Security

Last updated 9 September 2026

Certadian holds the record of how a planning application was delivered, so how that record is protected matters as much as what it contains. This page sets out how the platform is built. We will keep it current as the platform grows, and we would rather say what is true today than describe an end state.

Where it runs

The platform runs on Amazon Web Services in the London region. Your information is held in the United Kingdom.

Separation between customers

Every record belongs to one customer, and the database enforces that itself rather than relying on the application to remember. We test it by trying to read another customer’s data and requiring the attempt to be refused, so the tests fail loudly if the separation is ever weakened.

The audit record

The audit record is append only. Entries cannot be edited or removed, including by us. What was recorded at the time stays as it was recorded.

Access

People have named accounts, not shared ones. Access is granted by role and kept to what the role needs. Administrative access to the underlying infrastructure sits with Certadian.

Our suppliers

Certadian is built with a development partner, under a written agreement covering confidentiality, and with defined access that Certadian controls.

Certification

Certadian is working towards Cyber Essentials. We do not describe a certification as held until it has been issued, so this page will name it, and the date it was issued, once it is.

Reporting something


If you think you have found a security problem, write to support@certadian.com. We will acknowledge it within two working days and tell you what we are doing about it.