Everything your procurement and security teams will ask for
Certivo is built to pass enterprise due diligence. This page gathers the security, data-processing, deployment and commercial information a vendor-risk, legal or procurement team needs to evaluate us.
Security & vendor-risk pack
The documents below are published and current. Together they form the core of a vendor-risk file; we will supplement them with responses to your own security questionnaire.
Security overview
Technical & organisational measures across infrastructure, application, access and data.
Information Security Statement
A formal summary of the controls we maintain, suitable for a vendor-risk file.
Data Processing Addendum
EU GDPR (Article 28) processor terms with the standard annexes.
Sub-processors
The infrastructure providers engaged to deliver the service, kept current.
AML & CTF Policy
Our financial-crime programme and how the platform supports customer programmes.
Responsible Disclosure Policy
How to report a vulnerability, with safe-harbour.
Start at the Trust Center, which indexes every security, compliance and legal document.
How procurement works
- 1
Scoping
A tailored walkthrough on your use case, with a sandbox pilot so your team can evaluate against real integration work — using simulated providers, no real data required.
- 2
Security review
We share the Trust Center pack, respond to security questionnaires, and support a DPA and sub-processor review with your risk team.
- 3
Commercials
An Order Form sets scope, plan, currency and any bespoke terms; governing law is that of the Republic of Cyprus.
- 4
Onboarding
Environments are provisioned, SSO/SAML and roles are configured, real provider credentials are connected, and workflows are promoted from sandbox to production.
Deployment, access & data residency
- Tenant isolation. Every record is scoped to your organisation; there are no cross-tenant reads.
- Access control. Role-based access with least-privilege roles, plus SSO/SAML on Enterprise plans.
- Data residency. The platform runs in an EU/UK region; Enterprise plans can pin data to a configured region.
- Encryption. TLS 1.2+ in transit, AES-256 at rest; secrets held in managed storage, never in source control.
- Auditability. An append-only audit log records who did what and when, with configurable retention and exports.
Service levels — as offered
Service-level commitments are agreed per contract in the Order Form. The following describes what is offered; specific figures and remedies are set out in your agreement.
Support & response
Email support with response targets on Growth; a named contact and priority support on Enterprise.
Availability posture
The platform runs on managed, redundant cloud infrastructure; availability commitments are set out in the Order Form for Enterprise agreements.
Incident communication
Security incidents affecting your data are communicated in line with the DPA and applicable law.
Change & continuity
Encrypted backups, versioned workflows with rollback, and reviewed, auditable infrastructure changes.
Compliance posture
Our control framework is aligned to SOC 2 and ISO 27001 practices; formal attestations are on the roadmap and in progress rather than held today, and we say so plainly. Certivo is a technology vendor, not a licensed financial institution. See the Compliance & Regulatory overview for frameworks and the shared-responsibility model.
Start a review
To open a procurement or security review, or to request our security pack and complete a questionnaire, request a demo or contact management@certivo.uk.