Skip to main content

Security at Certify

How Certify protects your organisation's data and your recipients' data: certifications, hosting, access control and account security.

Certify holds personal data for the organisations that use it and for everyone who receives a credential. Here is how we keep it safe.

Certifications and compliance

  • Cyber Essentials Plus certified. Our security controls are independently tested under the UK government-backed scheme.

  • SOC2 data centre. Our databases are hosted in a SOC2-certified data centre.

  • Annual data audits. Our security and data privacy controls are audited every year, internally and independently.

  • GDPR and LGPD compliant. We comply with UK GDPR, EU GDPR and Brazil's LGPD.

  • Penetration testing. We regularly test our systems against attack.

  • Open Badges 2.0. Our credentials follow the Open Badges 2.0 standard, with support for Open Badges 3.0 coming soon.

Where your data is held

Our databases are hosted by Digital Ocean. We use a small number of other trusted suppliers to run our service, such as Intercom for customer support. Every supplier is under contract to protect personal data and not to sell or pass it on. We never sell personal data.

Access to data

We use role-based access control, so Certify staff can only see personal data when their job requires it.

Protecting your account

Protecting your credentials

Every credential is recorded on a blockchain and has a public verification page, so anyone can check it is genuine and it is very hard to fake. See How can others check that my credential is genuine?

More information

Did this answer your question?