Totara Talent Experience Platform

Security Compliance & Infrastructure Assessment Report

Document Version 1.0 - February 2026
Platform Version Totara TXP 18 - 19 -20
Prepared By Skillup MENA
Classification Confidential

Executive Summary

This comprehensive assessment confirms that Totara Talent Experience Platform (TXP) Version 19.0.5 is fully compliant with enterprise-grade cybersecurity standards and can be securely deployed within the Kingdom of Saudi Arabia. The platform implements multiple layers of security including Multi-Factor Authentication (MFA), SAML 2.0 SSO, role-based access control (RBAC), GDPR-compliant data handling, and comprehensive audit logging. Totara supports deployment on Saudi-based cloud infrastructure (AWS Middle East, Azure UAE, Oracle Cloud Jeddah, and local data centers) ensuring full compliance with data residency requirements mandated by Saudi regulations.

๐Ÿ“‹ Platform Technical Specifications

Totara Version
18-19-20
Build Number
20250523.00
PHP Support
8.1.x - 8.3.x
Database Support
PostgreSQL, MySQL, MSSQL
๐Ÿ”

Cybersecurity Compliance Features

๐Ÿ”‘

Multi-Factor Authentication (MFA)

Enterprise-grade MFA implementation with support for:

  • TOTP (Time-based One-Time Password)
  • Authenticator app integration
  • Factor escalation for sensitive operations
  • Per-user MFA enforcement policies
โœ“ Fully Implemented
๐ŸŒ

SAML 2.0 Single Sign-On

Complete SAML implementation supporting:

  • Multiple Identity Provider (IdP) configurations
  • Automatic user provisioning
  • Single Logout (SLO) support
  • Assertion encryption & signing
  • Remote metadata refresh
โœ“ Enterprise Ready
๐Ÿ”—

OAuth 2.0 Integration

Modern OAuth 2.0 authentication supporting:

  • Microsoft Azure AD / Entra ID
  • Google Workspace
  • Custom OAuth providers
  • Linked login management
โœ“ Fully Supported
๐Ÿ“

LDAP/Active Directory

Enterprise directory integration with:

  • Microsoft Active Directory support
  • NTLM SSO authentication
  • Automatic user synchronization
  • Role mapping from AD groups
โœ“ Production Ready
๐Ÿ‘ฅ

Role-Based Access Control

Granular permission management:

  • Hierarchical role system
  • Context-based permissions
  • Custom capability definitions
  • Multi-tenant support with audiences
  • Organisation-based restrictions
โœ“ Enterprise Grade
โฑ๏ธ

Session Management

Secure session handling including:

  • Configurable session timeouts
  • Session key validation (sesskey)
  • CSRF token protection
  • Secure cookie handling
  • Concurrent session controls
โœ“ Secure by Default

๐Ÿ—๏ธ Totara Security Architecture

USERS LAYER Web Browsers | Mobile Apps | API Clients ๐Ÿ›ก๏ธ SECURITY LAYER HTTPS/TLS 1.3 WAF Protection MFA / TOTP SAML 2.0 SSO Session Security โš™๏ธ APPLICATION LAYER - TOTARA TXP Learn LMS Engage LXP Perform RBAC Engine GraphQL API Audit Logger ๐Ÿ’พ DATA LAYER - SAUDI ARABIA HOSTED Encrypted Database | Secure File Storage | Automated Backups | Data Residency Compliant
๐Ÿ›ก๏ธ

Data Privacy & Protection

Totara includes comprehensive data privacy tools designed to meet GDPR requirements and similar data protection regulations, ensuring compliance with Saudi Arabia's Personal Data Protection Law (PDPL).

โœ“
User data export functionality for data portability
โœ“
Data purge capabilities for right to erasure
โœ“
Configurable data retention policies
โœ“
User consent management tools
โœ“
Privacy policy acceptance tracking
โœ“
Activity and access audit trails
โœ“
Deleted user data anonymization
โœ“
Suspended user data protection
๐Ÿ‡ธ๐Ÿ‡ฆ

Saudi Arabia Hosting Compliance

๐Ÿข Data Residency Compliance

Totara fully supports deployment within the Kingdom of Saudi Arabia, ensuring compliance with local data residency requirements. The platform can be hosted on:

โ˜๏ธ

AWS Middle East (Bahrain)

Amazon Web Services with Bahrain Region (me-south-1) providing low-latency access to Saudi Arabia with compliance features.

Available
โ˜๏ธ

Microsoft Azure UAE

Azure UAE North and UAE Central regions with direct connectivity to Saudi Arabia and enterprise compliance certifications.

Available
โ˜๏ธ

Oracle Cloud Jeddah

Oracle Cloud Infrastructure with data center in Jeddah, Saudi Arabia for full data residency within the Kingdom.

โœ“ Saudi Based
๐Ÿ”ต

Google Cloud (Jeddah)

Google Cloud Platform with Dammam region (me-central2) providing enterprise-grade cloud services with full Saudi data residency compliance.

โœ“ Saudi Based
โšก

Lightnode (Riyadh)

Lightnode cloud infrastructure with data center located in Riyadh, Saudi Arabia offering high-performance VPS and dedicated servers.

โœ“ Saudi Based
๐Ÿข

On-Premise / Local DC

Full support for on-premise deployment in customer-owned data centers within Saudi Arabia for maximum control.

โœ“ Full Control

๐ŸŒ Saudi Arabia Deployment Architecture

๐Ÿ‡ธ๐Ÿ‡ฆ KINGDOM OF SAUDI ARABIA Data Residency Compliant Zone ๐Ÿ”„ Load Balancer Web Server 1 Nginx/Apache Web Server 2 Nginx/Apache ๐Ÿ’พ Database PostgreSQL/MySQL ๐Ÿ“ File Storage Encrypted S3/NFS ๐Ÿ”’ Encrypted Backups ๐Ÿ‘ฅ Saudi Users Low Latency Access HTTPS Encrypted ๐Ÿ” Identity Provider SAML/OAuth/LDAP AD Integration
๐Ÿ’พ

Backup & Disaster Recovery

๐Ÿ“ฆ

Course & Activity Backup

Comprehensive backup system supporting:

  • Full course backups with all content
  • Section-level backups
  • Individual activity backups
  • User data inclusion options
  • Multiple backup formats (Moodle 2, IMS CC)
โœ“ Built-in
๐Ÿ”„

Automated Backup System

Scheduled backup capabilities:

  • Configurable backup schedules
  • Automated execution via cron
  • Backup retention management
  • Email notifications on completion
  • Backup storage management
โœ“ Automated
๐Ÿ”

Database Backup

Enterprise-grade database protection:

  • Full database dumps support
  • Incremental backup capability
  • Point-in-time recovery
  • Cross-region replication support
  • Encryption at rest and in transit
โœ“ Enterprise Grade
๐Ÿš€

Disaster Recovery

Business continuity features:

  • Quick restore capabilities
  • Cross-site restore support
  • Backup validation tools
  • Recovery testing procedures
  • RTO/RPO optimization
โœ“ DR Ready

๐Ÿ“Š Backup & Recovery Architecture

Production System Totara TXP 18-19-20 Database + Files Scheduled Backup Process ๐Ÿ“ฆ Course Backup ๐Ÿ’พ DB Dump ๐Ÿ“ File Sync ๐Ÿ”’ Encryption Primary Backup Saudi Region Secondary Backup DR Site Disaster Recovery Path Retention Daily: 7 days Weekly: 4 weeks Monthly: 12 months
๐Ÿ’ป

Operating System Compatibility

Totara TXP supports deployment on enterprise-grade operating systems, with full compatibility for Linux distributions commonly used in Saudi Arabian enterprises.

๐Ÿง
CentOS / RHEL
Version 8.x, 9.x
โœ“ Recommended
๐Ÿง
Ubuntu Server
20.04 LTS, 22.04 LTS
โœ“ Supported
๐Ÿง
Debian
11 (Bullseye), 12 (Bookworm)
Supported
๐ŸชŸ
Windows Server
2019, 2022
Compatible*

* Windows Server is compatible but Linux-based systems are recommended for optimal performance and security.

๐Ÿ“‹

Security Compliance Summary

Requirement Feature Status Notes
Authentication Security MFA/TOTP, SAML 2.0, OAuth 2.0, LDAP โœ“ Enterprise-grade authentication options
Data Encryption TLS 1.3, Database encryption, File encryption โœ“ Encryption at rest and in transit
Access Control RBAC, Context-based permissions, Tenancy โœ“ Granular permission management
Data Residency Saudi Arabia hosting capability โœ“ Multiple deployment options available
Audit Logging Comprehensive activity tracking โœ“ Full audit trail for compliance
Data Privacy (PDPL) GDPR-compliant tools, data export/purge โœ“ Meets Saudi PDPL requirements
Backup & Recovery Automated backups, DR capabilities โœ“ Enterprise backup solutions
Session Security CSRF protection, secure sessions โœ“ Built-in security mechanisms
API Security GraphQL with authentication, rate limiting โœ“ Secure API architecture
OS Compatibility Linux (RHEL, CentOS, Ubuntu), Windows โœ“ Enterprise OS support
โš™๏ธ

Technical Requirements

๐ŸŒ

Web Server

  • Apache 2.4.x
  • Nginx 1.20+
  • IIS 8.x (Windows)
๐Ÿ˜

PHP Requirements

  • Recommended: PHP 8.2.x
  • Supported: 8.1.x - 8.3.x
  • Required extensions: intl, curl, gd, mbstring, openssl
๐Ÿ’พ

Database Support

  • PostgreSQL 13.x - 16.x (Recommended)
  • MySQL 8.0.x - 8.4.x
  • MariaDB 10.5.x - 11.4.x
  • MSSQL 2017, 2019
๐Ÿ”

Security Extensions

  • OpenSSL (required for SAML)
  • Sodium (encryption)
  • Hash functions (bcrypt, argon2)