Built for regulated markets
How Certivo's control framework, data practices and product map to the regulatory obligations of banks, acquirers, PSPs and EMIs. Certifications are described honestly as aligned or in progress; the underlying controls are implemented.
Frameworks & alignment
SOC 2
Controls aligned to the Trust Services Criteria; formal attestation on the roadmap.
ISO 27001
Information-security management practices aligned; certification in progress.
GDPR
Processor commitments, DPA, SCC-based transfers and data-subject-rights support.
CCPA / CPRA
California consumer-rights support; we do not sell or share personal information.
Certivo is a technology vendor, not a licensed financial institution. We provide the infrastructure and evidence trail that regulated customers use to meet their own obligations.
AML program summary
We operate a risk-based financial-crime program covering due diligence on our own customers, sanctions screening of counterparties, ongoing monitoring, internal escalation and record-keeping. Read the full AML & CTF Policy for detail on governance, sanctions compliance and how the platform supports customer programs.
How the product maps to your obligations
| Obligation area | Platform capability |
|---|---|
| KYC — identity verification | Document, biometric and liveness checks with per-provider adapters and audit trails. |
| AML — screening & monitoring | Sanctions, PEP and adverse-media screening plus ongoing re-screening and alerts. |
| KYB — business verification | Entity, registry and beneficial-ownership review with case management. |
| Evidence & recordkeeping | Immutable audit logs, decision history and configurable retention. |
Data residency & transfers
Enterprise customers can pin data to a configured region. International transfers, where they occur, are governed by Standard Contractual Clauses or an applicable adequacy basis, as described in our Privacy Policy and Data Processing Addendum.
Responsible decisioning
Screening and risk outputs are designed to support human review, not to replace it. Rules and thresholds are configurable and transparent, decisions are logged with their inputs, and case-level review supports four-eyes controls. Customers retain accountability for final onboarding and compliance decisions.
Documents & contact
Compliance and due-diligence enquiries: compliance@certivo.uk.