Service safeguards
Administrator actions require an authenticated, explicitly authorised owner account. Student and certificate records are separated by authenticated user identity. The service uses encrypted HTTPS connections, prepared database statements, server-side validation, same-origin checks for changes, restricted file types and sizes, request rate limits, no-store controls for private pages, restrictive browser security headers and administrator audit records.
Sign-in and two-step verification
The learner portal uses a GEC email-and-password account for primary sign-in. Passwords are salted and processed with PBKDF2-SHA-256 before storage; the readable password is not stored. GEC then requires a time-based authenticator code before access to the Student Portal, lessons, certificates or administrator area. Authenticator secrets are encrypted at rest; recovery codes are stored as one-way hashes; five failed password or authenticator attempts trigger a 15-minute lock; and successful verification creates signed, HttpOnly, Secure, SameSite session cookies lasting no more than 12 hours. Signing out clears both cookies. See our account security steps.
Payments
Online payment processing is not currently active. When payments are introduced, card details should be collected by a PCI DSS-compliant hosted payment provider rather than stored by this website.
Report a concern
Email gec.limited@outlook.com with the subject “Security report”. Include the affected page, a clear description and safe reproduction steps. Do not access another person’s information, disrupt the service, use automated denial-of-service testing or publish personal information.
What happens next
We will acknowledge legitimate reports when possible, investigate proportionately and take steps to contain and correct confirmed issues. This page does not authorise security testing.
