Certify holds personal data for the organisations that use it and for everyone who receives a credential. Here is how we keep it safe.
Certifications and compliance
Cyber Essentials Plus certified. Our security controls are independently tested under the UK government-backed scheme.
SOC2 data centre. Our databases are hosted in a SOC2-certified data centre.
Annual data audits. Our security and data privacy controls are audited every year, internally and independently.
GDPR and LGPD compliant. We comply with UK GDPR, EU GDPR and Brazil's LGPD.
Penetration testing. We regularly test our systems against attack.
Open Badges 2.0. Our credentials follow the Open Badges 2.0 standard, with support for Open Badges 3.0 coming soon.
Where your data is held
Our databases are hosted by Digital Ocean. We use a small number of other trusted suppliers to run our service, such as Intercom for customer support. Every supplier is under contract to protect personal data and not to sell or pass it on. We never sell personal data.
Access to data
We use role-based access control, so Certify staff can only see personal data when their job requires it.
Protecting your account
Turn on two-factor authentication for everyone on your team.
Give each colleague their own login. See How to manage team members.
Premium customers can use single sign-on (SSO).
Protecting your credentials
Every credential is recorded on a blockchain and has a public verification page, so anyone can check it is genuine and it is very hard to fake. See How can others check that my credential is genuine?
More information
Our Privacy Policy explains what data we collect and why.
For organisations, see GDPR and data protection at Certify.
Recipients who want their data deleted should see My data privacy & "right to be forgotten".
If you need our security documentation for a procurement or security review, contact us.
