VerifyX

Security & Compliance

The smallest attack surface in KYC.

The most secure data is the data you never hold. VerifyX is built so a breach of our systems reveals no personal information - because there is none to reveal.

Zero PII at rest

User media is processed in isolated pod memory and destroyed at decision time. Nothing is written to disk or any database.

GDPR by architecture

Biometric data is never stored, so GDPR Article 9 obligations do not apply. Erasure is a single SQL update.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest for the scores database, AWS Secrets Manager with rotation.

Narrow SOC 2 scope

No image storage means the audit covers only the scores database, API access, and secrets.

Data residency

Score data is small and straightforward to restrict to a single jurisdiction.

No PII in telemetry

Traces, metrics, and logs are engineered so no personal data ever appears in observability output.

Compliance, traditional vs. ephemeral

Area
Traditional KYC
VerifyX
GDPR Article 9 (biometrics)
Consent, DPIA, DPO, safeguards
Not applicable - never stored
Right to erasure
Locate & delete across all tiers
One SQL update anonymises the ref
Breach notification
Image exposure triggers 72-hour notice
Scores reveal no personal data
Data minimisation
Hard to satisfy under retention pressure
Satisfied by architecture