# 1. Cryptography & Encryption Standards
All customer data is encrypted in transit using TLS 1.3 with PFS and at rest using AES-256 encryption. Cryptographic credential signatures use ECDSA secp256k1 keys managed in Azure Key Vault HSMs.
# 2. Microsoft Azure Cloud Hosting
Certifada infrastructure operates exclusively in Microsoft Azure Tier-4 datacenters in Abu Dhabi & Dubai (UAE Central & UAE North regions), featuring 24/7 physical security, biometric access, and redundant power feed generators.
# 3. Automated Backups & Disaster Recovery
Database backups execute automatically every hour with point-in-time recovery. Our Recovery Point Objective (RPO) is less than 15 minutes, and Recovery Time Objective (RTO) is under 1 hour.
# 4. Access Control, SSO & MFA
Platform administration requires Multi-Factor Authentication (MFA). Enterprise accounts support SAML 2.0 / Azure AD Single Sign-On (SSO) with Granular Role-Based Access Control (RBAC).
# 5. Tenant Data Isolation Architecture
Certifada utilizes schema-level multi-tenant database isolation. Each tenant workspace operates inside a dedicated cryptographic boundary, preventing unauthorized cross-tenant data access.
# 6. Vulnerability Disclosure & Patching
Security patches are applied automatically. We conduct quarterly vulnerability assessments and invite ethical researchers to submit reports under our Responsible Disclosure Policy.