Security is not a feature of CertAssist. It is the whole idea.
Last updated: 31 August 2026
Unlike most compliance platforms, CertAssist does not connect to your cloud, identity provider, code or infrastructure, and it does not pull your live data. There are no integrations to secure and no agents installed on your systems, so CertAssist cannot become a way in for an attacker. This is a deliberate design choice that keeps your environment smaller and safer.
CertAssist runs on Google Cloud and Firebase, enterprise-grade infrastructure with strong physical and network security.
Your data is encrypted in transit using TLS and encrypted at rest.
Multi-factor authentication using an authenticator app is mandatory for every account, so a password alone is never enough to sign in.
Access is role based. You control which people can see and edit each assessment, and auditors can be given read-only access scoped to what they need to review.
You own the data you put into CertAssist, and you can request an export or deletion of your data at any time.
If you believe you have found a security issue, please email contact@certassist.io and we will respond promptly. We appreciate responsible disclosure.
We hold ourselves to the same standards we help our customers meet. Formal certification of the CertAssist platform against recognised frameworks is on our roadmap, and we run our own platform through CertAssist as part of that work.