Skip to content
Certrevo
Security

Your students' records, kept apart from everyone else's.

Education records are sensitive: transcripts, identity documents, payment receipts, and in some programs, information about who was rejected. The architecture starts from that.

One tenant per deployment

Your institution runs on a dedicated application instance. There is no shared runtime, so another customer's traffic cannot affect your availability and a bug in their configuration cannot reach your data.

A database of your own

Not a tenant column in a shared table. Your records live in a Postgres database provisioned for you alone, which is what makes a clean export and a clean exit possible.

Data residency you choose

Pick the region your database and application run in. Students are served from nearby, and records stay in the jurisdiction you selected.

Least privilege by role

Five roles, and permissions enforced on the server rather than by hiding buttons. Instructors cannot read the payment ledger. Payment receipts and student contact details are gated to staff who need them.

In transit and at rest

All traffic is served over TLS. Data at rest is encrypted by the managed database and object storage providers. Sessions are carried in signed, HTTP-only cookies and revoked on password change.

Card details never touch us

Card and wallet payments are completed on the payment provider's hosted checkout. Certrevo stores the outcome and the amount, never a card number.

Operational practice

The things that matter after launch day.

Backups
Automated daily backups with point-in-time recovery on the managed database.
Access to your data
Staff access for support is granted per request and time-boxed, not standing.
Student contact details
Instructor and student email addresses are server-only fields. Messages route through a relay so addresses are never exposed in the page.
Audit trail
Enrollment decisions, credential issuance and revocation are recorded against the staff member who performed them.
Rate limiting
Authentication and public submission endpoints are rate limited to slow credential stuffing and form abuse.
Dependencies
Package versions are pinned and lockfiles committed, so a compromised upstream release is not pulled in automatically.
Sub-processors

Who else touches your data.

Certrevo runs on managed infrastructure. These are the categories of provider involved in a standard deployment; the specific vendors and regions are named in your agreement.

Application hosting
Serves the application in your chosen region
Managed Postgres
Stores your records; encrypted at rest
Object storage
Holds uploaded documents and receipts
Email delivery
Sends transactional mail from your domain
Payment provider
Processes card and wallet payments

What we do not claim

Certrevo does not currently hold a SOC 2 or ISO 27001 certification, and we are not going to put a badge on this page that we have not earned. What we can do is walk your team through the architecture, answer a security questionnaire, and contract specific commitments where you need them.

If your procurement process requires a certification we do not yet hold, tell us early. It is a fair reason to say no, and we would rather hear it on the first call than the fifth.

Send us your security questionnaire.

We will complete it, and put an engineer on the call rather than an account manager.