Security and transparency by design.
MachineCert is built by a security company, for security teams. Here is how we protect your data, run our infrastructure, and earn the trust of the enterprises that rely on us.
How we protect
your data.
Defense-in-depth across application, data, and infrastructure layers.
Certificate metadata only — private keys are never collected or stored.
TLS 1.3 in transit, AES-256 at rest, with managed key rotation.
Hardened, isolated cloud infrastructure with least-privilege access.
A documented, tested process with defined SLAs and notification.
Comprehensive audit logging and continuous security monitoring.
Private keys never
leave your environment.
Everything you need
to evaluate us.
99.9%+ uptime with a public status page.
A current, published list of all subprocessors.
A dedicated channel for vulnerability reports.
Architecture and security docs on request.
SOC 2 Type II, ISO 27001, HIPAA, GDPR.
Regular third-party penetration testing.
Security & trust,
answered.
Related resources
Questions for our security team?
Request our SOC 2 report, security documentation, or a conversation with the team that builds MachineCert.