LEGAL COMPLIANCE
Last Updated: July 14, 2026
CertVault collects email addresses, secure credential records, and uploaded document attachments (PDFs and images) solely to perform the credential storage, verification, and API showcase services.
When you activate the Public Feed toggle on your integration dashboard, any certificates flagged as "public" become queryable by anonymous network clients. Your private API credentials and hashed keys are strictly guarded and never exposed.
Uploaded certificate files are saved to secure directory blocks on Vercel storage or local volumes. Access tokens protect authenticated document links.
We deploy secure cookies to persist user sessions via NextAuth. Rate limiting middleware active on API nodes resolves request rates by tracking incoming client IPs anonymously.