Security With Clear Boundaries
Simple verification.
Every time.
Supported approval flows use device-bound cryptographic keys
Biometric checks are performed by the phone and biometric templates are not sent to Certifyd
Sensitive events create signed or tamper-evident security records where the product supports them
Recovery and revocation are designed to invalidate old trust rather than silently transfer it
Built for zero trust.
Not just compliance.
Device-Bound Approval
Supported flows bind approval to a cryptographic key held by the enrolled device. A valid signature confirms control of that key, not a person’s legal identity or freedom from coercion.
Protected Account Credentials
Where a product uses passwords, the server stores password hashes rather than plaintext. Device private keys and biometric templates are not uploaded to Certifyd.
Replay-Resistant Exchanges
Fresh nonces, short expiry times, signatures and server state are used to detect replay in supported protocols. No security protocol removes every relay, endpoint or implementation risk.
Auditable Verification Trail
Security events record the account, enrolled device, time and result needed for investigation. Some products add a tamper-evident hash chain. Retention and deletion follow the applicable product policy.
Phishing Resistant by Design
Domain-bound WebAuthn credentials and app-bound device keys reduce common credential phishing risks where implemented. Users must still check the request shown on the trusted surface.
Privacy by Default
We aim to collect only the account, device, relationship, request and security data needed for each service. We do not sell personal data or biometric templates.
Enterprise-grade
by design.
UK GDPR
Our controls and processes are designed to support UK GDPR duties including data minimisation, purpose limitation and user rights.
ICO Registered
Registered with the UK Information Commissioner’s Office as a data controller.
Platform Cryptography
Products use platform security capabilities such as WebAuthn, Secure Enclave, Android Keystore, App Attest and Play Integrity where appropriate.
Documented Processing
Our privacy policy describes relevant processing and international-transfer safeguards. Product-specific disclosures are updated as services change.