CertEdge / Security & data
Security, with the scope made clear.
What the public demo does today, where to report a concern and what must be agreed before a real-data pilot.
The public demo today
CertEdge currently demonstrates a workflow using fictional data and scripted AEGIS reports. It does not provide production accounts, enforce tenant isolation, accept evidence uploads or call an AI model. Switching demo roles illustrates the experience; it is not an access-control boundary.
Demo actions remain in browser memory and reset on reload. The website is delivered over HTTPS by Vercel, with self-hosted fonts and scripts. No site analytics or advertising tracker is installed. Technical hosting records and email correspondence are described in the Privacy Notice.
Report a security concern
Email security@secureedgeadvisory.com and include the affected URL, a description, safe reproduction steps and the potential impact. Do not include credentials, customer evidence or another person’s data.
Follow SecureEdge Advisory’s responsible disclosure policy. This page does not authorise disruptive testing or access to records that do not belong to you.
Before real evidence is accepted
A private pilot needs agreed access roles, auditor invitation boundaries, evidence storage and versioning, retention and deletion, incident handling, provider arrangements and appropriate data-processing terms.
Any AI use must identify the provider, data sent for processing and its applicable retention and training terms. Hosting location and international transfers must be assessed for that pilot. These are prerequisites for the production phase, not features supplied by the current demo.
The corporate Data Processing and Assessment Terms and provider register provide background. Specific scope must be agreed before real data is shared.
Claims you can assess
The public demo is not presented as ISO-certified or SOC 2-attested. Provider certifications do not certify CertEdge. Sample evidence scores, control mappings and interface permissions are not proof that production security controls have been implemented.
For procurement, data-residency or security questions, contact the team so the intended service and requirements can be discussed.