Security & Trust

Security With Clear Boundaries

Certifyd combines device-bound cryptography, signed events, recovery controls and data minimisation. We also state what each result does and does not prove.

How We Protect Data

Simple verification.
Every time.

1

Supported approval flows use device-bound cryptographic keys

2

Biometric checks are performed by the phone and biometric templates are not sent to Certifyd

3

Sensitive events create signed or tamper-evident security records where the product supports them

4

Recovery and revocation are designed to invalidate old trust rather than silently transfer it

Security Architecture

Built for zero trust.
Not just compliance.

Device-Bound Approval

Supported flows bind approval to a cryptographic key held by the enrolled device. A valid signature confirms control of that key, not a person’s legal identity or freedom from coercion.

Protected Account Credentials

Where a product uses passwords, the server stores password hashes rather than plaintext. Device private keys and biometric templates are not uploaded to Certifyd.

Replay-Resistant Exchanges

Fresh nonces, short expiry times, signatures and server state are used to detect replay in supported protocols. No security protocol removes every relay, endpoint or implementation risk.

Auditable Verification Trail

Security events record the account, enrolled device, time and result needed for investigation. Some products add a tamper-evident hash chain. Retention and deletion follow the applicable product policy.

Phishing Resistant by Design

Domain-bound WebAuthn credentials and app-bound device keys reduce common credential phishing risks where implemented. Users must still check the request shown on the trusted surface.

Privacy by Default

We aim to collect only the account, device, relationship, request and security data needed for each service. We do not sell personal data or biometric templates.

Compliance & Standards

Enterprise-grade
by design.

UK GDPR

Our controls and processes are designed to support UK GDPR duties including data minimisation, purpose limitation and user rights.

ICO Registered

Registered with the UK Information Commissioner’s Office as a data controller.

Platform Cryptography

Products use platform security capabilities such as WebAuthn, Secure Enclave, Android Keystore, App Attest and Play Integrity where appropriate.

Documented Processing

Our privacy policy describes relevant processing and international-transfer safeguards. Product-specific disclosures are updated as services change.

Security isn't a feature. It's the foundation.