Veridexa is currently free for everyone โ€” Fraud Detection, Biometrics, and Developer APIs.

Trust Center

This page is maintained by Veridexa to answer common security and privacy questions about the Veridexa document verification platform.

New
Biometric Portrait Consistency

Veridexa now evaluates the consistency between multiple portrait images contained within the same document as part of the fraud detection process.

Learn more

Compliance Readiness

Veridexa maintains internal programs mapped to widely-recognised frameworks. Veridexa is not ISO/IEC 27001 certified and has not completed an independent SOC 2 examination. The wording below reflects our actual status.

GDPR Privacy Program

Data subject request workflow, documented retention, secure deletion, DPA and subprocessor disclosures. See Privacy, DPA, Subprocessors.

SOC 2 Readiness

Controls program aligned to Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. No independent SOC 2 examination has been performed.

ISO 27001 ISMS Readiness

Information security management system with documented risk register, policy set, and evidence index. No independent ISO/IEC 27001 certification has been issued.

Live Reliability Metrics

Aggregated operational metrics served directly from the public metrics API. No organization names, report IDs, or document data are ever exposed.

Data Protection

All data is encrypted in transit with TLS and at rest using industry-standard algorithms. Access to production data is restricted to authorized personnel and audited.

Application Security

Secure development practices, dependency scanning, and code review are part of every release. Sensitive operations are protected by strict role-based access controls.

Infrastructure

Veridexa runs on hardened cloud infrastructure with isolated environments, DDoS protection, and continuous monitoring across regions.

Privacy & Compliance

We align our practices with GDPR and comparable data protection laws. A DPA and subprocessor list are available for customers with regulatory obligations.

Access & Identity

Authentication is protected by strong password policies and support for federated sign-in. Session tokens are rotated and revocable.

Incident Response

We maintain documented procedures for detecting, responding to, and communicating security incidents. Affected customers are notified without undue delay.

Shared Responsibility

Security is a shared responsibility. Veridexa is responsible for the security of the platform โ€” infrastructure, application, and operational controls. Customers are responsible for how they use the Services, including account credentials, user access, and the data they choose to submit.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in the Veridexa platform, please report it responsibly to security@veridexa.io. Please include steps to reproduce and avoid accessing data that is not yours.

New capability

Read more about Biometric Portrait Consistency and how it strengthens document fraud detection on supported biometric passports and identity documents.

Contact

For security or privacy questions, contact security@veridexa.io.