SECURITY · EVIDENCE · RESPONSIBILITY

Security with clear responsibilities.

Certo combines application controls with Google Cloud infrastructure. We document what Certo protects, what depends on the deployment model, and what remains with the customer.

See controls

Controls built into the platform.

Security is layered and validated according to the contracted scope and each customer’s configuration.

Organization isolation

Data and operations are scoped by organization to separate access across tenants.

Role-based access

Roles, permissions, and product entitlements limit the capabilities available to each user.

Data protection

Encrypted transport and cloud-managed encryption protect data in transit and at rest.

Secrets management

Operational credentials remain outside source code and are managed as protected configuration.

Traceability

Available administrative events and audit records support investigation of relevant activity and changes.

Backup and delivery

Data backups and automated CI/CD checks reduce risk during operations and deployments.

GOOGLE CLOUD INFRASTRUCTURE

The cloud foundation is audited too.

Google Cloud maintains third-party certifications and reports for services within its scope. Certo uses those services as part of its architecture; applicable coverage depends on the service and contracted configuration.

Important distinction: ISO and SOC 2 apply to Google Cloud. They do not mean Certo currently holds its own ISO certification or SOC 2 report.

  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • SOC 2 Type II

Shared responsibility by deployment model.

Product controls remain consistent; infrastructure ownership and operating tasks change.

ResponsibilityCerto CloudCerto IsolatedCerto BYOC
Cloud projectOwned by CertoOwned by CertoOwned by the customer
IsolationShared platform with organization-level separationInfrastructure dedicated to the customerCustomer project with agreed boundaries
Certo operationsManaged by CertoManaged by CertoManaged by Certo under agreement
Identity and usersConfiguration shared by Certo and the customerConfiguration shared by Certo and the customerShared configuration; integration subject to scope
Network and cloud policiesManaged by CertoDefined with the customer and managed by CertoCustomer-controlled; operations coordinated with Certo
Cloud billingIncluded in the planDefined in the enterprise proposalPaid directly by the customer

Regulated requirements: frameworks such as HIPAA or PCI DSS require a specific assessment of data, services, configuration, contracts, and customer controls. They are not included automatically by using Google Cloud.

Review your security scope before contract.

We can document architecture, responsibilities, data residency, integrations, and available evidence for your organization’s assessment process.

Request a security review