Built for regulated markets
How Certivo's control framework, data practices and product map to the regulatory obligations of banks, acquirers, PSPs, EMIs and other regulated businesses. Certifications are described honestly as aligned or in progress; the underlying controls are implemented.
Frameworks & alignment
SOC 2
Controls aligned to the Trust Services Criteria; formal attestation on the roadmap, not yet held.
ISO 27001
Information-security management practices aligned; certification in progress, not yet held.
EU GDPR & Cyprus Law 125(I)/2018
Processor commitments, DPA, SCC/adequacy-based transfers and data-subject-rights support.
PECR
Cookie categories and consent handled per the Privacy and Electronic Communications Regulations.
EU GDPR
Article 28 processor terms and lawful international-transfer mechanisms for EU personal data.
CCPA / CPRA
California consumer-rights support; we do not sell or share personal information.
Certivo is a technology vendor, not a licensed financial institution. We provide the infrastructure and evidence trail that regulated customers use to meet their own obligations. See the full compliance roadmap in the Trust Center.
Regulatory positioning
Certivo is operated by a company established in the Republic of Cyprus and governed by the laws of the Republic of Cyprus. The platform is a tool that supports our customers' compliance programmes — it does not make regulated decisions, hold client money, or provide payment services. Where a customer is itself regulated (for example a licensed payment institution or EMI), Certivo supplies the verification, screening and recordkeeping infrastructure they rely on, while accountability for regulatory decisions remains entirely with the customer.
AML program summary
We operate a risk-based financial-crime program covering due diligence on our own customers, sanctions screening of counterparties, ongoing monitoring, internal escalation and record-keeping. Read the full AML & CTF Policy for detail on governance, sanctions compliance and how the platform supports customer programs.
How the product maps to your obligations
| Obligation area | Platform capability |
|---|---|
| KYC — identity verification | Document, biometric and liveness checks with per-provider adapters and audit trails. |
| AML — screening & monitoring | Sanctions, PEP and adverse-media screening plus ongoing re-screening and alerts. |
| KYB — business verification | Entity, registry and beneficial-ownership review with case management. |
| Evidence & recordkeeping | Immutable audit logs, decision history and configurable retention. |
| Governance & review | Role-based access, four-eyes review and reviewable, reconstructable decisions. |
Shared responsibility
Compliance is a partnership. Certivo secures the platform and produces the evidence trail; you own your policy, risk appetite and final decisions.
| Area | Certivo provides | You own |
|---|---|---|
| Platform security | Infrastructure, encryption, headers, patching | Strong credentials, SSO config, key hygiene |
| Access | RBAC engine, audit logging, tenant isolation | Role assignment, joiner/mover/leaver reviews |
| Decisions | Orchestration, thresholds, evidence trail | Policy, risk appetite, final onboarding calls |
| Data | Storage, retention controls, deletion tooling | Lawful basis, retention policy, data-subject responses |
Data residency & transfers
The platform runs in an EU/UK region, and Enterprise customers can pin data to a configured region. International transfers, where they occur, are governed by Standard Contractual Clauses or an applicable adequacy basis, as described in our Privacy Policy and Data Processing Addendum.
Responsible decisioning
Screening and risk outputs are designed to support human review, not to replace it. Rules and thresholds are configurable and transparent, decisions are logged with their inputs, and case-level review supports four-eyes controls. Customers retain accountability for final onboarding and compliance decisions.
Documents & contact
- Trust Center
- Security overview
- For Enterprise — procurement & review
- AML & CTF Policy
- Data Processing Addendum
- Sub-processors
Compliance and due-diligence enquiries: management@certivo.uk.