Trust · Security
Security compliance you can prove
Certinal is built to meet the strictest security and privacy standards, so every signature, workflow and record stands up to enterprise, government and auditor scrutiny.
- SOC 1 & 2 Type 2
- ISO 27001
- IRAP
- FIPS 140-2
- APEC PRP
Certifications & standards
The most exhaustive coverage of security compliance
Independently certified and continuously assessed against the frameworks that global enterprises and regulators rely on.

ISO 27001:2013
Specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization.

SSAE SOC 1 & SOC 2 Type 2
Independent attestation of the internal controls that capture how Certinal safeguards customer data - and how effectively those controls operate over time.

TrustArc APEC PRP
The Asia-Pacific Economic Cooperation Privacy Recognition for Processors certification represents the requirements a processor must meet to be recognized as qualified by data controllers.

3rd-party VAPT
Vulnerability Assessment and Penetration Testing by an independent firm, designed to identify and help address cyber-security vulnerabilities before attackers can.

IRAP
The Information Security Registered Assessors Program - a comprehensive independent assessment of a system's security against Australian government policies and guidelines.

ISO 9594-8
Specifies the data objects used to represent public-key certificates and the revocation notices for issued certificates that should no longer be trusted.

FIPS 140-2
The US and Canadian government standard specifying the security requirements for the cryptographic modules that protect sensitive information.

FIPS 186-4
The standard specifying the suite of algorithms that can be used to generate a secure digital signature.
See Certinal's security in action
Get a walkthrough of the controls, certifications and audit trail behind every Certinal agreement.





















