Journey holds your apprentices' special-category data, the evidence behind your funding claims and your audit trail. We protect it with externally-audited standards, defence-in-depth engineering and a security model designed for multi-tenant scale.
Journey is built and operated by TechGeek, a UK company certified to ISO 9001, ISO 27001 and Cyber Essentials — the same externally-audited standards expected of enterprise software.
Quality and security assurance
Journey shares current, scope-specific assurance evidence during procurement. Do not rely on this page as a certification register.
Cyber-security assurance
Journey provides current, scope-specific assurance evidence during procurement where applicable.
Security is built into the architecture, not bolted on. These are the controls that protect every tenant.
Tenant context is derived server-side and tenant-owned reads, writes, files and exports are checked against active membership, permission and record scope.
Permissions are catalogue-defined and granted per role. Staff and learners see only what their role allows, and sensitive PII is gated behind specific permissions.
Significant application actions record who did what and when. Routine application paths do not edit audit entries; authorised retention or erasure operations are separately controlled and audited.
Journey's primary PostgreSQL database is hosted in London, with application delivery and approved sub-processors documented in our current register. Data is encrypted in transit and at rest.
Journey Advance AI is tenant-aware and metered. It prepares authorised drafts and K/S suggestions for human review; regulated decisions, behaviour verification and record changes remain with authorised people. If a model is unavailable, the record remains unchanged.
Funding, gateway, EPA and ILR checks run server-side against versioned rules. Journey provides explainable controls and audit evidence; the provider remains responsible for submission and regulatory decisions.
Everything we publish, in one place. Need a signed DPA, a security questionnaire completed or evidence for your due diligence? We are ready.