Legal and Security Policies

Legal and Security Policies

Certifier's security hub is where you'll discover all you need to know about our data storage, security standards, and procedures. The security of our services are paramount for us.

Our processes are constantly improving — last updated: January 13, 2026.

Legal Documents

Leveraging our experience, we construct legal agreements that are not only customer-oriented but also compliant with regulations.

Explore Legal Agreementsarrow

Security Protocols

Security and data integrity are paramount at Certifier. Given the nature of our offerings, fulfilling our responsibilities is crucial.

Explore Security Policiesarrow

Our Commitment

Certifier is deeply committed to safeguarding our customers and their data. Our goal is to continuously enhance our security measures, providing you with a secure, scalable platform that delivers an exceptional certification and credentialing experience.

We take security as our highest priority

Our dedication to keeping customer data secure is unwavering

Certifier – Data Protection

Data Protection

Regular penetration tests, adherence to GDPR guidelines, and stringent encryption protocols for data at rest and in transit are just the beginning. We take the responsibility of safeguarding your sensitive information very seriously.

Certifier – Security by design

Security by design

Certifier is ISO 27001 certified, reinforcing our top-tier security practices. We provide security training for developers and employ automated code analysis tools to preemptively identify and address potential vulnerabilities, ensuring we deliver a reliably secure product to our customers.

Security and Privacy Practices

At Certifier, we adopt enterprise-grade development practices, infrastructure, and compliance certifications to underscore our security.

ISO 27001 Certification

ISO 27001 Certification

ISO 27001 represents the highest standard in global information security assurance, certifying that Certifier adheres to rigorous international protocols. Upon request, we can share the assessments from independent third-party auditors.

ISO 9001 Certification

ISO 9001 Certification

ISO 9001 quality management certification confirms that Certifier's software design practices meet the highest standards of excellence. Independent third-party auditor opinions and certificates are available upon request.

GDPR Compliance

GDPR Compliance

Certifier is fully GDPR compliant, ensuring that all subprocessors also adhere to GDPR requirements. We maintain the confidentiality, integrity, and resilience of systems processing personal data.

AWS Security Infrastructure

AWS Security Infrastructure

Certifier's infrastructure is securely hosted on AWS within the Europe region. AWS data centers feature round-the-clock security, biometric scanning, video surveillance, and adhere to various global security and compliance standards.

Penetration Testing

Penetration Testing

Certifier conducts regular independent third-party penetration tests and vulnerability scans to identify and mitigate potential security risks. Reports from audits are available upon request.

99.9% Application Uptime

99.9% Application Uptime

Certifier consistently achieves an uptime exceeding 99.9%, with a robust architecture designed to eliminate single points of failure through multiple failover instances.

Disaster Recovery

Disaster Recovery

We employ advanced replication techniques and regular snapshot backups. Our automated backup system for Amazon RDS is a key component of our robust disaster recovery strategy, designed to meet industry standards.

Data Encryption

Data Encryption

All data is encrypted in transit using TLS 1.2 or higher and at rest with AES-256 encryption. Access to Certifier's application servers is strictly via HTTPS.

Incident Response

Incident Response

Our incident response strategy is based on the SANS Incident Response methodology, with thorough post-mortem analyses conducted on each incident to prevent recurrence and enhance response measures.

Secure Passwords & 2FA

Secure Passwords & 2FA

We take your account security seriously by encrypting all passwords before database storage and advocating for strong password choices on your part. Certifier offers Two-factor Authentication (2FA) to all users, enhancing security.

Frequently Asked Questions

Have more questions? Contact Support

No, we do not have a separate SOC 2 compliance report. At Certifier, we have chosen ISO 27001 certification due to its global recognition and thorough approach to data security, which includes key areas of information security such as confidentiality, availability, and integrity.

Both ISO 27001 and SOC 2 frameworks significantly overlap in these core principles, underscoring our commitment to upholding the highest security standards globally. However, we understand our clients have diverse needs. We are open to discussing how we can meet specific requirements, including those seeking SOC 2 compliance. For a tailored discussion on meeting your security and compliance needs, please reach out to us at support@certifier.io.
Yes, we conduct regular independent tests to ensure our platform's integrity, and we can share our latest penetration test report upon request after signing the standard NDA. Please send your request directly to support@certifier.io to access the report.
Absolutely! If you are an issuer and would like us to remove the data we have about you at any time, please submit a request to support@certifier.io. We aim to process "Right to be Forgotten" requests within 14 working days.

Important Note for Recipients: If you are a recipient and have credentials issued to you through Certifier, we will need to contact your issuer and request that they delete these credentials first. Under GDPR regulations, Certifier is a "Data Processor," meaning that we can manage your data, but we are not permitted to alter or delete it. Only your issuer has the authority to do this.
Certifier's production infrastructure is hosted entirely on AWS (Amazon Web Services). All persistent data (databases, file storage, temp data) alongside compute power (web servers, processing machines, etc.) are operated in the AWS EU Ireland Region (eu-west-1). We store backups in AWS S3 within the same AWS Region but in different Availability Zones.
PCI-DSS is a security standard with which any company handling credit card data must comply.

Certifier has not been audited by a PCI-certified auditor because it does not receive sensitive credit card details. At Certifier, we utilize Stripe and Chargebee to manage subscription billing for our customers, and these services are responsible for all credit card data. Stripe and Chargebee comply with PCI-DSS Level 1.