Are my certificate files really safe?
CertNudge uses technical and organisational controls intended to protect uploaded certificate files.
Files are stored in private Microsoft Azure Blob Storage. Security controls reduce risk, but no online service can promise absolute safety.
Private file storage
Uploaded certificate files are held in private storage rather than being available through an unrestricted public file address.
How is access controlled?
Authorised organisation users
Signed-in users can access records according to the permissions and roles available to their organisation account.
Short-lived authorised downloads
Normal authenticated downloads use short-lived signed access rather than permanent public document links.
Active bearer share links
Anyone holding a valid active share link may be able to access the shared resource until the link expires or is revoked.
Can CertNudge access uploaded files?
CertNudge restricts operational access to authorised, need-to-know purposes required to operate, maintain or support the service.
Protect secure share links
Share links should be sent only to the intended recipient and should not be posted in a public or widely accessible location.
Revoke a link when access is no longer required. Revocation prevents future use but cannot undo a file that has already been downloaded.
How can I help protect my account?
- Use a unique password: Do not reuse a password from another service.
- Enable two-factor authentication: Use the available authenticator-app option.
- Review team access: Remove organisation users who no longer need access.
- Check shared links: Review and revoke active links that are no longer needed.
- Avoid unnecessary personal data: Do not upload tenancy agreements, ID or unnecessary tenant information.
What happens when a file is deleted?
Deletion is handled through CertNudge's supported deletion processes and remains subject to lawful retention requirements described in the Privacy Policy. CertNudge does not promise immediate permanent removal from every historical or retained record.
No system is risk-free
Keep appropriate copies of important evidence and contact CertNudge promptly if you believe an account, file or share link may have been accessed without authorisation.