Security

How We Protect Your Data

Last updated: October 4, 2026

No marketing language: just what we run, how we isolate your data, and what happens if something goes wrong.

Infrastructure & Hosting

CertLister runs on Google Cloud Platform — one of the most audited and certified cloud environments in the world. We use no self-managed servers. Our website and verification pages (certlister.com and customers' custom verification domains) are delivered through Cloudflare's network, which also handles their HTTPS connections.

  • Application layer: Google Cloud Run — fully managed, auto-scaling containers with no persistent server state
  • Database: PostgreSQL on Google Cloud SQL — no direct public internet access; connections are private
  • File storage: Google Cloud Storage, with files organized by organization ID — your PDFs and design assets are never mixed with another organization's files
  • Encryption in transit: All connections use TLS 1.2 or higher. Plain-HTTP requests are redirected to HTTPS, except the path certificate authorities use to check our certificates.
  • Encryption at rest: Google Cloud Platform encrypts all stored data at rest by default using AES-256
  • Daily backups: Cloud SQL performs automated daily backups. Deleted data may persist in encrypted backups for up to 90 days before being purged.
  • Environment isolation: Production and staging environments are fully separate — separate databases, separate storage buckets, separate services

Access & Authentication

Your organization's data is isolated at the database level. Every query is scoped to your organization. Row-level security in the database enforces that scoping on the tables holding your records, on top of the checks in the application.

  • Authentication options: email/password (bcrypt-hashed), Google OAuth 2.0, or email OTP for multi-factor authentication
  • MFA: Available on all accounts at no extra cost. OTP codes are valid for 10 minutes and single-use.
  • Account lockout: Accounts are locked for 15 minutes after 5 consecutive failed login attempts
  • Session management: Authentication uses short-lived JWTs (24 hours). Signing out adds the token to a server-side blocklist. Changing your email or password ends every open session immediately.
  • Role-based access: Within your organization, access is controlled by roles — USER → MANAGER → ADMIN. Users only see what their role permits.
  • Bot protection: Cloudflare Turnstile is applied to public-facing forms to block automated abuse

Network & Application Security

  • Security headers: Our app, website and verification pages are served with HTTP security headers: HSTS, X-Content-Type-Options and a Content Security Policy. The app also sends X-Frame-Options, and our API sets its security headers with Helmet.js. Verification pages can be embedded in an issuer's own site, so they do not send X-Frame-Options
  • CORS: Cross-origin requests are restricted to app.certlister.com. No other origin can make authenticated API calls.
  • Rate limiting: Two-tier system — a global limit of 500 requests per 15 minutes per user, plus stricter limits on authentication endpoints (10 login attempts per 15 minutes)
  • Logging: We log errors and significant events for debugging and abuse detection. We do not log request bodies containing personal data. IP addresses are used for rate limiting, security and usage analytics. They are kept for up to 90 days in our analytics log, and with each verification record — see the Privacy Policy.

Responsible Disclosure

No system is perfectly secure. If you discover a vulnerability in CertLister, we want to hear from you.

  • Contact: support@certlister.com
  • Response time: We review all security reports within 5 business days
  • Our ask: Please don't exploit or publicly disclose the vulnerability until we've had a chance to investigate and fix it
  • We do not currently operate a bug bounty program

We treat all security reports seriously and will keep you informed as we investigate.

Questions about how we use your data? Read our Privacy Policy →

Questions about security?

Email support@certlister.com, or create a free account and see the platform yourself.