bounty unless Webschool has expressly agreed otherwise in writing.
6. Product and customer environments
This page must not be used as a technical specification or security schedule for a Webschool product, LMS or customer environment. Security information for those services is provided separately where relevant through their specific documentation and contractual processes.
