Skip to content
For Enterprise

Everything your procurement and security teams will ask for

Certivo is built to pass enterprise due diligence. This page gathers the security, data-processing, deployment and commercial information a vendor-risk, legal or procurement team needs to evaluate us.

Security & vendor-risk pack

The documents below are published and current. Together they form the core of a vendor-risk file; we will supplement them with responses to your own security questionnaire.

Security overview

Technical & organisational measures across infrastructure, application, access and data.

Information Security Statement

A formal summary of the controls we maintain, suitable for a vendor-risk file.

Data Processing Addendum

EU GDPR (Article 28) processor terms with the standard annexes.

Sub-processors

The infrastructure providers engaged to deliver the service, kept current.

AML & CTF Policy

Our financial-crime programme and how the platform supports customer programmes.

Responsible Disclosure Policy

How to report a vulnerability, with safe-harbour.

Start at the Trust Center, which indexes every security, compliance and legal document.

How procurement works

  1. 1

    Scoping

    A tailored walkthrough on your use case, with a sandbox pilot so your team can evaluate against real integration work — using simulated providers, no real data required.

  2. 2

    Security review

    We share the Trust Center pack, respond to security questionnaires, and support a DPA and sub-processor review with your risk team.

  3. 3

    Commercials

    An Order Form sets scope, plan, currency and any bespoke terms; governing law is that of the Republic of Cyprus.

  4. 4

    Onboarding

    Environments are provisioned, SSO/SAML and roles are configured, real provider credentials are connected, and workflows are promoted from sandbox to production.

Deployment, access & data residency

  • Tenant isolation. Every record is scoped to your organisation; there are no cross-tenant reads.
  • Access control. Role-based access with least-privilege roles, plus SSO/SAML on Enterprise plans.
  • Data residency. The platform runs in an EU/UK region; Enterprise plans can pin data to a configured region.
  • Encryption. TLS 1.2+ in transit, AES-256 at rest; secrets held in managed storage, never in source control.
  • Auditability. An append-only audit log records who did what and when, with configurable retention and exports.

Service levels — as offered

Service-level commitments are agreed per contract in the Order Form. The following describes what is offered; specific figures and remedies are set out in your agreement.

Support & response

Email support with response targets on Growth; a named contact and priority support on Enterprise.

Availability posture

The platform runs on managed, redundant cloud infrastructure; availability commitments are set out in the Order Form for Enterprise agreements.

Incident communication

Security incidents affecting your data are communicated in line with the DPA and applicable law.

Change & continuity

Encrypted backups, versioned workflows with rollback, and reviewed, auditable infrastructure changes.

Compliance posture

Our control framework is aligned to SOC 2 and ISO 27001 practices; formal attestations are on the roadmap and in progress rather than held today, and we say so plainly. Certivo is a technology vendor, not a licensed financial institution. See the Compliance & Regulatory overview for frameworks and the shared-responsibility model.

Start a review

To open a procurement or security review, or to request our security pack and complete a questionnaire, request a demo or contact management@certivo.uk.