Security · Data Handling · Assurance

Security & data-handling dossier

How the CERTE governance platform protects customer data: our security architecture, encryption and data-handling practices, compliance approach, and the controls behind the product. Prepared for procurement, risk, and audit teams.

CERTE is a governance, risk, and continuity platform hosted entirely within Australia. We hold platform data to a least-privilege, encrypted-by-default standard and actively track an independent remediation roadmap. Detailed assessment findings are available to verified stakeholders.

Explore architecture

Security Architecture

Defense in depth — how CERTE is built

CERTE applies layered controls across infrastructure, data, identity, and application. The description below reflects the platform as actually deployed.

LAYER 01INFRASTRUCTURE

Infrastructure

Hosted in AWS Sydney (ap-southeast-2) on Amazon Linux 2023 with Alpine-based Docker containers. Weekly OS patching is applied to the underlying platform.

AWSEC2Dockerap-southeast-2
LAYER 02ENCRYPTED

Data Protection

AES-256-GCM at rest via AWS KMS across database storage, backups, and S3 report files. TLS in transit with TLS 1.0/1.1 disabled at the load balancer.

AES-256-GCMAWS KMSTLS 1.2+S3
LAYER 03ENFORCED

Identity & Access

Administrative and staff access uses IAM least-privilege with enforced MFA (passkey/TOTP/FIDO; SMS disabled). Database access is brokered through a bastion/proxy rather than exposed directly.

IAMMFABastion brokerRBAC
LAYER 04SECURE SDLC

Application

NestJS + Apollo GraphQL backend and a Next.js frontend. Passwords are hashed with bcrypt, ORM queries are parameterised, and dependencies are scanned with Snyk during development.

NestJSNext.jsbcryptSnyk
LAYER 05MONITORED

Logging & Privacy

Activity is logged to AWS CloudWatch with sensitive fields redacted. Critical user actions are recorded against unique IDs to maintain an auditable timeline.

CloudWatchField redactionAudit trail
LAYER 06RESILIENT

Backup & Retention

Encrypted daily database backups are retained in AWS. Generated report files (PDFs) are automatically purged after 7 days to limit data exposure.

Encrypted backupsKMS7-day report TTL

Identity & Access

Built for enterprise identity

Certe authenticates against standards-based enterprise identity. Privileged access already enforces phishing-resistant MFA; end-user MFA and single sign-on are in active development and integrate with any SAML 2.0 / OIDC identity provider — so access stays governed by your own directory.

Available today
  • Phishing-resistant MFA on privileged accessAdmin and infrastructure access enforces passkey / TOTP MFA via IAM. SMS and email codes are disabled.
  • Role-based access controlIn-platform roles — owner, collaborator, viewer — scope access to every document.
  • Encrypted credential storagePasswords are hashed with bcrypt; no credentials are stored in plaintext.
In active development
  • Phishing-resistant MFA for all end usersTOTP authenticator apps and passkeys / FIDO2. SMS and email codes are intentionally excluded.
  • Enterprise SSO (SAML 2.0 / OIDC)Sign in through your own identity provider — no separate Certe password to manage.
  • Automated de-provisioning (SCIM)Disable a user in your directory and their Certe access is revoked automatically — no manual offboarding.
  • Inherited conditional accessRisk-based access policies and threat protection from your identity provider apply to Certe sign-ins.

Why single sign-on matters

Centralised off-boarding

Revoke access in your directory and it ends in Certe immediately — closing the window where a departing employee could retain access to sensitive risk documents.

Oversight & logging

Every sign-in flows through your identity provider’s audit trail, giving your security team full visibility with no extra tooling.

Inherited security policy

Conditional access and threat detection from your identity provider automatically block compromised accounts and alert your team.

Standards-based by design: Certe integrates with any SAML 2.0 / OIDC identity provider, so identity, MFA policy, and access governance stay in your control. Planning an enterprise rollout? Talk to our team about SSO.

Data Handling & Residency

What we hold, and where it lives

CERTE is a self-reporting governance and risk tool. We design to minimise the personal information held and to keep customer data within Australia.

Primary dataBusiness-confidential governance & risk content
Personal informationMinimal — stakeholder names & email addresses
Not collected by designNo health records · no payment-card data stored on platform
ResidencyAWS Sydney — no overseas transfer without consent
At restAES-256-GCM (AWS KMS)
Report retentionGenerated PDFs purged after 7 days

Free-text fields may contain organisationally sensitive material; access is restricted to invited document owners, collaborators, and viewers.

Data resides in Australia — AWS Sydney

Compliance & Assurance Approach

Standards, frameworks & status

We are transparent about what is certified, what is aligned, and what is still under evaluation. CERTE does not currently hold formal ISO or SOC certification — items below reflect our genuine control posture and direction.

Aligned

Australian Privacy Act 1988 (APPs)

Data handling aligned to the 13 Australian Privacy Principles, including the Notifiable Data Breach scheme. The platform is designed to minimise personal information.

APP alignedAU-hosted
Enforced

Data Residency — Australia

All platform data is hosted in the AWS Sydney region. Personal information is not transferred overseas without explicit consent.

AWS ap-southeast-2No overseas transfer
Completed

Independent Security Review

An external review of the platform was completed in 2025. Findings are tracked on a remediation roadmap; the detailed register is available to verified stakeholders.

Reviewed 2025Remediation tracked
Reference framework

OWASP ASVS / Top 10

Application security controls are reviewed against the OWASP Application Security Verification Standard and Top 10 risk categories.

ASVS L2 targetCode review
Aligning

ASD Essential Eight

The ASD Essential Eight mitigation strategies are used as a hardening reference for patching, application control, and access management.

Hardening referenceMaturity assessment planned
Reference framework

NIST CSF 2.0

Controls are mapped against the NIST Cybersecurity Framework core functions to structure our security programme.

Govern → RecoverSelf-assessed
Under evaluation

ISO/IEC 27001:2022 Procurement

Not currently certified. We are assessing the path to an Information Security Management System certification as the product matures.

Not yet certifiedEvaluating
Under evaluation

SOC 2 Procurement

Not currently held. Trust Services Criteria readiness is being explored to support enterprise procurement.

Not yet heldExploring readiness

Items flagged Procurement are commonly requested in enterprise procurement. CERTE does not currently hold ISO/IEC 27001 or SOC 2 certification; these are represented as under evaluation rather than achieved.

Independent & Internal Assessment

Security assessment register

A transparent, evidence-based record of findings and remediation. The summary, roadmap, and lower-severity findings are published openly; high and critical findings are released to verified stakeholders under NDA.

Loading assessment…