Certadox Security

How we protect your vendor compliance data.

Tenant Isolation

Certadox is architected as a multi-tenant system: every vendor, document, and activity log record is tagged with your company ID, and every application query is scoped to that ID before data is returned. This tenant isolation is enforced in our application layer on every request, so one organization's data is never mixed with another's.

Encryption

  • In transit: All connections between your browser and Certadox are encrypted via HTTPS/TLS.
  • At rest: The database runs on encrypted storage. Uploaded documents (COIs, W-9s, licenses) are stored in encrypted object storage, separate from the application database.

Authentication

We use NextAuth.js with hashed passwords, secure session tokens, and email verification. No credentials are stored in plain text.

Role-Based Access

  • Admin: Full access — manage vendors, invite team members, configure document requirements, change billing.
  • Member: View-only access to compliance dashboards and documents.

Unlimited team members on all plans.

Audit Trail

Every action in Certadox is logged: who uploaded a document, who changed a compliance status, who invited a team member, who approved or rejected a submission. This record is immutable.

Privacy and Your Data

You own your data. You can request access, correction, or deletion at any time. See our Privacy Policy and Terms of Service.

What We Don't Claim (Yet)

  • SOC 2 or ISO 27001 certification: We're built on infrastructure that supports these certifications, but we have not yet completed an external audit. This is on our near-term roadmap.
  • Third-party penetration test: Our architecture follows security best practices, but it has not yet been independently penetration-tested.

Report a Security Issue

If you discover a vulnerability, email security@certadox.com. We will respond within 48 hours.