Security
What we actually implement, and nothing more. Every point below describes a measure in place today.
Last updated: July 2026
Authentication
No password is ever stored: you sign in with your organisation’s Google or Microsoft account. Two-factor authentication is mandatory for everyone from the first sign-in, and requested again before sensitive actions. Sessions are opaque, time-limited and revocable.
Isolation between organisations
Every organisation is partitioned by two independent barriers: a filter applied automatically to every query, and a row-level security policy in the database. The second holds even if the first is bypassed. Dedicated tests verify on every release that one organisation can neither read nor write another’s data.
Your evidence stays with you
Certatix stores no evidence files. A piece of evidence is a link to a document you host wherever you choose; we keep only its address and label, and never fetch its content.
Audit trail
Every sensitive action is written to an append-only log, chained by hash: an entry cannot be altered or deleted without breaking the chain. That is what makes the history defensible to an auditor.
Payment
No card details pass through Certatix or are stored by it. Payment happens entirely on our provider’s hosted pages.
Hosting
The application, database and backups are hosted in France with a European provider. Traffic to the platform is encrypted in transit.
Retention and erasure
While your subscription is active, your data stays in your workspace and you can export it yourself at any time. If access is cut off, it remains exportable for 30 days: that is the window in which you take everything back without going through us, and we email you before it closes. After that, the workspace is deleted from our live databases and an encrypted archive is kept for 2 years to meet our legal retention obligations. That archive is not readable in the product and cannot be loaded back into it; it is produced on legitimate request, then permanently erased when the term ends.
Reporting a vulnerability
Write to hello@certatix.com. We acknowledge within two working days and commit to taking no action against anyone reporting a flaw in good faith.