Security at Certyfy

Secure by design for trusted digital certificates

Certyfy is built to help organizations issue and verify digital certificates with strong access controls, secure authentication, protected certificate records, and reliable public verification.

Secure Certificate Records
  • Certificate records are stored securely in our managed database with row-level access controls.
  • Every certificate is issued with a unique, non-guessable verification ID.
  • The public verification page exposes only verification-safe details (recipient, title, status, issuer).
  • Private organization data, billing details, and account information are never exposed publicly.
QR-Based Verification Security
  • Every certificate receives a unique verification link tied to its ID.
  • QR codes embedded on certificates point only to Certyfy verification pages.
  • Revoked and expired certificates are clearly marked with their current status.
  • Recipients and verifiers don't need to log in to confirm authenticity.
Organization-Level Access Control
  • Organizations can only access certificates they have issued.
  • Authenticated dashboard access is required to issue or manage certificates.
  • Organization members and admins have separate permissions for sensitive actions.
  • Platform admin access is restricted and audited.
Verified Organization Controls
  • Organization verification documents may be reviewed before granting verified status.
  • Name and logo changes for verified organizations may require approval.
  • These checks help reduce fraudulent or misleading certificate issuance.
Payment Security
  • Payments are processed through Razorpay, a PCI-DSS compliant gateway.
  • Certyfy does not store card numbers, UPI handles, or banking credentials on our servers.
  • Payment status is verified through secure server-side signature checks and webhooks.
File Upload Protection
  • Logo, signature, and verification document uploads enforce file type and size limits.
  • Uploaded files are used only for certificate branding and organization verification workflows.
  • Files are scoped to the uploading organization and isolated via access policies.
Public Verification & Long-Term Trust
  • Issued certificates remain publicly verifiable based on their current status.
  • Verification continues to function independently of an organization's plan access state where applicable.
  • Revoked and expired certificates are clearly marked so verifiers always see the truth.
Secrets and API Keys
  • API keys, webhook secrets, and payment credentials are stored as environment secrets.
  • Sensitive secrets are never exposed in frontend code or version-controlled files.
  • Server-side code uses scoped, least-privilege keys for database and third-party access.
Monitoring and Abuse Prevention
  • Suspicious activity, fraudulent usage, or misuse may result in account suspension.
  • Certyfy reserves the right to review organizations and certificate activity to prevent abuse.
  • We respond to credible reports of fraudulent certificate issuance promptly.

Contact security

For security, abuse, or vulnerability reports, contact us. We aim to acknowledge credible reports promptly.

support@certyfy.in

Frequently asked questions

Is certificate verification public?
Yes. Anyone with a verification link or QR code can confirm a certificate's authenticity and current status without logging in.
Does Certyfy store payment card details?
No. All payments are handled by Razorpay. Certyfy never sees or stores your card number, CVV, UPI handle, or banking credentials.
Can revoked certificates still show as valid?
No. Once a certificate is revoked by the issuing organization, the public verification page clearly shows its revoked status.
Can one organization access another organization's certificates?
No. Dashboard access is scoped to each organization. Members of one organization cannot view, edit, or revoke certificates issued by another.
What happens if an organization's plan expires?
Previously issued certificates remain publicly verifiable. The organization may lose access to issue new certificates or use premium features until the plan is renewed manually.
How do I report fraudulent certificate usage?
Email support@certyfy.in with the certificate verification link and a brief description. We review credible reports and take action where appropriate.

Certyfy uses industry-standard practices to help protect your data. This page describes how our platform is designed; it does not represent third-party certifications unless explicitly stated.