Verazify Legal & Trust

Security at Verazify

Verifying identity means handling some of the most sensitive data there is. Here is how we protect it — described honestly, including what we have and what is still on our roadmap.

Effective date: August 11, 2026

Trust is the product. Verazify processes identity documents, biometric data, and screening results on behalf of businesses across Latin America and the Caribbean, and we treat the security of that data as foundational. This page summarizes our controls and our compliance posture. We describe certifications truthfully: where a framework is in progress or planned, we say so — we never claim a certification we do not hold.

Encryption everywhere

TLS in transit and AES-256 at rest for all sensitive data, including documents and biometrics.

Trusted infrastructure

Built on AWS, Supabase, and Vercel, with hardened, regularly patched systems.

Least-privilege access

Role-based access, MFA for administrators, and full audit logging of production access.

Network protection

Segmentation, firewalls, and rate limiting to defend the API against abuse.

Biometric safeguards

Purpose-limited, encrypted biometric processing with short, configurable retention.

Monitoring & response

Centralized logging, alerting, and a documented incident-response process.

01Encryption in transit & at rest

All data exchanged with the Service travels over encrypted connections using TLS. Data at rest — including identity document images, biometric data, extracted fields, and screening results — is encrypted using AES-256. Encryption keys are managed through our cloud providers’ key-management services with restricted access and rotation practices.

02Infrastructure

Verazify runs on established cloud infrastructure rather than self-managed hardware, so we inherit strong physical and environmental security from our providers and focus our effort on the application and data layers.

  • Amazon Web Services (AWS) — compute, storage, and identity/biometric processing components.
  • Supabase — managed PostgreSQL database and authentication.
  • Vercel — application hosting and global content delivery.

A full list of the providers that process data on our behalf is published on our Sub-processors page.

03Access controls

Access to production systems and customer data is granted on a least-privilege, need-to-know basis. We enforce unique accounts, require multi-factor authentication for administrative access, and log access to production environments. Internal access is reviewed periodically and revoked promptly when no longer required.

04Network & rate limiting

Our services are protected by network segmentation and firewalls, and the API enforces rate limiting and abuse protection to guard against automated attacks, credential stuffing, and denial-of-service attempts. Suspicious traffic patterns are monitored and throttled, and authentication and security controls cannot be bypassed by exceeding published limits.

05Biometric data protection

Biometric data is among the most sensitive data we handle, and we apply heightened safeguards:

  • it is encrypted in transit and at rest and subject to strict access controls;
  • it is used only to perform the face-match and liveness checks a customer requests — never to build facial-recognition databases or for unrelated purposes;
  • it is retained only for short, configurable windows and then deleted or de-identified; and
  • customers, as controllers, are responsible for obtaining the explicit consent required before biometric data is submitted, as described in our Privacy Policy.

06Monitoring & logging

We maintain centralized logging, monitoring, and alerting across our infrastructure to detect anomalous or unauthorized activity, and we operate a documented incident-response process so that potential issues are triaged and addressed promptly. Encrypted backups and redundancy across availability zones support recovery and continuity.

07Vulnerability handling & responsible disclosure

We welcome reports from security researchers and treat responsible disclosure as a partnership. If you believe you have found a vulnerability in Verazify, please report it to us and give us a reasonable opportunity to investigate and remediate before any public disclosure.

Report a vulnerability

Email security@verazify.com with details and steps to reproduce. Please do not access or modify data that is not yours, and avoid privacy violations, service degradation, or data destruction while testing. We aim to acknowledge reports promptly and will keep you updated on our progress.

08Compliance roadmap

We are transparent about where we are on our compliance journey. The following reflects our current status. Items marked “in progress” or “planned” are on our roadmap and are not yet held.

In progress

SOC 2 Type II

We are actively working toward a SOC 2 Type II examination. Not yet held.

Planned

ISO/IEC 27001

On our roadmap for a future certification cycle. Not yet held.

Aligned

GDPR & CCPA

Our practices are designed to align with GDPR and CCPA requirements.

To be explicit: Verazify does not currently hold SOC 2 or ISO/IEC 27001 certification. We will update this page as our status changes, and we are happy to share our current security documentation with customers under NDA.

09Contact

For security questions, disclosures, or to request our current security documentation, contact our security team.

Security contact

For vulnerability reports and security questions. For privacy matters, see our Privacy Policy.
Legal entity:
Devlpfy LLC (d/b/a Verazify)
Registered address:
1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean
    Security — Verazify · Verazify