2025 Audit Reports Now Available
Security and trust at Certn.
Our Human Risk Intelligence Platform validates identity and migrates risk while
prioritising the ultimate security, confidentiality, and availability of your data.
0
BREACHES (SOC 2 PERIOD)
24/7
AUTOMATED MONITORING
AES-256
ENCRYPTION AT REST
CLOUD
HIGH-AVAILABLITY HOSTING
Certifications and reports
Certn undergoes rigorous, independent third-party assessments annually to validate the design and operating effectiveness of our security controls. These reports are refreshed on a regular cadence so you’re never looking at stale evidence.
Current and Valid
SOC 2 Type 2
Period: Sept 2024 – Sep 2025
Evaluates the effectiveness of Certn’s controls regarding Security, Confidentiality, and Availability based on AICPA Trust Services Criteria.
Publicly Available
SOC 3
Period: Sept 2024 – Sep 2025
A generalized, publicly distributable report detailing the system controls relevant to Security, Confidentiality, and Availability.
Surveillance Cleared
ISO/IEC 27001:2022
Date: Oct 31, 2025
Validates that Certn’s Information Security Management System (ISMS) meets the rigorous international standards for data protection and risk management.
Security practices
Beyond audits and certifications, our day-to-day practices are built to keep your data secure at every layer. From access controls to incident response, security is engineered into how we operate, not bolted on after the fact.
Access Management
Centralized identity management via an Enterprise Identity Provider (IdP). We enforce Multi-Factor Authentication (MFA), strict Password Policies, and Role-Based Access Control (RBAC) across all systems. Access reviews occur quarterly.
Data Encryption
Data at rest is secured with AES-256 encryption. All web requests and data in transit traverse over encrypted connections using TLS 1.2+ and recognized third-party certificates.
Secure SDLC
Software changes are tracked via an enterprise project management tool, require peer reviews, and are tested in non-production environments (free of customer data). We utilise industry-leading Static and Dynamic Application Security Testing (SAST/DAST) tools.
Vulnerability Management
Continuous protection including weekly infrastructure vulnerability scans and annual manual penetration tests. Security events are triaged via a formal Incident Response framework.
Resilience and Backups
Hosted in secure cloud infrastructure across multiple availability zones. Daily automated backups and an annually tested Business Continuity and Disaster Recovery (BCDR) plan ensure high system availability.
Personnel Security
All personnel undergo comprehensive background checks prior to employment. Staff must acknowledge our Code of Conduct and complete security awareness training within 7 days of hire.
Security Portal
Access our public security programs, policies, and acknowledgments.
Trust Center
View our real-time security posture and continuous compliance monitoring.
Vulnerability Disclosure
Review our guidelines and scope for reporting security vulnerabilities.
security.txt
Our machine-readable RFC 9116 standards security contact information.
Frequently Ask Questions
Common questions from security, risk, and procurement teams.
The Certn Human Risk Intelligence Platform is hosted entirely within secure, ISO 27001-certified enterprise-grade cloud data centers (located in Canada, Australia, the UK, and/or the EU depending on the region). We do not operate on-premise servers.
Yes. We conduct external penetration tests at least annually by a certified third-party firm, and internal penetration testing quarterly by our in-house security team. We also maintain a formal Vulnerability Disclosure Program (VDP) to provide safe harbor for responsible security research.
We maintain a formal data retention and disposal policy in compliance with applicable regulations (e.g. PIPEDA, GDPR, FCRA). Our platform allows clients to configure their own data retention periods. Secure deletion processes are applied when data is no longer required.
Certn maintains a formal Incident Management policy. Our SLA is to inform affected clients within 24 hours of becoming aware of a data incident. We utilise an Enterprise SIEM to achieve real-time logging, monitoring, and alerting of security events across our environment.
As verified in our latest SOC 2 Type 2 report (covering Sept 16, 2024 to Sept 15, 2025), there were no system incidents requiring disclosure resulting from a control failure or causing significant impairment to our service commitments.
Access our full compliance documentation
Visit our Trust Centre to download our public SOC 3 report, or sign an NDA to request our complete security package, including the detailed SOC 2 Type 2 report, ISO 27001 certificate, and latest penetration testing executive summary.