Security and compliance you can put in front of a regulator
Certivo is built to pass enterprise due diligence. This hub explains how we secure the platform and handle data, and links to every security, compliance and legal document.
Control summary
Data encryption
TLS 1.2+ in transit; AES-256 at rest for all customer data.
Access control
RBAC with least-privilege roles; SSO/SAML on Enterprise.
Audit logging
Every mutating action is recorded in an append-only audit log.
Tenant isolation
All records are scoped by organization; no cross-tenant reads.
Data residency
EU/UK-region hosting; configurable region pinning on Enterprise.
Vendor management
External providers sit behind reviewed, swappable adapters.
Security architecture
Security is layered so that no single failure exposes customer data. Controls run from the network edge inward — through the application, authorisation and tenant isolation, down to the data itself.
Edge & network
TLS 1.2+, strict security headers (HSTS, CSP, X-Frame-Options), no server fingerprinting.
Application
argon2id hashing, signed http-only sessions, typed input validation, CSRF protection.
Authorisation
Role-based access control with least-privilege roles; SSO/SAML on Enterprise.
Tenant isolation
Every query constrained to the caller's organisation — no cross-tenant reads.
Data
AES-256 at rest, managed secret storage, data minimisation and configurable retention.
Data handling & lifecycle
We practise data minimisation: only the data needed for a configured check is collected, and it is handled in line with our Privacy Policy and DPA.
| Stage | What happens |
|---|---|
| Collect | Only the data needed for the configured check is captured, at the point of onboarding. |
| Process | Data is used solely to run the verification, screening or KYB you requested, and to produce the evidence trail. |
| Store | Records are encrypted at rest in an EU/UK-region managed database, scoped to your organisation. |
| Retain | Retention is configurable to your policy; we hold data only as long as it is needed. |
| Delete | Data is deleted or anonymised when no longer required, or on documented request per the DPA. |
Access control
Access follows least-privilege principles end to end. Within the product, role-based access control scopes what each user can see and do; SSO/SAML is available on Enterprise plans. Internal administrative access is limited to personnel who need it, uses strong authentication, and is reviewed periodically. Every record is scoped to its organisation, and queries are constrained to the caller's tenant — there are no cross-tenant reads.
Secure development lifecycle
- Changes go through review before reaching production, with an auditable history.
- Inputs are validated with typed schemas; secrets are kept out of source control.
- Dependencies are monitored for known vulnerabilities and updated when advisories land.
- Production is isolated from development and test environments.
- Security headers (HSTS, CSP, X-Frame-Options, nosniff, strict referrer policy) are enforced at the edge.
Availability & resilience
Certivo runs on managed, redundant cloud infrastructure. Regular, encrypted backups support recovery, and continuity procedures are designed to restore service after disruption. Live service status is published at /status, and specific availability commitments are set out per contract for Enterprise agreements.
Sub-processors
We engage a small number of infrastructure sub-processors to deliver the service. The current list is maintained on the Sub-processors page; the core infrastructure is summarised here.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting & edge delivery | EU region |
| Neon | Managed Postgres database | EU/UK region |
Certifications & compliance roadmap
Our control framework is aligned to SOC 2 and ISO 27001 practices. Formal attestations are on our roadmap and in progress; they are not yet held. The underlying controls are implemented in the platform today. Certivo is a technology vendor, not a licensed financial institution, and does not hold or imply any regulatory licence, authorisation or certification.
Modern security controls
Encryption, RBAC, tenant isolation, argon2id, security headers and audit logging are live in the platform today.
SOC 2 alignment
Controls are mapped to the Trust Services Criteria; formal attestation is on the roadmap and not yet held.
ISO 27001 alignment
Information-security management practices are aligned; certification is planned, not yet held.
Independent penetration test
Third-party testing is planned as part of the assurance roadmap.
Security & compliance documents
Security
Technical & organisational measures.
Information Security Statement
Formal summary of our security controls.
Compliance & Regulatory
Frameworks, AML summary and data residency.
For Enterprise
Procurement, security review and SLAs as offered.
System status
Live availability of platform services.
Data Processing Addendum
Processor terms and annexes.
Sub-processors
Providers engaged to deliver the service.
AML & CTF Policy
Financial-crime program and platform controls.
Responsible Disclosure
How to report a vulnerability, with safe-harbour.
Legal
Contact
Security, privacy and compliance enquiries can be sent to management@certivo.uk. For general help, visit Support, or open a procurement review from the Enterprise page.