Organization isolation
Data and operations are scoped by organization to separate access across tenants.
SECURITY · EVIDENCE · RESPONSIBILITY
Certo combines application controls with Google Cloud infrastructure. We document what Certo protects, what depends on the deployment model, and what remains with the customer.
See controlsSecurity is layered and validated according to the contracted scope and each customer’s configuration.
Data and operations are scoped by organization to separate access across tenants.
Roles, permissions, and product entitlements limit the capabilities available to each user.
Encrypted transport and cloud-managed encryption protect data in transit and at rest.
Operational credentials remain outside source code and are managed as protected configuration.
Available administrative events and audit records support investigation of relevant activity and changes.
Data backups and automated CI/CD checks reduce risk during operations and deployments.
GOOGLE CLOUD INFRASTRUCTURE
Google Cloud maintains third-party certifications and reports for services within its scope. Certo uses those services as part of its architecture; applicable coverage depends on the service and contracted configuration.
Important distinction: ISO and SOC 2 apply to Google Cloud. They do not mean Certo currently holds its own ISO certification or SOC 2 report.
Product controls remain consistent; infrastructure ownership and operating tasks change.
| Responsibility | Certo Cloud | Certo Isolated | Certo BYOC |
|---|---|---|---|
| Cloud project | Owned by Certo | Owned by Certo | Owned by the customer |
| Isolation | Shared platform with organization-level separation | Infrastructure dedicated to the customer | Customer project with agreed boundaries |
| Certo operations | Managed by Certo | Managed by Certo | Managed by Certo under agreement |
| Identity and users | Configuration shared by Certo and the customer | Configuration shared by Certo and the customer | Shared configuration; integration subject to scope |
| Network and cloud policies | Managed by Certo | Defined with the customer and managed by Certo | Customer-controlled; operations coordinated with Certo |
| Cloud billing | Included in the plan | Defined in the enterprise proposal | Paid directly by the customer |
Regulated requirements: frameworks such as HIPAA or PCI DSS require a specific assessment of data, services, configuration, contracts, and customer controls. They are not included automatically by using Google Cloud.
We can document architecture, responsibilities, data residency, integrations, and available evidence for your organization’s assessment process.
Request a security review