Security & trust at Sertifier

Your credential data is protected by enterprise-grade security, independent certification, and privacy-by-design, so you can issue with confidence.

ISO 27001:2022 certified • GDPR compliant • Zero incidents in 3+ years

Credential data card marked protected, with encryption at rest and in transit and role-based access
  • ISO 27001:2022 certified
  • GDPR & UK GDPR compliant
  • EU-U.S. / Swiss-U.S. DPF
  • AES-256 encryption
  • Zero incidents in 3+ years
Sertifier is ISO 27001:2022 certified, GDPR compliant, and has maintained zero security incidents in over three years. Credential data is encrypted with AES-256 at rest and TLS 1.2+ in transit, hosted on Google Cloud Platform with configurable EU or US data residency.

Certifications & compliance

Independently certified, privacy-first by design

Sertifier meets the certification and privacy standards enterprise procurement and RFP teams expect, audited by third parties and backed by clear data-processing terms.

ISO 27001:2022 certified

Independently audited information-security management system.

GDPR & UK GDPR compliant

Privacy-by-design, with data subject rights fully supported.

CCPA / CPRA & COPPA compliant

Aligned with US state privacy law and children’s-privacy requirements.

EU-U.S. & Swiss-U.S. Data Privacy Framework

A participant for compliant cross-border transfers, plus SCCs where applicable.

Standard DPA available

Sent on request; Sertifier acts as your Data Processor.

Data protection

Encryption, access control, and data minimization

Encryption everywhere

AES-256 encryption at rest and TLS 1.2+ in transit for all credential data.

Access control

Role-based access control, SSO and SCIM for provisioning, and full audit logs.

Privacy by design

You control what goes into each credential, typically just a name and email.

Infrastructure & reliability

Serverless infrastructure you can depend on

Sertifier runs on Google Cloud Platform with a serverless architecture that auto-scales, plus business continuity and disaster recovery processes to keep credentials available.

99.9%Committed uptime SLA
99.99%Demonstrated uptime
0Security incidents
3+ yrsClean track record

Google Cloud Platform

Serverless architecture that auto-scales with your issuance volume.

Data residency you choose

EU (europe-west1) or US (us-east1 / us-central1), configurable per customer.

Resilience built in

Business continuity and disaster recovery processes keep credentials available.

Testing & monitoring

Tested by outsiders, watched continuously

Independent penetration testing

Conducted annually by a third party, most recent test in January 2026.

Continuous vulnerability scanning

Ongoing scanning via Google Cloud-native security tooling.

Real-time monitoring

Infrastructure and systems monitored around the clock.

Privacy & your data

You stay in control of your data

Sertifier acts as a Data Processor; your organization remains the Controller. We process the minimum needed to issue and verify credentials, typically a recipient’s name and email, the credential fields you choose, and admin business-contact details.

We use a limited set of vetted sub-processors; details are available under our DPA.

  • DPA on request

    A standard Data Processing Agreement is available whenever you need one.

  • Data residency selection

    Choose EU or US storage to match your compliance requirements.

  • Data subject request support

    We support access, correction, and deletion requests for your recipients.

FAQ

Security & trust, answered

Is Sertifier ISO 27001 certified?
Yes, Sertifier holds ISO 27001:2022 certification, with its information-security management system independently audited by a third party.
Is Sertifier GDPR compliant?
Yes. Sertifier is compliant with GDPR and UK GDPR, and is a participant in the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, with SCCs used for international transfers where applicable.
Where is my data stored?
On Google Cloud Platform, with configurable EU (europe-west1) or US (us-east1 / us-central1) data residency selected per customer.
How is my data encrypted?
Credential data is encrypted with AES-256 at rest and TLS 1.2+ in transit.
Does Sertifier do penetration testing?
Yes, Sertifier undergoes annual third-party penetration testing, alongside continuous vulnerability scanning and real-time monitoring.
Is Sertifier a data processor or a controller?
Sertifier is a Data Processor; your organization remains the Controller. A standard Data Processing Agreement (DPA) is available on request.
Has Sertifier had any security incidents?
No, Sertifier has maintained zero security incidents in over three years.