Skip to content
Legal

Information Security Statement

A formal summary of the technical and organisational measures Certivo maintains to protect customer data. This statement complements our Security page and the technical measures in Annex B of the DPA.

1. Our approach

Certivo treats information security as a first-class product requirement, not a bolt-on. We build the platform for regulated financial-services customers, so our controls are designed to be defensible in front of a bank's vendor-risk and security teams. This statement describes the controls that are implemented today; where a control is aspirational or on our roadmap, it is labelled as such.

2. Encryption

All data in transit is protected with TLS 1.2 or higher. Data at rest, including the primary database, is encrypted using AES-256. Secrets and credentials are held in managed secret storage, never committed to source control, and access to them is restricted and logged.

3. Authentication & access control

Application passwords are hashed with argon2id. Sessions are signed and delivered as http-only cookies. Within the product, role-based access control (RBAC) enforces least-privilege, and SSO/SAML is available on Enterprise plans. Internal administrative access is limited to personnel who require it for their role and is reviewed periodically.

4. Tenant isolation

Every record is scoped to a single organisation. Queries are constrained to the caller's tenant and there are no cross-tenant reads; this isolation is enforced consistently across the API and the application, and is covered by automated checks.

5. Application & platform hardening

Mutating requests are CSRF-protected and all inputs are validated with typed schemas. A full set of security response headers is applied at the edge — HTTP Strict Transport Security, a Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, a strict referrer policy and a restrictive permissions policy. API errors are structured and never leak stack traces.

6. Secure development lifecycle

Changes follow a reviewed, auditable process: version control with peer review, a typed codebase, automated tests, and dependency monitoring for known vulnerabilities. Production is isolated from development and test environments, and infrastructure changes are auditable.

7. Logging, audit & monitoring

Every mutating action is recorded in an append-only audit log capturing who did what and when. These trails support investigation, four-eyes review, and evidence for the customer's own regulatory obligations.

8. Resilience & continuity

The platform runs on managed, access-controlled cloud infrastructure. Regular encrypted backups support recovery, and continuity procedures are designed to restore service after disruption, with recovery objectives set commensurate with the platform's criticality to regulated operations.

9. Sub-processors & vendor management

External providers sit behind reviewed, swappable adapters and are engaged under data-protection terms consistent with our DPA. Our active infrastructure sub-processors are listed on the Sub-processors page.

10. Certifications — honest status

Our control framework is aligned to SOC 2 and ISO 27001 practices. We do not currently hold a SOC 2 report or ISO 27001 certificate; formal attestation is on our roadmap and in progress. We will state clearly, and only, what we actually hold once attestations are complete.

11. Reporting a vulnerability

We welcome reports from security researchers. Please follow our Vulnerability Disclosure Policy and email security@certivo.uk. We acknowledge reports within two business days.

Company details

Registered entity namePuzzle Piece Ventures Ltd
Company numberHE 469272
Registered office[Registered office — Cyprus, to be confirmed]
JurisdictionRepublic of Cyprus
Governing lawthe Republic of Cyprus
GroupOnyxOne Group
General enquiriesmanagement@certivo.uk

Any bracketed value is a registration detail to be confirmed by the operating entity.

Last updated: 22 July 2026.

This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.