Skip to content
Compliance & Regulatory

Built for regulated markets

How Certivo's control framework, data practices and product map to the regulatory obligations of banks, acquirers, PSPs and EMIs. Certifications are described honestly as aligned or in progress; the underlying controls are implemented.

Frameworks & alignment

SOC 2

Controls aligned to the Trust Services Criteria; formal attestation on the roadmap.

ISO 27001

Information-security management practices aligned; certification in progress.

GDPR

Processor commitments, DPA, SCC-based transfers and data-subject-rights support.

CCPA / CPRA

California consumer-rights support; we do not sell or share personal information.

Certivo is a technology vendor, not a licensed financial institution. We provide the infrastructure and evidence trail that regulated customers use to meet their own obligations.

AML program summary

We operate a risk-based financial-crime program covering due diligence on our own customers, sanctions screening of counterparties, ongoing monitoring, internal escalation and record-keeping. Read the full AML & CTF Policy for detail on governance, sanctions compliance and how the platform supports customer programs.

How the product maps to your obligations

Obligation areaPlatform capability
KYC — identity verificationDocument, biometric and liveness checks with per-provider adapters and audit trails.
AML — screening & monitoringSanctions, PEP and adverse-media screening plus ongoing re-screening and alerts.
KYB — business verificationEntity, registry and beneficial-ownership review with case management.
Evidence & recordkeepingImmutable audit logs, decision history and configurable retention.

Data residency & transfers

Enterprise customers can pin data to a configured region. International transfers, where they occur, are governed by Standard Contractual Clauses or an applicable adequacy basis, as described in our Privacy Policy and Data Processing Addendum.

Responsible decisioning

Screening and risk outputs are designed to support human review, not to replace it. Rules and thresholds are configurable and transparent, decisions are logged with their inputs, and case-level review supports four-eyes controls. Customers retain accountability for final onboarding and compliance decisions.

Documents & contact

Compliance and due-diligence enquiries: compliance@certivo.uk.