Security controls built for sensitive AML data
How secure is Certivus for AML compliance data?
Certivus is designed for sensitive AML, CDD, KYC, and identity evidence workflows. The platform presents controls for encryption, role-based access, audit logs, monitoring, UK data residency, and vulnerability scanning so practices can review how client data is protected.
- Built for identity documents, screening results, and AML evidence records
- Security controls are part of the buying journey, not an afterthought
- Practices can review data residency, access, logging, and support before rollout
Encryption
In transit + at rest
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
Access Controls
Role-based access
- Granular role-based access control (RBAC)
- Multi-factor authentication (MFA) support
- Principle of least privilege enforced
Monitoring & Logging
Full audit trail
- Real-time security monitoring and alerting
- Comprehensive audit logs for all user actions
Data Residency
UK-based infrastructure
- All data stored in UK-based data centres
- GDPR-compliant data processing
Vulnerability Management
Patching and dependency checks
- Continuous vulnerability scanning
- Regular security updates and patching
Compliance posture
Certivus Compliance Ltd is registered with the ICO (ZC189266) with an appointed Data Protection Officer. Client data is encrypted at rest and in transit and stored in the UK. Our sub-processors are published, and our retention policy sets how long records are kept.
Common security questions
How does Certivus protect AML and identity data?
Certivus uses encryption in transit and at rest, access controls, monitoring, audit logs, UK data residency controls, and vulnerability scanning to protect sensitive AML and identity evidence.
Why does security matter for AML software?
AML software can hold identity documents, verification results, screening outcomes, risk decisions, and audit records. Practices should review access control, encryption, data residency, logging, and support before trusting any provider.
Watch this in practice
All tutorialsAdding colleagues, and what happens when they leave
Invites, what the roles genuinely differ on, and why removal never erases the record.
