Security
Your compliance data, protected.
CertFlow holds the evidence that proves your firm is compliant, and we treat it accordingly: SOC 2 infrastructure, isolated per customer, encrypted, backed up and fully auditable.
UK-hosted, SOC 2 infrastructure
Your data is hosted in the UK on enterprise cloud infrastructure operated to SOC 2 standards, encrypted in transit and at rest.
Isolated per company
Every organisation has its own separate database schema, logically isolated so one customer can never reach another customer’s data.
Daily backups
Automated daily backups with point-in-time recovery, so your records are never a single failure away from loss.
Full audit logging
Every action is logged with user, timestamp and IP, giving you a defensible record years after the event.
Role-based access
Granular permissions control who can see and do what, with separate client-portal access that exposes only their own data.
Your data, portable
Your data remains yours. Export it in full at any time, with no lock-in.
Hosting & isolation
UK-hosted, SOC 2 infrastructure, isolated per customer.
CertFlow is hosted in the UK on enterprise cloud infrastructure operated to SOC 2 standards. Every organisation's data lives in its own separate database schema, kept logically isolated from every other customer, so your compliance records are never co-mingled with anyone else's. For security reasons we keep the finer details of our architecture private, and we are happy to work through specific due-diligence or procurement requirements directly.
GDPR & data protection
CertFlow is GDPR compliant and operates as a data processor on your behalf. A Data Processing Agreement is available covering the categories of data we process, the security measures in place, and sub-processor arrangements.
If you have a specific security, due-diligence or procurement requirement, contact us and we will work through it with you.
See also our Privacy Policy, Data Processing Agreement and GDPR statement.