ColabYard
Trust Center

Built for accessibility, security & privacy

ColabYard is built by a cyber-security education company, so we hold ourselves to the standards we teach. Here’s how we approach accessibility, keep the platform secure, and protect your data under UK GDPR.

♿ WCAG 2.1 AA🔒 UK GDPR compliant🛡️ Continuously scanned🔑 Encrypted in transit
Accessibility

A built-in accessibility toolbar and a 90% independent audit score, working toward WCAG 2.1 AA.

Read more →
🛡️
Security

Automated static & dynamic security scanning on every release, plus encryption and strict access controls.

Read more →
🔒
Privacy & GDPR

Data minimisation by design — students never need an account — and full data-subject rights.

Read more →

Accessibility

We want every learner and trainer to be able to use ColabYard, regardless of ability or assistive technology. We are working toward conformance with the Web Content Accessibility Guidelines (WCAG) 2.1 level AA.

90%
Independent audit score
AA
WCAG 2.1 target level
8
Built-in adjustments
Adjustments available on every page
  • Dark mode & high contrast — reduce eye strain and strengthen colour contrast
  • Dyslexia-friendly font and adjustable text size, line and letter spacing
  • Reduced motion — disables animations and transitions
  • Preferences are remembered in your browser and applied everywhere
  • Keyboard-operable controls and semantic, screen-reader-friendly markup

Our score is verified by an independent accessibility audit. Accessibility is never “done” — if you hit a barrier, tell us at customer.support@colabyard.co.uk and we’ll work to fix it.

🛡️

Security

Security is continuous, not a one-off. Every change to ColabYard is automatically scanned before and after it ships, and the platform is built on encryption and least-privilege access controls.

Continuous security testing
SASTSemgrep — static code analysisSASTSonarCloud — code quality & securityDASTOWASP ZAP — dynamic scanning on every release
Platform safeguards
  • Encryption in transit — all traffic served over HTTPS/TLS
  • Passwords hashed with bcrypt — never stored in plain text
  • Row-level security on the database restricts data access at the source
  • Sessions expire after 60 minutes of inactivity; reset links are single-use and expire in 1 hour
  • Least-privilege admin access, restricted to verified accounts
Responsible disclosure

If you believe you’ve found a security vulnerability, we’d like to hear from you. Please email us with details and we’ll investigate promptly. We ask that you give us reasonable time to respond before any public disclosure.

Security contact: dpo@colabyard.co.uk

To protect our users, we describe our testing programme rather than publishing raw scan results. Detailed reports can be shared with partners and procurement teams on request.

🔒

Privacy & GDPR

ColabYard is operated by NextGenCyber and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We collect the minimum data needed to run the service.

Data protection by design
  • Students need no account and can join anonymously — no email required
  • No advertising or tracking cookies — only essential session cookies
  • Named sub-processors and a clear lawful basis for every use of data
  • Full data-subject rights — access, rectification, erasure, portability and objection
  • Right to complain to the Information Commissioner’s Office (ICO)

Full details — what we collect, why, how long we keep it, and how to exercise your rights — are in our Privacy Policy. Data protection enquiries: dpo@colabyard.co.uk.