Verifiable by anyone
Every certificate carries a public verification URL confirming the issuer, the issue date, and that the certificate is genuine — no login or account required to check it.
Everything we can publish, published. CertTrigger issues verifiable digital certificates — your recipients’ data belongs to you, we never sell it, market to your recipients, or build a talent network from your lists, and where we don’t have something yet, we say so plainly.
Last reviewed: 26 July 2026
Our agreements and privacy documents — open, not gated behind a request form.
The terms that govern use of CertTrigger.
Learn moreWhat we collect, how we use it, and your rights.
Learn moreAvailable on request while we finalise a self-serve download — email privacy@certtrigger.com.
Learn moreThe third parties that process data on our behalf, listed in full.
Learn moreDoing a vendor review? Email admin@certtrigger.com and we'll send our completed questionnaire.
Learn moreWhere and how to report a vulnerability.
Learn moreWhat's true today. We don't display seals we haven't earned — planned certifications are in the roadmap below.
What a CertTrigger certificate proves, and who stays in control of it.
Every certificate carries a public verification URL confirming the issuer, the issue date, and that the certificate is genuine — no login or account required to check it.
Issuers can revoke a credential at any time. Revoked and expired certificates show their status publicly on the verification page, so a withdrawn credential can’t be passed off as valid.
Every certificate has a unique, unguessable ID and an authoritative server-side record. The public verification page always reflects that record, so an edited or forged PDF simply won’t match what we show. (Verification is record-based, not a signature embedded in the file.)
Cancelling doesn’t invalidate what you’ve already issued: delivered certificates keep their verification pages, recipients keep their PDFs, and you can export a full record of everything issued at any time.
Every certificate exposes an Open Badges 2.0 assertion at its verification URL. Open Badges 3.0 / W3C Verifiable Credentials are on our roadmap.
What happens to the recipient data and content you put into CertTrigger.
The people you issue to are yours, not ours. We never market to your recipients, never sell data, and never build a talent network or directory from the lists you upload.
We don’t train any AI models on your data. The optional AI design assistant sends only your prompt to a third-party model provider to draft a design in the moment — it’s never used to train our models, and we never feed it your recipient lists.
Export your contact lists, batches and issued-certificate records as CSV from the dashboard at any time. Delete your account and its data from your profile settings — live data goes immediately, backups clear within 30 days.
We keep your data for as long as your account is active and delete it on request. Backups rotate on a 30-day cycle.
The third parties that process data on our behalf are listed in full on this page — not behind a request form.
Where your data lives and how it is protected.
Your data is hosted on a dedicated Hostinger VPS, managed with Coolify, running in a single region. Need a specific data-residency region? Talk to us.
All traffic is served over HTTPS (TLS 1.2+). Sensitive secrets — OAuth tokens and SMTP credentials — are encrypted at rest with AES-256-GCM.
We take automated database backups and can restore from them. Formal recovery-time and recovery-point (RTO/RPO) targets are being documented — see the roadmap.
We don’t publish a public status page yet — it’s on the roadmap. For incidents affecting your account, we contact you directly.
Passwords are hashed with bcrypt. Sign-in options include passwordless email one-time codes and Google/Microsoft SSO; app-based two-factor (TOTP) is on the roadmap.
CertTrigger is run by a small team. Access to customer data is limited to the operators who maintain the service, and only when needed for support or maintenance — never for marketing, and never sold or shared.
Contracts, compliance posture, and how to reach us on security.
For the recipient data you upload, you are the data controller and CertTrigger is the data processor — we process it only to deliver your certificates. We support data-subject requests (access, rectification, erasure) via privacy@certtrigger.com.
A DPA is available on request while we finalise a self-serve download — email privacy@certtrigger.com.
Doing a vendor review? Email admin@certtrigger.com and we’ll send our completed questionnaire.
Email admin@certtrigger.com. We aim to acknowledge reports within 3 business days. Good-faith research is welcome — see Report an issue.
Exactly what CertTrigger can and cannot do with a connected Google account.
| Scope | What it lets CertTrigger do | Why the feature needs it |
|---|---|---|
| openid, email, profile (Google) | Read your name, email address and profile picture. | To let you sign in with Google and create/secure your account. |
| User.Read (Microsoft) | Read your basic Microsoft profile (name, email). | To let you sign in with Microsoft. |
| gmail.send (Google, optional) | Send certificate emails from your Gmail — send only, no reading. | So certificates arrive from your own address. Requested only if you connect a Gmail sending mailbox. |
| Mail.Send + offline_access (Microsoft, optional) | Send certificate emails from your Outlook mailbox. | Same as above, for Outlook. Requested only when you connect it. |
We request the narrowest scopes each feature needs. Sign-in uses only basic profile scopes; the send scopes are requested only when you explicitly connect a sending mailbox, and we never read your mail, files or contacts.
The third parties that process data on our behalf.
| Provider | Purpose | Data processed | Location | Added on |
|---|---|---|---|---|
| Hostinger (via Coolify) | Application hosting & database | All application data | Single-region VPS | Since launch |
| Resend / Brevo | Transactional & platform email | Recipient addresses, email content | EU / US | Since launch |
| Lemon Squeezy | Subscription billing (merchant of record) | Billing name, email, payment details | US / global | Since launch |
| Anthropic / DeepSeek | AI design generation (optional feature) | Only the prompt you submit | US | Since launch |
| Google & Microsoft | Optional sign-in and send-from-your-mailbox | Basic profile; email content only when you send via your mailbox | Global | Since launch |
Want to be notified when this list changes? Email privacy@certtrigger.com and we’ll add you.
Planned work. Nothing in this list is in place today — we’ll move each item into the sections above when it ships.
Doing procurement, or found a vulnerability? Reach a human — no bot, no form maze. Report vulnerabilities to admin@certtrigger.com; we aim to acknowledge within 3 business days.