Built like grown-up software
Encryption at rest and in transit, identity that maps to yours, and an audit log that survives your auditor's questions.
What we cover
Encryption
Everything we persist is encrypted, indexes and backups included.
See encryption and data handlingIdentity
OIDC, SAML and SCIM, with RBAC by group and per-document ACLs from your source systems.
See identity and accessAudit
Every read, write and prompt, streamed to your SIEM and never rewritten.
See audit and monitoringData residency
Cloud regions in AU, EU and US. A sovereign deployment stays in-country, in-perimeter.
See where data sitsCompliance
APP 8, IRAP and CPS 230, with SOC 2-aligned controls. More detail on the sovereign tier.
Request the compliance detailVulnerability disclosure
Coordinated disclosure against a public PGP key, answered within 24 hours.
See vulnerability disclosureEncryption and data handling
All persisted data is encrypted, indexes and embeddings included. Backups use separate keys.
Encrypted between every service hop. Nothing moves unencrypted, internal or external.
AWS KMS on Certant Cloud, your KMS or HSM on a sovereign deployment. Customer-managed keys work on both tiers, so you hold them and you revoke them.
We index what you upload, and prompts are not kept past the audit horizon. We never train models on customer data.
Identity and access
Tested with the providers your IT team already uses.
Users and groups sync from your IdP. De-provisioning is automatic, so leavers lose access the same day.
Permissions at the workspace, knowledge base, agent and chatbot level. Inherits into chat answers, so Certant won't surface what the user couldn't read directly.
Where your source system carries them, Certant respects them at query time. The bot can't cite what the user can't open.
Audit and monitoring
Every auth, query, agent run, document ingest and config change, with actor, timestamp and payload digest.
365 days on Certant Cloud, and configurable on a sovereign deployment, so you can set it to your auditor's horizon.
Logs stream to your existing forensics stack; you pick the destination.
Entries cannot be changed once written, so tampering shows.
Sub-processors
We list every sub-processor that touches Certant Cloud customer data.
A sovereign deployment uses no sub-processors at all, because your data never leaves your perimeter.
| Sub-processor | Purpose | Region |
|---|---|---|
| AWS | Compute, storage, KMS | AU, EU, US |
| OVH Cloud | Compute, storage | EU |
| Runpod | GPU compute for model inference | EU, US |
| DeepInfra | GPU compute for model inference | EU, US |
| Vercel | Marketing site and docs hosting. No customer data. | Global edge |
| Resend | Transactional email for sales and support | EU |
| Stripe | Billing for Certant Cloud | Global |
Vulnerability disclosure
Found something? Email [email protected] with a clear description and a reproduction if you have one.
We answer within a day. We don't pursue good-faith researchers.
For high-severity issues, encrypt your report with our PGP key below before sending.
AC82 61CC ECAD 7EF1 1AE2 8CF8 D85A 7B6C EB8C 4170
Bring your security review.
We answer the questionnaire and share what we have. You don't have to sign an NDA to read this page.
At 10:42 UTC, A. Ngata exported the Q3 compliance report from Enterprise Agreement 2024.pdf.
