1CERT.ORGGlobal Trust Registry

Institution

Data and security

Registry, personal and risk data are subject to institutional requirements for lawful processing, minimisation, security, auditability and controlled access.

Registry data

A registry record is published only under the applicable inclusion, evidence and source-citation requirements. Publication is governed by the Standard for Registry Record Publication.

Due diligence data

Information gathered in the course of a due diligence engagement is confidential to the commissioning party and is not published in the registry or shared with third parties, except where the commissioning party directs otherwise or where required by law.

Submission channels

Sensitive case material is not accepted through unsecured public forms on this website. Enquiry forms on this site collect only basic contact and scoping information; a secure channel is provided for supporting documentation once an engagement is under way.

Retention

Registry records and their audit history are retained in accordance with the registry record publication standard. Due diligence records are retained only for a defined legal, operational or review purpose and remain subject to controlled access throughout that period.

Reporting a vulnerability

Security researchers and members of the public may report a suspected vulnerability in this website or its systems through the report a vulnerability page.