Trust Center

Legal & Security

Everything we can publish, published. CertTrigger issues verifiable digital certificates — your recipients’ data belongs to you, we never sell it, market to your recipients, or build a talent network from your lists, and where we don’t have something yet, we say so plainly.

1 scan

verifies any certificate, no account needed

VC 2.0

signed credential alongside Open Badges 3.0

EU

hosted, encrypted in transit and at rest

TOTP

app-based two-factor on every account

at a glance

Security & privacy at a glance

What is true today, on every account. We don't display seals we haven't earned: where a certification below belongs to a supplier rather than to us, the card says so, and anything we are only planning sits in the roadmap instead.

Verifiable by anyone
Verifiable without us
Issuer-controlled revocation
Cryptographically signed
Open Badges 3.0 & W3C VC 2.0
You own your recipient data
No AI training on your data
Hosted in the EU
ISO 27001-certified infrastructure
Encrypted in transit & at rest
App-based 2FA (TOTP)
Security audit trail
what a certificate proves

Credential integrity

What a CertTrigger certificate proves, and who stays in control of it.

Verifiable by anyone

Every certificate carries a public verification URL confirming the issuer, the issue date, and that the certificate is genuine — no login or account required to check it. Behind that page sits a signed credential anyone can verify independently.

Revocation you control

Issuers can revoke a credential at any time. The verification page says so publicly, and the withdrawal is published in a signed W3C status list — so even someone holding the file offline can discover it was revoked, rather than having to take our word for it.

Cryptographically signed

Every certificate is issued as a credential signed with your organisation’s own Ed25519 key. Change a single character — the name, the date, the achievement — and the signature stops matching. This is not a record we look up on your behalf; the proof travels inside the credential itself.

Credentials outlive the subscription

Cancelling doesn’t invalidate what you’ve already issued: delivered certificates keep their verification pages, recipients keep their PDFs, and you can export a full record of everything issued at any time.

Open standards, not our format

Every certificate is a W3C Verifiable Credential 2.0 and an Open Badges 3.0 credential, validated against 1EdTech’s own published schema. The Open Badges 2.0 assertion stays exactly where it was, so nothing built against it breaks.

Verifiable without us

Your organisation’s public key is published as a did:web document, so a credential can be checked against it by anyone — with CertTrigger switched off entirely. We publish a single-file verifier that does exactly that and calls no API of ours.

accounts

Account & platform security

The protections running on every account today, not a roadmap.

Sign-in you control

App-based two-factor authentication (TOTP), passwordless one-time codes by email, or single sign-on. Passwords are hashed with bcrypt and never stored in a readable form — we could not tell you your password if you asked.

Guessing gets you nowhere

Repeated failed sign-ins lock an account rather than letting an attacker keep trying, and every attempt is rate-limited by address. Automated probing is detected and blocked without anyone having to be awake for it.

Breached passwords refused

New and changed passwords are checked against public breach corpora and refused if they appear there. The check uses k-anonymity — your password never leaves our servers, in any form.

Sessions you can end

See every signed-in device and sign them all out in one click — from your account, at any time. Changing your password ends every other session automatically.

Roles and workspace isolation

Team members hold a role — designer, operator, manager, admin, owner — and every request is checked against it. One organisation can never read another’s templates, recipients or credentials.

An audit trail that answers questions

Sign-ins, failed attempts, password and role changes, sign-in from a new address — recorded and readable, so "was that us?" has an answer months later rather than a shrug.

ownership

Your data

What happens to the recipient data and content you put into CertTrigger.

Recipient data belongs to the issuer

The people you issue to are yours, not ours. We never market to your recipients, never sell data, and never build a talent network or directory from the lists you upload.

No AI training on customer data

We don’t train any AI models on your data. The optional AI design assistant sends only your prompt to a third-party model provider to draft a design in the moment — it’s never used to train our models, and we never feed it your recipient lists.

Export and deletion

Download any issued certificate as a PDF, a whole batch as a ZIP and claim-form responses as CSV from the dashboard at any time; ask us for a complete export of your data. Deletion is on request from your account address: live data within 30 days, every backup within 90.

Retention

We keep your data for as long as your account is active and delete it on request. Backups are kept daily for 7 days, weekly for 4 weeks and monthly for 3 months.

Subprocessors

Every third party that touches your data is on this page — what it does, what it sees and where it sits. The named vendor list comes with the DPA.

where it runs

Infrastructure

Where your data lives and how it is protected.

Where your data lives

Your data lives on dedicated servers in a single region in Germany, inside the European Union. Need a specific data-residency region? Talk to us.

Certified infrastructure

CertTrigger runs on infrastructure whose provider holds ISO/IEC 27001:2022 certification for its information-security management. That certificate is theirs and covers their operations — it is not a certification of CertTrigger, and we don’t present it as one.

Encryption

All traffic is served over HTTPS (TLS 1.2+). Sensitive secrets — OAuth tokens and SMTP credentials — are encrypted at rest with AES-256-GCM.

Backups and recovery

We take automated database backups and can restore from them. Formal recovery-time and recovery-point (RTO/RPO) targets are being documented — see the roadmap.

Uptime

We don’t publish a public status page yet — it’s on the roadmap. For incidents affecting your account, we contact you directly.

Account security

Passwords are hashed with bcrypt. Sign-in options include passwordless email one-time codes and Google/Microsoft SSO; app-based two-factor (TOTP) is on the roadmap.

Least-privilege access

CertTrigger is run by a small team. Access to customer data is limited to the operators who maintain the service, and only when needed for support or maintenance — never for marketing, and never sold or shared.

governance

Governance & privacy

Contracts, compliance posture, and how to reach us on security.

GDPR

For the recipient data you upload, you are the data controller and CertTrigger is the data processor — we process it only to deliver your certificates. We support data-subject requests (access, rectification, erasure) via privacy@certtrigger.com.

Data Processing Agreement

A DPA is available on request while we finalise a self-serve download — email privacy@certtrigger.com.

Security questionnaire

Doing a vendor review? Email admin@certtrigger.com and we’ll send our completed questionnaire.

connected accounts

Connected accounts

Exactly what CertTrigger can and cannot do with a Google or Microsoft account you connect.

PermissionWhat it lets CertTrigger doWhy the feature needs it
Sign in with Google or MicrosoftYour name, email address and profile picture — nothing else.So you can sign in without another password for us to store.
Send from your own mailbox (optional)Send certificate emails as you. Sending only: we cannot read your mail, your files, your calendar or your contacts.So certificates arrive from your address rather than ours. Asked for only if you connect a mailbox, and revocable from your account at any time.

We ask for the narrowest permission each feature needs, and never more in advance of needing it. Sending is requested only when you choose to connect a mailbox, and you can disconnect it at any time — from your account here, or from your Google or Microsoft security settings. Access tokens are encrypted at rest and used for nothing but sending the certificates you send.

third parties

Subprocessors

The third parties that process data on our behalf.

ServicePurposeData processedLocationAdded on
Cloud hosting & databaseRuns the platform and stores your dataAll application dataGermany (EU), single regionSince launch
Email deliveryDelivers certificates and account emailRecipient addresses, email contentEU / USSince launch
PaymentsSubscription billing, as merchant of recordBilling name, email, payment details — we never see or store a card numberUS / globalSince launch
AI design assistance (optional)Drafts a design from your prompt, only when you ask it toOnly the prompt you submit — never your recipient listsUSSince launch
Identity providers (optional)Sign-in, and sending from your own mailboxBasic profile; email content only when you send via your mailboxGlobalSince launch

We describe each subprocessor by the job it does rather than naming the vendor here. The named list is part of our Data Processing Agreement and goes to anyone running a vendor review — ask at privacy@certtrigger.com and it comes back the same day. Want to hear when this list changes? Ask at the same address and we’ll add you.

not yet

Roadmap — not yet achieved

Planned work. Nothing in this list is in place today — we’ll move each item into the sections above when it ships.

  • Public status page
  • Self-serve DPA & security-questionnaire downloads
  • Documented backup RPO/RTO targets
  • SOC 2 — under consideration as we scale
questions

Frequently asked questions

The questions a security review usually opens with. If yours is not here, ask us — the answer will end up on this page.

Where is my data stored?

On dedicated servers in a single region in Germany, inside the European Union, running on infrastructure whose provider is certified to ISO/IEC 27001:2022. If you need a specific data-residency region, contact us.

Who owns the recipient data I upload?

You do. The recipients you upload are yours — we act only as a processor to deliver your certificates. We never sell your data, market to your recipients, or build a directory from your lists.

Do you train AI models on my data?

No. We don’t train any AI models on your data. The optional AI design assistant sends only your prompt to a third-party model to draft a design in the moment; your recipient data is never used for training.

What happens to issued certificates if I cancel my plan?

Certificates you’ve already issued stay valid — their verification pages keep working and recipients keep their PDFs. You can export a full record of everything issued before or after cancelling.

Can I delete my account and all associated data?

Yes. Ask us from the email address on your account, at privacy@certtrigger.com, and we delete your live data within 30 days and confirm it to you. Backups are kept daily for 7 days, weekly for 4 weeks and monthly for 3 months, so a deleted record is gone from every backup within 90 days. Certificates you have already issued stay verifiable, as the privacy policy explains.

Do you have SOC 2 or ISO 27001?

Not ourselves, and we won’t display a badge we haven’t earned. One distinction worth stating plainly, because it is easy to blur: the infrastructure we run on is certified to ISO/IEC 27001:2022, but that certificate belongs to our hosting provider and covers their operations — it says nothing about CertTrigger’s own practices. What we do ourselves today: HTTPS everywhere, AES-256-GCM encryption of stored secrets, bcrypt password hashing, least-privilege access, and this public Trust Center. Formal certification of our own is under consideration as we grow (see the roadmap).

Can recipients verify a certificate without an account?

Yes. Every certificate has a public verification URL — anyone can confirm the issuer, issue date and validity without logging in or creating an account.

Do you contact my recipients?

No. We only email your recipients the certificates you send them. We never market to them or contact them for our own purposes.

Report an issue

Talk to us about security

Doing procurement, or found a vulnerability? Reach a human — no bot, no form maze. Report vulnerabilities to admin@certtrigger.com; we aim to acknowledge within 3 business days.