Security Policy
Last updated: September 27, 2026
Describes how we protect this site, the information we receive, and the educational platforms we implement and operate for our clients.
1. Data Controller
This English version is provided for convenience; in case of discrepancy, the Spanish version prevails.
Grupo de Soluciones Creativas S.A.C., with RUC (Peruvian tax ID) 20607431117 and registered address at Las Almendras 286, San Martín de Porres, Lima, Peru, owner of the trademarks AulasMoodle (aulasmoodle.com) and Aulaxis (aulaxis.com). AulasMoodle is transitioning to its new brand, Aulaxis, with the same team.
2. Scope
Applies to aulasmoodle.com and to the implementation, hosting, SaaS, Cloud infrastructure, support and development services we provide.
3. Site Protection
The site is served over an encrypted connection (HTTPS) and applies security headers at the server level. Its pages are static; contact and subscription forms are processed server-side with data validation, protection against automated submissions (temporary token, honeypot field and submission rate limiting), and credentials stored outside the public folder.
4. Access Control
Access to servers, panels and databases is restricted to authorized personnel, with individual credentials, minimum privileges, and strengthened authentication where the service allows it. We never request passwords by chat or email.
5. Backups
We perform daily backups of the platforms we operate, with periodic restoration tests. In custom architectures, frequency is defined with each client and can be as often as hourly.
6. Monitoring and Updates
We monitor platforms 24/7, apply security patches, and test updates in a staging environment before moving to production.
7. Secure Development
We follow Moodle development standards and secure coding best practices: data validation, permission control, and code review before delivery.
8. Providers
We work with recognized infrastructure and service providers, which have their own security measures and certifications.
9. Incident Management
In the event of a security incident, we contain it, investigate its cause, inform the affected client, and apply measures to prevent recurrence.
10. Vulnerability Reporting
If you find a vulnerability in our systems, write to us at info@aulasmoodle.com with the subject line "Security". We will respond as soon as possible.
11. Client Responsibility
Each client must protect its passwords, manage its users’ permissions, keep its responsible parties’ information up to date, and review the content it publishes on its platform.
AulasMoodle and Aulaxis are brands of the same owner. See also the equivalent document of our new brand: Security Policy of Aulaxis.