Security

C3RTA protects your inspection and maintenance records using industry-standard security controls. We do not claim security certifications we have not formally obtained.

Effective date: August 20, 2026

Security measures

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using industry-standard TLS.

Account Isolation

Each organisation's data is logically isolated. Users cannot access data belonging to other accounts.

Cloud Infrastructure

C3RTA runs on recognised cloud infrastructure providers with established physical and network security controls.

Access Controls

Role-based access controls limit what each user can view or modify within your account.

Payments and Card Data

Payments are processed through Stripe. C3RTA does not control Stripe's security measures, availability, or data practices; please also review Stripe's terms and documentation.

Public Certificate Verification

The Service allows inspection certificates to be verified via QR code or public link without requiring a login. Data shown on public verification is limited to asset information and inspection outcome. Account administrators can enable or disable this feature for each asset.

Account Access

Role-based access controls limit what each user can view or modify within your account. Configure user permissions according to your organisation's responsibilities.

Vulnerabilities and Incident Reporting

If you discover a potential security vulnerability in the Service, we ask that you report it to us responsibly at: support@c3rta.com

Limitations

No security system can guarantee absolute protection. C3RTA applies reasonable industry-standard controls, but cannot guarantee that the Service is entirely free of vulnerabilities or that data will never be accessed without authorisation.

Security Contact

To report vulnerabilities or for security questions: support@c3rta.com

Security Information Review

C3RTA's Product & Compliance Owner coordinates a review of this page, the Terms of Use, and the Privacy Policy at least quarterly and before material changes are published. A qualified legal counsel reviews the change for each affected jurisdiction (the United States, Canada, or Mexico).

Legal review is required when security controls, authentication, access control, storage, incident reporting, public verification, payments, supported markets, or legal requirements materially change. Approved material updates are published with a new effective date and equivalent English and Mexican-Spanish wording.