Security

How we protect your data and your clients' data.


Our Commitment

At Certifable, Inc., security is foundational — not an afterthought. Certification agencies handle sensitive business information, proprietary formulations, supplier relationships, and audit findings. We treat every byte of that data with the care it deserves.

Infrastructure

  • Cloud hosting: All services run on enterprise-grade cloud infrastructure with automatic failover, redundancy, and geographic distribution.
  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS everywhere).
  • Encryption at rest: Databases and file storage are encrypted at rest using AES-256 encryption.
  • Isolated tenancy: Each agency's data is logically isolated. One agency cannot access another agency's clients, documents, or certificates.

Authentication & Access

  • OAuth 2.0: We use industry-standard OAuth 2.0 for authentication with secure session management.
  • Role-based access control: Granular permissions ensure team members only see what they need — admins, reviewers, auditors, and clients each have appropriate access levels.
  • Session security: Sessions are cryptographically signed, expire after inactivity, and cannot be forged or replayed.

Application Security

  • Input validation: All user inputs are validated and sanitized on both client and server to prevent injection attacks.
  • API security: All API endpoints require authentication. Rate limiting prevents abuse. Webhook signatures are verified before processing.
  • Dependency management: We continuously monitor and update dependencies to patch known vulnerabilities.

Data Handling

  • Minimal data collection: We only collect data necessary to provide the service. We never sell or share your data with third parties for marketing.
  • Backups: Automated daily backups with point-in-time recovery ensure data durability.
  • Data retention: When you delete data, it is permanently removed from active systems. Backups are rotated on a defined schedule.

Compliance

We design our systems to support agencies in meeting their own compliance obligations. Our platform supports audit trails, document versioning, and tamper-evident certificate records — giving you the evidence chain your accreditation body expects.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@certifable.com. We take all reports seriously and will respond within 48 hours.

Questions?

For security-related inquiries, contact us at security@certifable.com.