Security is foundational to Certova. Compliance teams trust us with sensitive policy and evidence documents, and we engineer the platform to protect that data.
Data protection
- Encryption in transit - all traffic is served over TLS.
- Encryption at rest - documents are stored in encrypted, S3-compatible object storage.
- Project isolation - each project has its own data scope and an isolated vector store, so the AI assistant only answers from that project's documents.
Access control
- Authentication uses short-lived access tokens with secure, HttpOnly refresh tokens.
- Role-based access within companies and projects.
- Enterprise plans support SSO and SCIM provisioning.
AI processing
Document content is sent to AI model providers only to deliver the analysis you request. Where provider settings allow, content is excluded from training third-party foundation models.
Infrastructure
- Containerized, least-privilege services running on hardened images.
- Secrets are managed outside of source control and injected at runtime.
- Regular dependency and image updates.
Enterprise commitments
Enterprise customers can request a custom Data Processing Agreement (DPA), a security review, and SLA-backed uptime guarantees.
Reporting a vulnerability
If you believe you've found a security issue, please email [email protected]. We appreciate responsible disclosure and will respond promptly.