Security and compliance

Customer data protected at every step

We design the platform so that a breach of one component does not expose the rest: data is encrypted with separate keys, files are processed in isolation, and every employee action is recorded in the audit log.

Controls

  • Hosting in Germany

    Processing, storage and backups run in the platform region in Germany; a key of another region is never applied to the data.

  • Encryption

    AES-256-GCM with a separate data key per applicant, case, report and webhook; key encryption keys are held in the regional KMS.

  • Isolated file processing

    Documents, video and chip data are parsed in a separate executor with kernel restrictions; the main process does not parse files.

  • Malware scanning

    Every upload is scanned before it is admitted to processing; when scanning is unavailable, the upload is not accepted.

  • Audit log

    Actions of customer employees, the integration and the platform owner are written to an immutable log.

  • Deletion

    Deleting applicant data destroys its encryption key; the data disappears from backups within 35 days at most.

Employee access

  • Console sign-in with a mandatory second factor (TOTP or a passkey) or through the SSO of your organisation over OIDC or SAML.
  • Fresh sign-in for critical actions: issuing API keys, changing employees, deleting data.
  • Least-privilege roles and separate approval of policy changes by a second employee.
  • Support access to your data only with your permission and for a limited time.

Engineering and releases

  • OWASP ASVS 5.0 level 2 requirements are mapped to code and tests; the compliance matrix is kept in the repository.
  • Static code analysis, a software bill of materials (SBOM) and a dependency vulnerability scan are a build condition for every release.
  • A release is built from a verified commit; if services are not ready after an update, the previous release is restored automatically.
  • Database backups with a log archive every 5 minutes and a weekly restore check into an isolated cluster.

What we claim and what we do not

We describe controls that are implemented and covered by tests. We do not claim biometric certification or an external audit before they are obtained.

You can report a vulnerability through the form on the contact page; the address is also listed in /.well-known/security.txt.

Frequently asked questions

Who is the controller of applicant data?

For the data an applicant provides during a check, the customer is the controller and verkyc processes it on the customer behalf. Details are in the privacy policy and the data processing agreement.

Can we get detailed security materials?

Yes, after your request we will send a description of the controls, the data placement map and answers to your questionnaire.

See it on your own scenarios

Tell us who you need to verify and where. We will prepare a demo, test API access and a price estimate.