Skip to content
Trust Center

Security and compliance you can put in front of a regulator

Certivo is built to pass enterprise due diligence. This hub explains how we secure the platform and handle data, and links to every security, compliance and legal document.

Control summary

Data encryption

TLS 1.2+ in transit; AES-256 at rest for all customer data.

Access control

RBAC with least-privilege roles; SSO/SAML on Enterprise.

Audit logging

Every mutating action is recorded in an append-only audit log.

Tenant isolation

All records are scoped by organization; no cross-tenant reads.

Data residency

EU/UK-region hosting; configurable region pinning on Enterprise.

Vendor management

External providers sit behind reviewed, swappable adapters.

Security architecture

Security is layered so that no single failure exposes customer data. Controls run from the network edge inward — through the application, authorisation and tenant isolation, down to the data itself.

Edge & network

TLS 1.2+, strict security headers (HSTS, CSP, X-Frame-Options), no server fingerprinting.

Application

argon2id hashing, signed http-only sessions, typed input validation, CSRF protection.

Authorisation

Role-based access control with least-privilege roles; SSO/SAML on Enterprise.

Tenant isolation

Every query constrained to the caller's organisation — no cross-tenant reads.

Data

AES-256 at rest, managed secret storage, data minimisation and configurable retention.

Controls are layered so no single failure exposes customer data.

Data handling & lifecycle

We practise data minimisation: only the data needed for a configured check is collected, and it is handled in line with our Privacy Policy and DPA.

StageWhat happens
CollectOnly the data needed for the configured check is captured, at the point of onboarding.
ProcessData is used solely to run the verification, screening or KYB you requested, and to produce the evidence trail.
StoreRecords are encrypted at rest in an EU/UK-region managed database, scoped to your organisation.
RetainRetention is configurable to your policy; we hold data only as long as it is needed.
DeleteData is deleted or anonymised when no longer required, or on documented request per the DPA.

Access control

Access follows least-privilege principles end to end. Within the product, role-based access control scopes what each user can see and do; SSO/SAML is available on Enterprise plans. Internal administrative access is limited to personnel who need it, uses strong authentication, and is reviewed periodically. Every record is scoped to its organisation, and queries are constrained to the caller's tenant — there are no cross-tenant reads.

Secure development lifecycle

  • Changes go through review before reaching production, with an auditable history.
  • Inputs are validated with typed schemas; secrets are kept out of source control.
  • Dependencies are monitored for known vulnerabilities and updated when advisories land.
  • Production is isolated from development and test environments.
  • Security headers (HSTS, CSP, X-Frame-Options, nosniff, strict referrer policy) are enforced at the edge.

Availability & resilience

Certivo runs on managed, redundant cloud infrastructure. Regular, encrypted backups support recovery, and continuity procedures are designed to restore service after disruption. Live service status is published at /status, and specific availability commitments are set out per contract for Enterprise agreements.

Sub-processors

We engage a small number of infrastructure sub-processors to deliver the service. The current list is maintained on the Sub-processors page; the core infrastructure is summarised here.

ProviderPurposeRegion
VercelApplication hosting & edge deliveryEU region
NeonManaged Postgres databaseEU/UK region

Certifications & compliance roadmap

Our control framework is aligned to SOC 2 and ISO 27001 practices. Formal attestations are on our roadmap and in progress; they are not yet held. The underlying controls are implemented in the platform today. Certivo is a technology vendor, not a licensed financial institution, and does not hold or imply any regulatory licence, authorisation or certification.

Modern security controls

Encryption, RBAC, tenant isolation, argon2id, security headers and audit logging are live in the platform today.

Implemented

SOC 2 alignment

Controls are mapped to the Trust Services Criteria; formal attestation is on the roadmap and not yet held.

In progress

ISO 27001 alignment

Information-security management practices are aligned; certification is planned, not yet held.

In progress

Independent penetration test

Third-party testing is planned as part of the assurance roadmap.

Planned

Security & compliance documents

Legal

Contact

Security, privacy and compliance enquiries can be sent to management@certivo.uk. For general help, visit Support, or open a procurement review from the Enterprise page.