Security and privacy

What the product does to protect the record, and what it deliberately never stores.

This page describes the controls a buyer inherits. It is not a substitute for hardening the server itself, keeping PHP updated, and using HTTPS.

Accounts and sessions

Authorisation

The application surface

External API credentials

What the public can see

A verification page shows the participant name, the course, the certificate number, the issue date, the expiry date if there is one, the issuing organisation, the approving verifier organisation, and the certificate document.

It does not show, and no public route exposes, an email address, a telephone number, the participant's employer or job title, any internal identifier, or any account information. There is no public listing: a visitor can check a certificate they already have an identifier for, and cannot browse or enumerate the register.

What is never stored

The audit trail

Sensitive actions are recorded append-only: who acted, what changed from what to what, when, from which address and with which browser. Certificate status changes, verifier decisions, role changes, branding and email settings changes are all included. Nothing in the interface deletes an audit entry; the only removal path is the archiving job, which exports a completed calendar year to a compressed file first and then deletes exactly the rows it exported.

Reading the log after an upgrade

Each row keeps the action name that was current when it was written, because rewriting stored history would destroy the record. The filter groups an event under the name in use today and counts the older names into it, so one event is one option in the list and selecting it returns the older rows as well. The stored name is printed under every row, so nothing is hidden by the grouping.

Your obligations as the operator

You are the controller of the personal data in your installation. The product gives you the tools; the decisions remain yours.

Reporting a vulnerability. The package includes SECURITY.md at its root with the controls in place and the hardening checklist. If you find a security problem in the product, report it by email rather than in a public forum, and include the version from VERSION.