Trust Center
This page is maintained by Veridexa to answer common security and privacy questions about the Veridexa document verification platform.
Veridexa now evaluates the consistency between multiple portrait images contained within the same document as part of the fraud detection process.
Compliance Readiness
Veridexa maintains internal programs mapped to widely-recognised frameworks. Veridexa is not ISO/IEC 27001 certified and has not completed an independent SOC 2 examination. The wording below reflects our actual status.
Data subject request workflow, documented retention, secure deletion, DPA and subprocessor disclosures. See Privacy, DPA, Subprocessors.
Controls program aligned to Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. No independent SOC 2 examination has been performed.
Information security management system with documented risk register, policy set, and evidence index. No independent ISO/IEC 27001 certification has been issued.
Live Reliability Metrics
Aggregated operational metrics served directly from the public metrics API. No organization names, report IDs, or document data are ever exposed.
Data Protection
All data is encrypted in transit with TLS and at rest using industry-standard algorithms. Access to production data is restricted to authorized personnel and audited.
Application Security
Secure development practices, dependency scanning, and code review are part of every release. Sensitive operations are protected by strict role-based access controls.
Infrastructure
Veridexa runs on hardened cloud infrastructure with isolated environments, DDoS protection, and continuous monitoring across regions.
Privacy & Compliance
We align our practices with GDPR and comparable data protection laws. A DPA and subprocessor list are available for customers with regulatory obligations.
Access & Identity
Authentication is protected by strong password policies and support for federated sign-in. Session tokens are rotated and revocable.
Incident Response
We maintain documented procedures for detecting, responding to, and communicating security incidents. Affected customers are notified without undue delay.
Shared Responsibility
Security is a shared responsibility. Veridexa is responsible for the security of the platform โ infrastructure, application, and operational controls. Customers are responsible for how they use the Services, including account credentials, user access, and the data they choose to submit.
Documentation
Reporting a Vulnerability
If you believe you have discovered a security vulnerability in the Veridexa platform, please report it responsibly to security@veridexa.io. Please include steps to reproduce and avoid accessing data that is not yours.
New capability
Read more about Biometric Portrait Consistency and how it strengthens document fraud detection on supported biometric passports and identity documents.
Contact
For security or privacy questions, contact security@veridexa.io.