Security

2025 Audit Reports Now Available

Security and trust at Certn.

Our Human Risk Intelligence Platform validates identity and migrates risk while
prioritising the ultimate security, confidentiality, and availability of your data.

0

BREACHES (SOC 2 PERIOD)

24/7

AUTOMATED MONITORING

AES-256

ENCRYPTION AT REST

CLOUD

HIGH-AVAILABLITY HOSTING

Certifications and reports

Certn undergoes rigorous, independent third-party assessments annually to validate the design and operating effectiveness of our security controls. These reports are refreshed on a regular cadence so you’re never looking at stale evidence.

check circle

Current and Valid

SOC 2 Type 2

Period: Sept 2024 – Sep 2025

Evaluates the effectiveness of Certn’s controls regarding Security, Confidentiality, and Availability based on AICPA Trust Services Criteria.

license

Publicly Available

SOC 3

Period: Sept 2024 – Sep 2025

A generalized, publicly distributable report detailing the system controls relevant to Security, Confidentiality, and Availability.

language

Surveillance Cleared

ISO/IEC 27001:2022

Date: Oct 31, 2025

Validates that Certn’s Information Security Management System (ISMS) meets the rigorous international standards for data protection and risk management.

Security practices

Beyond audits and certifications, our day-to-day practices are built to keep your data secure at every layer. From access controls to incident response, security is engineered into how we operate, not bolted on after the fact.

group

Access Management

Centralized identity management via an Enterprise Identity Provider (IdP). We enforce Multi-Factor Authentication (MFA), strict Password Policies, and Role-Based Access Control (RBAC) across all systems. Access reviews occur quarterly.

lock

Data Encryption

Data at rest is secured with AES-256 encryption. All web requests and data in transit traverse over encrypted connections using TLS 1.2+ and recognized third-party certificates.

code

Secure SDLC

Software changes are tracked via an enterprise project management tool, require peer reviews, and are tested in non-production environments (free of customer data). We utilise industry-leading Static and Dynamic Application Security Testing (SAST/DAST) tools.

radar

Vulnerability Management

Continuous protection including weekly infrastructure vulnerability scans and annual manual penetration tests. Security events are triaged via a formal Incident Response framework.

data table

Resilience and Backups

Hosted in secure cloud infrastructure across multiple availability zones. Daily automated backups and an annually tested Business Continuity and Disaster Recovery (BCDR) plan ensure high system availability.

person check

Personnel Security

All personnel undergo comprehensive background checks prior to employment. Staff must acknowledge our Code of Conduct and complete security awareness training within 7 days of hire.

Security Portal

Access our public security programs, policies, and acknowledgments.

shield

Trust Center

View our real-time security posture and continuous compliance monitoring.

Visit the Trust Center arrow outward

search

Vulnerability Disclosure

Review our guidelines and scope for reporting security vulnerabilities.

View disclosure guidelines arrow outward

security.txt

Our machine-readable RFC 9116 standards security contact information.

View security.txt arrow outward

Frequently Ask Questions

Common questions from security, risk, and procurement teams.

Where is Certn's data hosted?

The Certn Human Risk Intelligence Platform is hosted entirely within secure, ISO 27001-certified enterprise-grade cloud data centers (located in Canada, Australia, the UK, and/or the EU depending on the region). We do not operate on-premise servers.

Do you perform regular penetration testing?

Yes. We conduct external penetration tests at least annually by a certified third-party firm, and internal penetration testing quarterly by our in-house security team. We also maintain a formal Vulnerability Disclosure Program (VDP) to provide safe harbor for responsible security research.

How do you handle customer data deletion requests?

We maintain a formal data retention and disposal policy in compliance with applicable regulations (e.g. PIPEDA, GDPR, FCRA). Our platform allows clients to configure their own data retention periods. Secure deletion processes are applied when data is no longer required.

What is you incident response protocol?

Certn maintains a formal Incident Management policy. Our SLA is to inform affected clients within 24 hours of becoming aware of a data incident. We utilise an Enterprise SIEM to achieve real-time logging, monitoring, and alerting of security events across our environment.

Have you experienced any recent security breaches?

As verified in our latest SOC 2 Type 2 report (covering Sept 16, 2024 to Sept 15, 2025), there were no system incidents requiring disclosure resulting from a control failure or causing significant impairment to our service commitments.

Access our full compliance documentation

Visit our Trust Centre to download our public SOC 3 report, or sign an NDA to request our complete security package, including the detailed SOC 2 Type 2 report, ISO 27001 certificate, and latest penetration testing executive summary.