CertiFlow PLUS
Trust Center · LIVE
Trust Center

CertiFlow PLUS

Direct Consulting Solutions SA · Switzerland

Illustrative demo · not live tenant data

Illustrative Trust Center for CertiFlow PLUS’s own posture. Evidence is held in a tamper-evident vault, SHA-256 hash-chained and continuously verifiable server-side. An external immutable-object-store anchor for insider-threat defence remains on the roadmap.

Page generated 2026-08-08. Regenerated every 24 hours.

CertiFlow PLUS’s own evidence is held under Zero-Knowledge Encryption.
CertiFlow PLUS stores ciphertext only. If the platform is subpoenaed or breached, attackers receive mathematical static. Only CertiFlow PLUS holds the keys to CertiFlow PLUS’s evidence. The same model applies to every customer. Detailed cryptographic architecture in the Security page.

Active frameworks

SOC 2 Type 1
AICPA TSC 2017 (rev 2022)
ISO/IEC 27001:2022
2022
GDPR
Regulation (EU) 2016/679
UK GDPR + DPA 2018
2021
HIPAA Security Rule
45 CFR 164.302-318
PCI DSS v4.0
4.0.1 (June 2024)
NIS2 Directive
Directive (EU) 2022/2555
NCA ECC-2:2024
ECC-2 (2024)
UAE IA Standard v2
v2 (2025)

CertiFlow PLUS runs its own compliance programme on this platform. Framework readiness below is illustrative of the shape a live Trust Center takes for customers; a customer’s own Trust Center draws from their tenant’s controls, evidence and audit-chain in real time.

Security posture — what an attacker can take

ScenarioWhat an attacker obtains
Lawful court order, customer-specificCiphertext + plaintext metadata only
Production database breachCiphertext only at rest
Out-of-band backup vault breachCiphertext only at rest
Compromised CertiFlow PLUS insider with rootMetadata only; cannot decrypt evidence

Full threat model and ZKE architecture detail: Security page.

Operational posture

Live status
Operational
View live status →
Audit chain
SHA-256 hash-chained
Hourly Merkle anchor → S3 Object Lock compliance mode

Documents

Need deeper access for an audit?

External auditors can be invited to a read-only Auditor View scoped to the controls in their engagement — every page-view, every comment, every export is recorded in the tamper-evident audit chain. Email shaun@directcs.net with your organisation name and your auditor’s firm name.

CertiFlow PLUS — Zero-Knowledge GRC for regulated SMEs