Information Security Statement
A formal summary of the technical and organisational measures Certivo maintains to protect customer data. This statement complements our Security page and the technical measures in Annex B of the DPA.
1. Our approach
Certivo treats information security as a first-class product requirement, not a bolt-on. We build the platform for regulated financial-services customers, so our controls are designed to be defensible in front of a bank's vendor-risk and security teams. This statement describes the controls that are implemented today; where a control is aspirational or on our roadmap, it is labelled as such.
2. Encryption
All data in transit is protected with TLS 1.2 or higher. Data at rest, including the primary database, is encrypted using AES-256. Secrets and credentials are held in managed secret storage, never committed to source control, and access to them is restricted and logged.
3. Authentication & access control
Application passwords are hashed with argon2id. Sessions are signed and delivered as http-only cookies. Within the product, role-based access control (RBAC) enforces least-privilege, and SSO/SAML is available on Enterprise plans. Internal administrative access is limited to personnel who require it for their role and is reviewed periodically.
4. Tenant isolation
Every record is scoped to a single organisation. Queries are constrained to the caller's tenant and there are no cross-tenant reads; this isolation is enforced consistently across the API and the application, and is covered by automated checks.
5. Application & platform hardening
Mutating requests are CSRF-protected and all inputs are validated with typed schemas. A full set of security response headers is applied at the edge — HTTP Strict Transport Security, a Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, a strict referrer policy and a restrictive permissions policy. API errors are structured and never leak stack traces.
6. Secure development lifecycle
Changes follow a reviewed, auditable process: version control with peer review, a typed codebase, automated tests, and dependency monitoring for known vulnerabilities. Production is isolated from development and test environments, and infrastructure changes are auditable.
7. Logging, audit & monitoring
Every mutating action is recorded in an append-only audit log capturing who did what and when. These trails support investigation, four-eyes review, and evidence for the customer's own regulatory obligations.
8. Resilience & continuity
The platform runs on managed, access-controlled cloud infrastructure. Regular encrypted backups support recovery, and continuity procedures are designed to restore service after disruption, with recovery objectives set commensurate with the platform's criticality to regulated operations.
9. Sub-processors & vendor management
External providers sit behind reviewed, swappable adapters and are engaged under data-protection terms consistent with our DPA. Our active infrastructure sub-processors are listed on the Sub-processors page.
10. Certifications — honest status
Our control framework is aligned to SOC 2 and ISO 27001 practices. We do not currently hold a SOC 2 report or ISO 27001 certificate; formal attestation is on our roadmap and in progress. We will state clearly, and only, what we actually hold once attestations are complete.
11. Reporting a vulnerability
We welcome reports from security researchers. Please follow our Vulnerability Disclosure Policy and email security@certivo.uk. We acknowledge reports within two business days.
Company details
| Registered entity name | Puzzle Piece Ventures Ltd |
| Company number | HE 469272 |
| Registered office | [Registered office — Cyprus, to be confirmed] |
| Jurisdiction | Republic of Cyprus |
| Governing law | the Republic of Cyprus |
| Group | OnyxOne Group |
| General enquiries | management@certivo.uk |
Any bracketed value is a registration detail to be confirmed by the operating entity.
Last updated: 22 July 2026.
This document is published by Certivo (Puzzle Piece Ventures Ltd) and is governed by the laws of the Republic of Cyprus. Questions about it can be directed to management@certivo.uk. It does not constitute legal advice; you should take your own advice on how it applies to your circumstances.