Security & compliance
Trust is the product. Security is how we earn it.
Credfex handles some of the most sensitive personal data an organisation holds. Every architectural decision starts from that fact: encrypt everything, grant the minimum, log every action and make consent explicit.
Security pillars
Defence in depth, from the browser to the database.
Encryption everywhere
TLS 1.2+ for all traffic, AES-256 for data at rest, field-level encryption for sensitive attributes and keys held in a hardware-backed KMS with automated rotation.
Identity & access
SSO/SAML 2.0, enforced MFA for privileged roles, least-privilege RBAC, IP allow-listing and short-lived scoped tokens for every API integration.
Signed, tamper-evident records
Every credential is hashed and signed with a key belonging to the issuing legal entity. Signature status is evaluated on every verification.
Complete audit trail
Immutable, timestamped logs of issuance, consent, verification and administrative actions, exportable to your SIEM or GRC platform.
Resilient infrastructure
Multi-availability-zone deployment, encrypted point-in-time backups, tested disaster recovery and a 99.9% uptime target with 24×7 monitoring.
Secure development
Peer-reviewed code, dependency scanning, static analysis in CI, regular third-party penetration testing and a responsible disclosure programme.
Privacy by design
Consent is not a checkbox. It is the access control model.
On Credfex, a verifier cannot read a credential unless the professional has granted consent that is specific, time-bound and revocable. The consent reference is stored with every verification report.
- Purpose limitation. Data is processed only to issue, hold and verify employment credentials. Nothing is sold, profiled or shared for advertising.
- Data minimisation. Issuers choose which fields to include; sensitive fields such as compensation are off by default.
- Data-subject rights. Professionals can view, export, dispute and request deletion of their data from the wallet.
- Clear roles. Employers are data fiduciaries for what they issue; Credfex acts as a processor under a documented agreement.
Privacy by design
Notice, explicit consent, purpose limitation and grievance handling are built into every issuance and verification workflow.
GDPR-ready
Lawful basis, data-subject rights and processor agreements aligned with GDPR for organisations operating in or hiring from the EU/UK.
ISO 27001 aligned
Information security management practices aligned with ISO/IEC 27001 controls across people, process and technology.
Data residency
Regional hosting options available for enterprise agreements, so data stays where your policies require.
- Background-checked staff with role-based production access and periodic access reviews
- Environment separation: production, staging and sandbox never share data or keys
- Vulnerability management with defined remediation SLAs by severity
- Automated dependency and container scanning on every build
- Annual third-party penetration testing and quarterly internal reviews
- Incident response runbooks with customer notification commitments
- Encrypted backups tested through regular restore drills
- Vendor risk assessment for every sub-processor
- Security awareness training for all employees on joining and annually
- Responsible disclosure programme for external researchers
Need a security questionnaire completed?
Share your vendor assessment and we will return it with supporting evidence, or book a session with our security team.