Cogniminds 360 Last Updated: July 2026
1. Our Commitment to Security
Cogniminds 360 is a premium online IT training institute based in the UAE, empowering professionals with globally recognized certifications across cybersecurity, cloud computing, IT governance, networking, and project management. We offer live instructor-led cohorts, 1-on-1 training, self-paced courses, downloadable learning products, and HR sourcing services to individuals and organizations throughout the UAE and beyond.
As a platform that handles student registrations, trainer profiles, payment transactions, course access credentials, and HR consulting engagements, we take the security of your personal and professional information seriously. This Security Policy outlines the technical and organizational measures we have in place to protect that information and the responsibilities we expect from everyone who interacts with our platform.
This policy applies to our website (cogniminds360.com), our student and trainer portals, our learning management system, downloadable digital products, HR services engagements, our internal systems, employees, instructors, contractors, and any third-party vendors who process data on our behalf.
2. Data We Collect and Protect
In the course of providing our training, learning products, and HR services, Cogniminds 360 may collect and process:
- Student and trainer registration details (name, email address, phone number, company name)
- Course enrollment records and learning progress data
- Payment and subscription billing information
- Login credentials for the student dashboard and trainer portal
- HR sourcing inquiry details (candidate profiles, company information, job briefs)
- Downloadable product purchase records
- Website usage, analytics, and session data
- Communications submitted via contact, registration, and callback request forms
We collect only the information necessary to deliver our services and do not sell student, trainer, or client data to third parties under any circumstances.
3. Data Protection Measures
- Encryption in Transit: All data exchanged between your browser or device and cogniminds360.com is encrypted using industry-standard TLS/SSL protocols, ensuring that sensitive information cannot be intercepted during transmission.
- Encryption at Rest: Sensitive data stored in our systems, including payment information and personal profile details, is protected using encryption at rest where applicable.
- Access Controls: Access to student, trainer, and HR client data is restricted to authorized Cogniminds 360 personnel on a strict need-to-know basis. Staff members can only access the data relevant to their specific role.
- Authentication Policies: Internal systems and administrative dashboards are protected by strong password requirements and multi-factor authentication, reducing the risk of unauthorized access even in the event of credential compromise.
- Regular Backups: Course records, user accounts, and business-critical data are backed up regularly to secure locations, ensuring continuity of service and protection against data loss.
4. Platform & Application Security
- Our website and learning management platform are protected by firewalls and continuously monitored for unauthorized access attempts and suspicious activity.
- Server infrastructure and all software components, including plugins and third-party integrations, are kept up to date with the latest security patches.
- We employ protections against Distributed Denial of Service (DDoS) attacks and other common web-based threats to maintain platform availability.
- New features, course modules, and platform updates go through internal review before deployment to identify potential vulnerabilities.
- Student and trainer portals enforce session timeouts and credential validation to prevent unauthorized account access.
- Database credentials, API keys, and third-party integration tokens are stored securely and managed separately from application code.
5. Access Control & User Permissions
- Student accounts provide access only to courses and materials the student is enrolled in or has purchased. Students cannot access other learners’ data or progress records.
- Trainer accounts are scoped to the courses and learner groups they are assigned to manage.
- Administrative access to platform configuration, financial data, and user records is limited to a small number of authorized personnel and is governed by the principle of least privilege.
- All administrative and privileged access is subject to periodic review to ensure it remains appropriate.
6. Payment Security
Cogniminds 360 uses trusted third-party payment processors to handle all financial transactions for course enrollments, learning product purchases, and training registrations. We do not store full credit card numbers or payment card details on our own servers. Payment processing follows industry practices for secure card handling, and transactions are carried out over encrypted connections. For questions about specific payment security practices, please contact us directly.
7. Incident Response
In the event of a suspected or confirmed security incident affecting your data, Cogniminds 360 will:
- Promptly investigate and work to contain the incident.
- Assess the nature and scope of any data exposure or unauthorized access.
- Notify affected students, trainers, or clients without undue delay, along with any recommended steps they should take to protect themselves.
- Cooperate with relevant UAE authorities as required by applicable law.
- Implement corrective and preventative measures to reduce the likelihood of recurrence.
8. Third-Party & Vendor Security
Cogniminds 360 works with select third-party providers to operate our platform effectively. These include cloud hosting and infrastructure providers, payment gateway processors, email and communication services, and learning management system components. We evaluate these providers for appropriate security practices and require that they handle any shared data responsibly. We share only the minimum data necessary for each provider to perform their function and do not authorize vendors to use your data for their own marketing or commercial purposes.
9. Vulnerability Disclosure
Given that Cogniminds 360 delivers training in cybersecurity — including CISSP, CISM, CISA, CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, and related programs — we understand and respect the security research community. If you believe you have identified a vulnerability in our website, student portal, or any associated system, we encourage you to report it to us responsibly.
Email: security@cogniminds360.com
Please include a clear description of the issue, the affected URL or component, and steps to reproduce it where possible. We ask that you refrain from publicly disclosing the vulnerability until we have had a reasonable opportunity to investigate and address it. We are committed to acknowledging reports promptly and working transparently with researchers to resolve valid findings.
10. Your Responsibilities as a User
To help protect your Cogniminds 360 account and learning data, we ask all students, trainers, and clients to:
- Use a strong, unique password for your Cogniminds 360 account and avoid reusing it across other websites or platforms.
- Keep your login credentials confidential. Do not share your account with others, including colleagues or classmates, as course access is issued on an individual basis.
- Log out of your dashboard when accessing it from a shared or public device.
- Be alert to phishing emails or messages that impersonate Cogniminds 360. We will never ask for your password via email or phone.
- Contact us immediately at info@cogniminds360.com if you notice any unauthorized activity in your account or receive suspicious communications claiming to be from us.
11. Free Security Awareness Sessions
As part of our commitment to the broader UAE community, Cogniminds 360 runs free Security Awareness Sessions every Saturday (next session: 11 July 2026), covering topics such as phishing awareness, cyber hygiene, online safety, data privacy, and digital literacy. We encourage students, professionals, and the general public to attend. Information shared during these sessions is used only to facilitate your attendance and is not used for commercial purposes.
12. Compliance
Cogniminds 360 operates in the UAE and strives to align our data handling and security practices with applicable UAE data protection regulations, including the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), as well as recognized international information security principles and frameworks — many of which we teach through our ISACA, ISC2, and CompTIA certification programs.
This policy is provided for informational purposes only and does not constitute legal advice or a guarantee of specific regulatory certification. Students or organizations with specific compliance requirements should consult their own legal or compliance advisors regarding their use of our platform.
13. Policy Updates
We may update this Security Policy periodically to reflect changes in our platform, practices, technology, or applicable legal requirements. The “Last Updated” date at the top of this page indicates when the policy was most recently revised. We encourage you to review this page from time to time. For material changes, we will make reasonable efforts to notify registered users via the email address on file.
14. Contact Us
If you have any questions, concerns, or requests related to this Security Policy or our data security practices, please reach out to us through any of the following channels:
Cogniminds 360 Email: info@cogniminds360.com Security Reports: security@cogniminds360.com Phone: +971 566 231 167 Website: https://cogniminds360.com Registered and operated under MAIT (Micro Aegis International Technologies LLC), UAE