Last updated August 2026
Platform practices
- Access to provider data is role-based and enforced at the database layer, not only in the interface.
- Evidence files are held in access-controlled storage with time-limited access links.
- Traffic is encrypted in transit and stored data is encrypted at rest by our infrastructure providers.
- Administrative and reviewer actions are recorded in an append-only audit log.
- Accounts are separated by organisation, and team invitations are scoped to a single provider.
Credential integrity
Issued accreditations carry a unique reference and a cryptographic hash so a certificate can be checked against the record held by GLS. Public verification returns only the facts needed to confirm a credential: provider, programme, reference, status and dates.
Reporting a vulnerability
If you believe you have found a security issue, contact us through the contact page with the affected URL, a description, and the minimum steps required to reproduce it. Please report privately and give us reasonable time to fix the issue before disclosing it.
What we ask you not to do
- Do not access, modify or exfiltrate data belonging to other organisations.
- Do not run denial-of-service, spam or social-engineering tests against staff or providers.
- Do not use automated scanning that degrades service for providers under review.
Our response
We aim to acknowledge reports within two working days, confirm or dismiss the finding after triage, and keep you informed until it is resolved. We will credit reporters who wish to be named once a fix is released.
This page sets out the policies of Global Learning Standards (GLS). GLS is an independent accreditation body. GLS is not a certification body and is not ISO. If anything here is unclear, contact us and we will explain it in plain language.

