Security and compliance you can put in front of a regulator
Certivo is built to pass enterprise due diligence. This hub summarises our controls and links to every security, compliance and legal document.
Control summary
Data encryption
TLS 1.2+ in transit; AES-256 at rest for all customer data.
Access control
RBAC with least-privilege roles; SSO/SAML on Enterprise.
Audit logging
Every mutating action is recorded in an append-only audit log.
Tenant isolation
All records are scoped by organization; no cross-tenant reads.
Data residency
Configurable region pinning on Enterprise plans.
Vendor management
External providers sit behind reviewed, swappable adapters.
Certifications & alignment
Our control framework is aligned to SOC 2 and ISO 27001 practices. In this evaluation environment, formal attestations are represented as in-progress; the underlying controls are implemented in the platform. Certivo is a technology vendor, not a licensed financial institution.
Security & compliance documents
Security
Technical & organisational measures.
Compliance & Regulatory
Frameworks, AML summary and data residency.
System status
Live availability of platform services.
Data Processing Addendum
Processor terms and annexes.
Sub-processors
Providers engaged to deliver the service.
AML & CTF Policy
Financial-crime program and platform controls.
Legal
Contact
Security: security@certivo.uk · Privacy: privacy@certivo.uk · Compliance: compliance@certivo.uk. For general help, visit Support.