Skip to content

Security & compliance

Trust is the product. Security is how we earn it.

Credfex handles some of the most sensitive personal data an organisation holds. Every architectural decision starts from that fact: encrypt everything, grant the minimum, log every action and make consent explicit.

Security pillars

Defence in depth, from the browser to the database.

Encryption everywhere

TLS 1.2+ for all traffic, AES-256 for data at rest, field-level encryption for sensitive attributes and keys held in a hardware-backed KMS with automated rotation.

Identity & access

SSO/SAML 2.0, enforced MFA for privileged roles, least-privilege RBAC, IP allow-listing and short-lived scoped tokens for every API integration.

Signed, tamper-evident records

Every credential is hashed and signed with a key belonging to the issuing legal entity. Signature status is evaluated on every verification.

Complete audit trail

Immutable, timestamped logs of issuance, consent, verification and administrative actions, exportable to your SIEM or GRC platform.

Resilient infrastructure

Multi-availability-zone deployment, encrypted point-in-time backups, tested disaster recovery and a 99.9% uptime target with 24×7 monitoring.

Secure development

Peer-reviewed code, dependency scanning, static analysis in CI, regular third-party penetration testing and a responsible disclosure programme.

Privacy by design

Consent is not a checkbox. It is the access control model.

On Credfex, a verifier cannot read a credential unless the professional has granted consent that is specific, time-bound and revocable. The consent reference is stored with every verification report.

  • Purpose limitation. Data is processed only to issue, hold and verify employment credentials. Nothing is sold, profiled or shared for advertising.
  • Data minimisation. Issuers choose which fields to include; sensitive fields such as compensation are off by default.
  • Data-subject rights. Professionals can view, export, dispute and request deletion of their data from the wallet.
  • Clear roles. Employers are data fiduciaries for what they issue; Credfex acts as a processor under a documented agreement.

Privacy by design

Notice, explicit consent, purpose limitation and grievance handling are built into every issuance and verification workflow.

GDPR-ready

Lawful basis, data-subject rights and processor agreements aligned with GDPR for organisations operating in or hiring from the EU/UK.

ISO 27001 aligned

Information security management practices aligned with ISO/IEC 27001 controls across people, process and technology.

Data residency

Regional hosting options available for enterprise agreements, so data stays where your policies require.

Operational security

What we do every day to keep the exchange safe.

Talk to our security team
  • Background-checked staff with role-based production access and periodic access reviews
  • Environment separation: production, staging and sandbox never share data or keys
  • Vulnerability management with defined remediation SLAs by severity
  • Automated dependency and container scanning on every build
  • Annual third-party penetration testing and quarterly internal reviews
  • Incident response runbooks with customer notification commitments
  • Encrypted backups tested through regular restore drills
  • Vendor risk assessment for every sub-processor
  • Security awareness training for all employees on joining and annually
  • Responsible disclosure programme for external researchers

Need a security questionnaire completed?

Share your vendor assessment and we will return it with supporting evidence, or book a session with our security team.