Trust & Operations

Security & Data Protection

PONS Method Institute treats security as an operating discipline: access control, controlled changes, recovery points, provider verification and incident response are part of the system lifecycle.

1. Security principles

  • Access is limited according to role and operational need where the platform supports it.
  • Critical configuration changes should be preceded and followed by a verified recovery point or checkpoint.
  • Authentication, hosting and other infrastructure may be provided by specialist technology providers whose own security controls form part of the overall service chain.
  • Operational errors are investigated and corrected before a change is treated as complete.
  • Sensitive credentials should never be published in course content, public pages or user-facing materials.

2. No absolute-security promise

No internet-connected system can guarantee zero risk. The Institute therefore uses reasonable technical and organisational measures, monitors important failures and maintains recovery procedures rather than making an unrealistic promise of perfect security.

3. User responsibilities

  • Use a strong, unique password and protect access to the email account associated with the service.
  • Do not share login credentials except where an organisational licence expressly permits authorised shared administration.
  • Keep local copies of business-critical source material and data.
  • Report suspected unauthorised access, unexpected account activity or security concerns promptly through the Institute contact channel.

4. Incident handling

When a material security or availability incident is confirmed, the operating objective is to contain the issue, preserve evidence where appropriate, restore safe service, assess affected data and communicate as required by applicable law and contractual obligations.

5. Third-party dependencies

The Institute depends on external providers for parts of its infrastructure. Their outages, policy changes or security incidents can affect the service. The Institute seeks to reduce this dependency risk through documented configuration, recovery points and provider-aware operational procedures.

6. Responsible reporting

If you believe you have found a security problem, please report it privately through the Institute contact page. Do not publish sensitive details, credentials or personal information while the issue is being investigated.

Last updated: 25 August 2026.

Share PONS value