Sertiva ← Ana sayfa

English summary

Sertiva — self-hosted PCI DSS 4.0.1 compliance platform

Sertiva is a compliance and vulnerability management platform built for one standard only: PCI DSS 4.0.1. It runs on your own servers, in Turkish, and is designed so that audit evidence accumulates throughout the year instead of being assembled in the weeks before an assessment.

This is a summary page

The product and its full site are in Turkish, aimed at banks, payment institutions and PSPs operating in Türkiye. Go to the Turkish site →

Why it exists

Most PCI DSS compliance platforms are cloud services: your control data, evidence files and audit trail live on infrastructure outside your organisation — and usually outside your country. For institutions that cannot move cardholder-data-adjacent records abroad, that rules the category out entirely. What remains is spreadsheets plus a consultant.

Sertiva takes the opposite position: the software comes to your infrastructure. Air-gapped installations are supported; nothing leaves the perimeter.

What it does

AreaCapability
ControlsAll 12 requirement groups modelled down to sub-requirement level, with owners, status and evidence links.
EvidenceEvery file fingerprinted with SHA-256; approvals and rejections written into an HMAC-SHA256 hash chain, so retroactive edits are detectable.
MonitoringContinuous control testing, payment page header and script inventory checks (Req 6.4.3 / 11.6.1), availability history.
RiskTargeted risk analysis (Req 12.3.1), 5×5 matrix, residual risk scoring, formal risk acceptance.
FindingsSix vulnerability scanner integrations normalised into one register, CVSS-weighted, with SLA ageing.
IntegrationsNessus, Tenable.io, Qualys, OpenVAS, Rapid7, AWS Inspector; Splunk, QRadar, Elastic, Wazuh; Active Directory, CyberArk, GitLab CI.
Audit outputEight-section report, evidence package, read-only assessor portal, chain verification.

Deployment and licensing

Where the product stands

Sertiva is new. There is no customer list to show yet and it has not been through a completed QSA assessment. It is currently looking for its first pilot organisations, who get installation and first-period support at no charge, direct access to the developer, and influence over the roadmap. We would rather say this plainly than imply a track record that does not exist.

Interested in a pilot?

Tell us your scope and audit timeline; we will be straight about whether Sertiva fits.

Explore Sertiva →