English summary
Sertiva — self-hosted PCI DSS 4.0.1 compliance platform
Sertiva is a compliance and vulnerability management platform built for one standard only: PCI DSS 4.0.1. It runs on your own servers, in Turkish, and is designed so that audit evidence accumulates throughout the year instead of being assembled in the weeks before an assessment.
This is a summary page
The product and its full site are in Turkish, aimed at banks, payment institutions and PSPs operating in Türkiye. Go to the Turkish site →
Why it exists
Most PCI DSS compliance platforms are cloud services: your control data, evidence files and audit trail live on infrastructure outside your organisation — and usually outside your country. For institutions that cannot move cardholder-data-adjacent records abroad, that rules the category out entirely. What remains is spreadsheets plus a consultant.
Sertiva takes the opposite position: the software comes to your infrastructure. Air-gapped installations are supported; nothing leaves the perimeter.
What it does
| Area | Capability |
|---|---|
| Controls | All 12 requirement groups modelled down to sub-requirement level, with owners, status and evidence links. |
| Evidence | Every file fingerprinted with SHA-256; approvals and rejections written into an HMAC-SHA256 hash chain, so retroactive edits are detectable. |
| Monitoring | Continuous control testing, payment page header and script inventory checks (Req 6.4.3 / 11.6.1), availability history. |
| Risk | Targeted risk analysis (Req 12.3.1), 5×5 matrix, residual risk scoring, formal risk acceptance. |
| Findings | Six vulnerability scanner integrations normalised into one register, CVSS-weighted, with SLA ageing. |
| Integrations | Nessus, Tenable.io, Qualys, OpenVAS, Rapid7, AWS Inspector; Splunk, QRadar, Elastic, Wazuh; Active Directory, CyberArk, GitLab CI. |
| Audit output | Eight-section report, evidence package, read-only assessor portal, chain verification. |
Deployment and licensing
- Self-hosted. A single server is enough for a typical scope: 4 vCPU, 8 GB RAM, 100 GB disk. Docker image or direct install, behind an nginx reverse proxy, PostgreSQL.
- Per-organisation licence. Not per seat — adding people to the team does not change the cost. Installation, updates and security patches are included.
- Security architecture. TOTP MFA with replay protection, five-role RBAC enforced at API level, Fernet encryption at rest for secrets, hash-chained audit log.
Where the product stands
Sertiva is new. There is no customer list to show yet and it has not been through a completed QSA assessment. It is currently looking for its first pilot organisations, who get installation and first-period support at no charge, direct access to the developer, and influence over the roadmap. We would rather say this plainly than imply a track record that does not exist.
Interested in a pilot?
Tell us your scope and audit timeline; we will be straight about whether Sertiva fits.
Explore Sertiva →