Trust Center

Legal & Security

Everything we can publish, published. CertTrigger issues verifiable digital certificates — your recipients’ data belongs to you, we never sell it, market to your recipients, or build a talent network from your lists, and where we don’t have something yet, we say so plainly.

Security & privacy at a glance

What's true today. We don't display seals we haven't earned — planned certifications are in the roadmap below.

Verifiable by anyone
Issuer-controlled revocation
Encrypted in transit & at rest
bcrypt password hashing
Google & Microsoft SSO
You own your recipient data
No AI training on your data
Open Badges 2.0

Credential integrity

What a CertTrigger certificate proves, and who stays in control of it.

Verifiable by anyone

Every certificate carries a public verification URL confirming the issuer, the issue date, and that the certificate is genuine — no login or account required to check it.

Revocation you control

Issuers can revoke a credential at any time. Revoked and expired certificates show their status publicly on the verification page, so a withdrawn credential can’t be passed off as valid.

Tamper-evident by design

Every certificate has a unique, unguessable ID and an authoritative server-side record. The public verification page always reflects that record, so an edited or forged PDF simply won’t match what we show. (Verification is record-based, not a signature embedded in the file.)

Credentials outlive the subscription

Cancelling doesn’t invalidate what you’ve already issued: delivered certificates keep their verification pages, recipients keep their PDFs, and you can export a full record of everything issued at any time.

Open standards

Every certificate exposes an Open Badges 2.0 assertion at its verification URL. Open Badges 3.0 / W3C Verifiable Credentials are on our roadmap.

Your data

What happens to the recipient data and content you put into CertTrigger.

Recipient data belongs to the issuer

The people you issue to are yours, not ours. We never market to your recipients, never sell data, and never build a talent network or directory from the lists you upload.

No AI training on customer data

We don’t train any AI models on your data. The optional AI design assistant sends only your prompt to a third-party model provider to draft a design in the moment — it’s never used to train our models, and we never feed it your recipient lists.

Export and deletion

Export your contact lists, batches and issued-certificate records as CSV from the dashboard at any time. Delete your account and its data from your profile settings — live data goes immediately, backups clear within 30 days.

Retention

We keep your data for as long as your account is active and delete it on request. Backups rotate on a 30-day cycle.

Subprocessors

The third parties that process data on our behalf are listed in full on this page — not behind a request form.

Infrastructure

Where your data lives and how it is protected.

Where your data lives

Your data is hosted on a dedicated Hostinger VPS, managed with Coolify, running in a single region. Need a specific data-residency region? Talk to us.

Encryption

All traffic is served over HTTPS (TLS 1.2+). Sensitive secrets — OAuth tokens and SMTP credentials — are encrypted at rest with AES-256-GCM.

Backups and recovery

We take automated database backups and can restore from them. Formal recovery-time and recovery-point (RTO/RPO) targets are being documented — see the roadmap.

Uptime

We don’t publish a public status page yet — it’s on the roadmap. For incidents affecting your account, we contact you directly.

Account security

Passwords are hashed with bcrypt. Sign-in options include passwordless email one-time codes and Google/Microsoft SSO; app-based two-factor (TOTP) is on the roadmap.

Least-privilege access

CertTrigger is run by a small team. Access to customer data is limited to the operators who maintain the service, and only when needed for support or maintenance — never for marketing, and never sold or shared.

Governance & privacy

Contracts, compliance posture, and how to reach us on security.

GDPR

For the recipient data you upload, you are the data controller and CertTrigger is the data processor — we process it only to deliver your certificates. We support data-subject requests (access, rectification, erasure) via privacy@certtrigger.com.

Data Processing Agreement

A DPA is available on request while we finalise a self-serve download — email privacy@certtrigger.com.

Security questionnaire

Doing a vendor review? Email admin@certtrigger.com and we’ll send our completed questionnaire.

Google account access

Exactly what CertTrigger can and cannot do with a connected Google account.

ScopeWhat it lets CertTrigger doWhy the feature needs it
openid, email, profile (Google)Read your name, email address and profile picture.To let you sign in with Google and create/secure your account.
User.Read (Microsoft)Read your basic Microsoft profile (name, email).To let you sign in with Microsoft.
gmail.send (Google, optional)Send certificate emails from your Gmail — send only, no reading.So certificates arrive from your own address. Requested only if you connect a Gmail sending mailbox.
Mail.Send + offline_access (Microsoft, optional)Send certificate emails from your Outlook mailbox.Same as above, for Outlook. Requested only when you connect it.

We request the narrowest scopes each feature needs. Sign-in uses only basic profile scopes; the send scopes are requested only when you explicitly connect a sending mailbox, and we never read your mail, files or contacts.

Subprocessors

The third parties that process data on our behalf.

ProviderPurposeData processedLocationAdded on
Hostinger (via Coolify)Application hosting & databaseAll application dataSingle-region VPSSince launch
Resend / BrevoTransactional & platform emailRecipient addresses, email contentEU / USSince launch
Lemon SqueezySubscription billing (merchant of record)Billing name, email, payment detailsUS / globalSince launch
Anthropic / DeepSeekAI design generation (optional feature)Only the prompt you submitUSSince launch
Google & MicrosoftOptional sign-in and send-from-your-mailboxBasic profile; email content only when you send via your mailboxGlobalSince launch

Want to be notified when this list changes? Email privacy@certtrigger.com and we’ll add you.

Roadmap — not yet achieved

Planned work. Nothing in this list is in place today — we’ll move each item into the sections above when it ships.

  • App-based two-factor authentication (TOTP)
  • Public status page
  • Self-serve DPA & security-questionnaire downloads
  • Open Badges 3.0 / W3C Verifiable Credentials
  • Documented backup RPO/RTO targets
  • SOC 2 — under consideration as we scale

Frequently asked questions

Where is my data stored?
Your data is hosted on a dedicated Hostinger VPS in a single region, managed with Coolify. If you need a specific data-residency region, contact us.
Who owns the recipient data I upload?
You do. The recipients you upload are yours — we act only as a processor to deliver your certificates. We never sell your data, market to your recipients, or build a directory from your lists.
Do you train AI models on my data?
No. We don’t train any AI models on your data. The optional AI design assistant sends only your prompt to a third-party model to draft a design in the moment; your recipient data is never used for training.
What happens to issued certificates if I cancel my plan?
Certificates you’ve already issued stay valid — their verification pages keep working and recipients keep their PDFs. You can export a full record of everything issued before or after cancelling.
Can I delete my account and all associated data?
Yes. Delete your account and its data from your profile settings; live data is removed immediately and clears from rotating backups within 30 days.
Do you have SOC 2 or ISO 27001?
Not yet. We’re an early-stage product and don’t hold SOC 2 or ISO 27001 today — and we won’t display badges we haven’t earned. What we do today: HTTPS everywhere, AES-256-GCM encryption of stored secrets, bcrypt password hashing, least-privilege access, and this public Trust Center. Formal certifications are under consideration as we grow (see the roadmap).
Can recipients verify a certificate without an account?
Yes. Every certificate has a public verification URL — anyone can confirm the issuer, issue date and validity without logging in or creating an account.
Do you contact my recipients?
No. We only email your recipients the certificates you send them. We never market to them or contact them for our own purposes.
Report an issue

Talk to us about security

Doing procurement, or found a vulnerability? Reach a human — no bot, no form maze. Report vulnerabilities to admin@certtrigger.com; we aim to acknowledge within 3 business days.