Security & Trust Center
Clear controls. Honest claims.
CertTracker handles employee certification and training records. This page explains how the product protects that data, which providers support the service, and the current limits of our compliance program.
Last reviewed September 20, 2026
Encryption
HTTPS/TLS protects data in transit. Our managed cloud providers encrypt stored application data at rest.
Tenant isolation
Database row-level security and company-scoped queries separate customer records between organizations.
Access controls
Application roles limit administrative actions. Sensitive service credentials remain server-side and are not exposed to browsers.
Managed infrastructure
The application runs on Vercel with authentication and PostgreSQL data services provided by Supabase.
Service providers
Current subprocessors
These providers may process limited data to deliver CertTracker. Payment card information is collected and processed by Paddle, not stored by CertTracker.
Data practices
- Customers control the employee and training records they enter.
- Account owners can export records and request account deletion.
- Certification files are stored in customer-scoped paths with access policies.
- Customer data is not sold for advertising.
- Patient health information should not be stored in CertTracker.
Compliance scope
CertTracker helps organize records; it does not certify an organization’s compliance or replace legal, regulatory, or security advice. CertTracker does not currently claim SOC 2, ISO 27001, or HIPAA certification. We will publish evidence here as our assurance program develops.
Templates are operational starting points. Customers should confirm applicable requirements with their regulator, counsel, insurer, or accrediting body.
Security questions or disclosures
Report a suspected vulnerability or request security information by email. Please include enough detail for us to reproduce and investigate the issue.