Active frameworks
CertiFlow PLUS runs its own compliance programme on this platform. Framework readiness below is illustrative of the shape a live Trust Center takes for customers; a customer’s own Trust Center draws from their tenant’s controls, evidence and audit-chain in real time.
Security posture — what an attacker can take
| Scenario | What an attacker obtains |
|---|---|
| Lawful court order, customer-specific | Ciphertext + plaintext metadata only |
| Production database breach | Ciphertext only at rest |
| Out-of-band backup vault breach | Ciphertext only at rest |
| Compromised CertiFlow PLUS insider with root | Metadata only; cannot decrypt evidence |
Full threat model and ZKE architecture detail: Security page.
Operational posture
Documents
- Data Processing Agreement (DPA) — includes Annex III ZKE clauses
- Sub-processor disclosure list — under ZKE, materially shorter than incumbents
- Privacy notice
- Security page — ZKE + 8-layer defence
Need deeper access for an audit?
External auditors can be invited to a read-only Auditor View scoped to the controls in their engagement — every page-view, every comment, every export is recorded in the tamper-evident audit chain. Email shaun@directcs.net with your organisation name and your auditor’s firm name.