Skip to content
CertKeeper

Security

Where your data lives, and how it is kept.

Everything on this page describes the service as it runs today. Last reviewed September 2026.

Where it is stored

CertKeeper runs on Amazon Web Services in the United States (the N. Virginia region). Records are held in Amazon DynamoDB and uploaded documents in Amazon S3. Nothing is stored outside AWS.

Encryption

All traffic between your browser and CertKeeper, including document uploads and downloads, is encrypted with TLS. The database and the document store are encrypted at rest with AWS server-side encryption.

Isolation between organizations

Every record is stored under your organization's identifier, and that identifier is taken from your signed-in identity, not from anything the browser sends. A request from one organization cannot address another organization's records.

Documents

The document store blocks all public access. A card or certificate you upload is written and read only through short-lived signed links, valid for 15 minutes, issued to a signed-in member of your organization. There is no public URL for a document.

Sign-in and passwords

Accounts are managed by Amazon Cognito. CertKeeper never sees or stores your password; resets go through your email address.

Payments

Subscriptions are billed by Stripe. Card numbers are entered on Stripe's pages and never pass through CertKeeper.

Backups

The database has point-in-time recovery enabled, which keeps continuous backups and allows a restore to any second in the preceding 35 days.

Export and deletion

You can export everything your organization has entered at any time, from Settings, as a ZIP of CSV files: employees, certification types, records with their renewal history, locations, users, requirements, and the notification log. To delete your organization's data, email us from the account owner's address and we will confirm when it is done.

Email

Reminders and account email are sent through Amazon Simple Email Service, only to addresses your organization entered. Employees receive email only if you turn that setting on.

Who can see your data

Sweet Cat Software staff access customer records only to run the service, to investigate a problem you report, or at your request. We do not sell data and do not use it for advertising. No advertising or analytics code runs inside the application; the marketing site at certkeeper.co carries a Google tag, the app does not.

Security questionnaires

If your procurement process needs a security questionnaire, a SOC 2 report, or answers about specific controls, email us and we will answer plainly.

Reporting a problem

If you find a security issue, email hello@certkeeper.co. You will get a reply from a person, and a fix before any public discussion.