Skip to main content

Security & Trust Center

Clear controls. Honest claims.

CertTracker handles employee certification and training records. This page explains how the product protects that data, which providers support the service, and the current limits of our compliance program.

Last reviewed September 20, 2026

Encryption

HTTPS/TLS protects data in transit. Our managed cloud providers encrypt stored application data at rest.

Tenant isolation

Database row-level security and company-scoped queries separate customer records between organizations.

Access controls

Application roles limit administrative actions. Sensitive service credentials remain server-side and are not exposed to browsers.

Managed infrastructure

The application runs on Vercel with authentication and PostgreSQL data services provided by Supabase.

Service providers

Current subprocessors

These providers may process limited data to deliver CertTracker. Payment card information is collected and processed by Paddle, not stored by CertTracker.

Data practices

  • Customers control the employee and training records they enter.
  • Account owners can export records and request account deletion.
  • Certification files are stored in customer-scoped paths with access policies.
  • Customer data is not sold for advertising.
  • Patient health information should not be stored in CertTracker.

Compliance scope

CertTracker helps organize records; it does not certify an organization’s compliance or replace legal, regulatory, or security advice. CertTracker does not currently claim SOC 2, ISO 27001, or HIPAA certification. We will publish evidence here as our assurance program develops.

Templates are operational starting points. Customers should confirm applicable requirements with their regulator, counsel, insurer, or accrediting body.

Security questions or disclosures

Report a suspected vulnerability or request security information by email. Please include enough detail for us to reproduce and investigate the issue.