Security
How we protect your data and your clients' data.
Our Commitment
At Certifable, Inc., security is foundational — not an afterthought. Certification agencies handle sensitive business information, proprietary formulations, supplier relationships, and audit findings. We treat every byte of that data with the care it deserves.
Infrastructure
- Cloud hosting: All services run on enterprise-grade cloud infrastructure with automatic failover, redundancy, and geographic distribution.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS everywhere).
- Encryption at rest: Databases and file storage are encrypted at rest using AES-256 encryption.
- Isolated tenancy: Each agency's data is logically isolated. One agency cannot access another agency's clients, documents, or certificates.
Authentication & Access
- OAuth 2.0: We use industry-standard OAuth 2.0 for authentication with secure session management.
- Role-based access control: Granular permissions ensure team members only see what they need — admins, reviewers, auditors, and clients each have appropriate access levels.
- Session security: Sessions are cryptographically signed, expire after inactivity, and cannot be forged or replayed.
Application Security
- Input validation: All user inputs are validated and sanitized on both client and server to prevent injection attacks.
- API security: All API endpoints require authentication. Rate limiting prevents abuse. Webhook signatures are verified before processing.
- Dependency management: We continuously monitor and update dependencies to patch known vulnerabilities.
Data Handling
- Minimal data collection: We only collect data necessary to provide the service. We never sell or share your data with third parties for marketing.
- Backups: Automated daily backups with point-in-time recovery ensure data durability.
- Data retention: When you delete data, it is permanently removed from active systems. Backups are rotated on a defined schedule.
Compliance
We design our systems to support agencies in meeting their own compliance obligations. Our platform supports audit trails, document versioning, and tamper-evident certificate records — giving you the evidence chain your accreditation body expects.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@certifable.com. We take all reports seriously and will respond within 48 hours.
Questions?
For security-related inquiries, contact us at security@certifable.com.