Simple Certificate Tracker is built for small teams tracking training certificates, DBS checks, and licences. This page describes our security practices in plain language — not marketing claims we cannot substantiate.
Authentication & sessions
- Passwords are hashed with bcrypt — we never store plain-text passwords.
- Sessions use secure, HTTP-only cookies.
- Email verification and password reset use time-limited single-use tokens.
Encryption
- All traffic is encrypted in transit using HTTPS (TLS 1.2+).
- Database and file storage use provider-standard encryption at rest.
- Uploaded certificate documents are not served from public URLs.
Access control
- Each organisation's data is isolated — users only see their own organisation.
- Document downloads require authentication (or short-lived signed URLs for S3 storage).
- API routes and server actions verify the session on every request.
Document storage (Premium)
Certificate files (PDF, JPG, PNG) are stored privately. We validate file type and size (10MB maximum). Depending on configuration, files are stored in the application database or private S3-compatible object storage — never on a public bucket.
Audit log (Premium)
Premium accounts record who created, updated, or deleted employees and certificates. View the audit log in Settings and export it as CSV for internal reviews.
Infrastructure
We use established cloud providers for hosting, database, email, and payments. See our sub-processor list for details. Production deployments should use EU or UK database regions where available.
Data retention
- Employee and certificate records are kept while your account is active and you choose to retain them.
- Deleted employees and certificates are soft-deleted and excluded from dashboards; records may be retained for recovery until permanently removed.
- On account deletion request, we delete or anonymise personal data within 90 days unless we must retain limited records for legal obligations.
- Uploaded certificate documents (Premium) are deleted when the parent certificate is deleted or when your organisation data is removed.
What we do not claim
We do not claim SOC 2, ISO 27001, or "bank-level" security unless explicitly obtained and published. We focus on sensible practices appropriate for a small-business SaaS product. The service helps you track certificates — it does not guarantee legal compliance.
Report a security issue
Email hello@simplecertificatetracker.com if you discover a vulnerability. We will respond as quickly as we can.