Built like grown-up software

Encryption at rest and in transit, identity that maps to yours, and an audit log that survives your auditor's questions.

In place today
AES-256 at rest TLS 1.3 in transit OIDC, SAML and SCIM Append-only audit log AU, EU and US regions
Data

Encryption and data handling

At rest

All persisted data is encrypted, indexes and embeddings included. Backups use separate keys.

AES-256 Per-tenant
In transit

Encrypted between every service hop. Nothing moves unencrypted, internal or external.

TLS 1.3 mTLS internal
Key management

AWS KMS on Certant Cloud, your KMS or HSM on a sovereign deployment. Customer-managed keys work on both tiers, so you hold them and you revoke them.

AWS KMS HSM CMK
Data minimisation

We index what you upload, and prompts are not kept past the audit horizon. We never train models on customer data.

No training Audit horizon
Identity

Identity and access

Single sign-on

Tested with the providers your IT team already uses.

OIDC SAML 2.0 Okta Azure AD Google Auth0
SCIM provisioning

Users and groups sync from your IdP. De-provisioning is automatic, so leavers lose access the same day.

SCIM 2.0 Auto deprovision
Role-based access

Permissions at the workspace, knowledge base, agent and chatbot level. Inherits into chat answers, so Certant won't surface what the user couldn't read directly.

RBAC Inherited at query
Per-document ACLs

Where your source system carries them, Certant respects them at query time. The bot can't cite what the user can't open.

SharePoint Google Drive Confluence Box
Audit

Audit and monitoring

Audit logs

Every auth, query, agent run, document ingest and config change, with actor, timestamp and payload digest.

Actor Timestamp Digest
Retention

365 days on Certant Cloud, and configurable on a sovereign deployment, so you can set it to your auditor's horizon.

365 days · Certant Cloud Configurable · sovereign
Streaming

Logs stream to your existing forensics stack; you pick the destination.

S3 Splunk Datadog S3-compatible
Append-only

Entries cannot be changed once written, so tampering shows.

WORM Tamper-evident
Third parties

Sub-processors

We list every sub-processor that touches Certant Cloud customer data.

A sovereign deployment uses no sub-processors at all, because your data never leaves your perimeter.

Sub-processorPurposeRegion
AWSCompute, storage, KMSAU, EU, US
OVH CloudCompute, storageEU
RunpodGPU compute for model inferenceEU, US
DeepInfraGPU compute for model inferenceEU, US
VercelMarketing site and docs hosting. No customer data.Global edge
ResendTransactional email for sales and supportEU
StripeBilling for Certant CloudGlobal
Responsible disclosure

Vulnerability disclosure

Report a vulnerability

Found something? Email [email protected] with a clear description and a reproduction if you have one.

Answered within a day

We answer within a day. We don't pursue good-faith researchers.

One business day
Encrypt sensitive reports

For high-severity issues, encrypt your report with our PGP key below before sending.

PGP key
PGP · 4096R Public key

AC82 61CC ECAD 7EF1 1AE2 8CF8 D85A 7B6C EB8C 4170

Bring your security review.

We answer the questionnaire and share what we have. You don't have to sign an NDA to read this page.

Audit logExample

At 10:42 UTC, A. Ngata exported the Q3 compliance report from Enterprise Agreement 2024.pdf.

Document export · 10:42 UTC Enterprise Agreement 2024.pdf