Keeping your documentation safe
Security is fundamental to what Credensa does. Agents and suppliers trust the platform with commercially sensitive documentation, and we design, build and operate our systems with that trust in mind.
1. Infrastructure
The Credensa platform is hosted in ISO 27001 certified data centres located in the United Kingdom. Our infrastructure is segregated into separate environments for development, staging and production, with strictly controlled promotion between them.
2. Encryption
All traffic between your browser and our platform is encrypted using TLS 1.2 or above. Documentation and personal data are encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management service, rotated regularly.
3. Access control
Access within the platform is role-based: users only see the suppliers, documents and audit history relevant to their organisation. Internally, access to production data is limited to a small number of authorised engineers, protected by multi-factor authentication, and every access is logged and reviewed.
4. Development practices
Code changes are peer-reviewed and pass automated security and quality checks before release. Dependencies are monitored for published vulnerabilities and patched promptly. We commission periodic penetration testing from independent specialists and act on the findings.
5. Availability and resilience
The platform is architected for high availability with automated failover. Data is backed up continuously, with encrypted backups stored in a separate location and restoration procedures tested regularly.
6. Certifications
Credensa is Cyber Essentials certified, demonstrating our commitment to protecting against the most common cyber threats. We keep our certifications under review as the business grows.
7. Reporting a vulnerability
If you believe you have found a security vulnerability in the Credensa platform, please report it responsibly via our contact page. We investigate all reports and will keep you informed of our progress.