Trust is the product. Verazify processes identity documents, biometric data, and screening results on behalf of businesses across Latin America and the Caribbean, and we treat the security of that data as foundational. This page summarizes our controls and our compliance posture. We describe certifications truthfully: where a framework is in progress or planned, we say so — we never claim a certification we do not hold.
Encryption everywhere
TLS in transit and AES-256 at rest for all sensitive data, including documents and biometrics.
Trusted infrastructure
Built on AWS, Supabase, and Vercel, with hardened, regularly patched systems.
Least-privilege access
Role-based access, MFA for administrators, and full audit logging of production access.
Network protection
Segmentation, firewalls, and rate limiting to defend the API against abuse.
Biometric safeguards
Purpose-limited, encrypted biometric processing with short, configurable retention.
Monitoring & response
Centralized logging, alerting, and a documented incident-response process.
01Encryption in transit & at rest
All data exchanged with the Service travels over encrypted connections using TLS. Data at rest — including identity document images, biometric data, extracted fields, and screening results — is encrypted using AES-256. Encryption keys are managed through our cloud providers’ key-management services with restricted access and rotation practices.
02Infrastructure
Verazify runs on established cloud infrastructure rather than self-managed hardware, so we inherit strong physical and environmental security from our providers and focus our effort on the application and data layers.
- Amazon Web Services (AWS) — compute, storage, and identity/biometric processing components.
- Supabase — managed PostgreSQL database and authentication.
- Vercel — application hosting and global content delivery.
A full list of the providers that process data on our behalf is published on our Sub-processors page.
03Access controls
Access to production systems and customer data is granted on a least-privilege, need-to-know basis. We enforce unique accounts, require multi-factor authentication for administrative access, and log access to production environments. Internal access is reviewed periodically and revoked promptly when no longer required.
04Network & rate limiting
Our services are protected by network segmentation and firewalls, and the API enforces rate limiting and abuse protection to guard against automated attacks, credential stuffing, and denial-of-service attempts. Suspicious traffic patterns are monitored and throttled, and authentication and security controls cannot be bypassed by exceeding published limits.
05Biometric data protection
Biometric data is among the most sensitive data we handle, and we apply heightened safeguards:
- it is encrypted in transit and at rest and subject to strict access controls;
- it is used only to perform the face-match and liveness checks a customer requests — never to build facial-recognition databases or for unrelated purposes;
- it is retained only for short, configurable windows and then deleted or de-identified; and
- customers, as controllers, are responsible for obtaining the explicit consent required before biometric data is submitted, as described in our Privacy Policy.
06Monitoring & logging
We maintain centralized logging, monitoring, and alerting across our infrastructure to detect anomalous or unauthorized activity, and we operate a documented incident-response process so that potential issues are triaged and addressed promptly. Encrypted backups and redundancy across availability zones support recovery and continuity.
07Vulnerability handling & responsible disclosure
We welcome reports from security researchers and treat responsible disclosure as a partnership. If you believe you have found a vulnerability in Verazify, please report it to us and give us a reasonable opportunity to investigate and remediate before any public disclosure.
Report a vulnerability
Email security@verazify.com with details and steps to reproduce. Please do not access or modify data that is not yours, and avoid privacy violations, service degradation, or data destruction while testing. We aim to acknowledge reports promptly and will keep you updated on our progress.
08Compliance roadmap
We are transparent about where we are on our compliance journey. The following reflects our current status. Items marked “in progress” or “planned” are on our roadmap and are not yet held.
SOC 2 Type II
We are actively working toward a SOC 2 Type II examination. Not yet held.
ISO/IEC 27001
On our roadmap for a future certification cycle. Not yet held.
GDPR & CCPA
Our practices are designed to align with GDPR and CCPA requirements.
To be explicit: Verazify does not currently hold SOC 2 or ISO/IEC 27001 certification. We will update this page as our status changes, and we are happy to share our current security documentation with customers under NDA.
09Contact
For security questions, disclosures, or to request our current security documentation, contact our security team.
Security contact
- Email:
- security@verazify.com
- Legal entity:
- Devlpfy LLC (d/b/a Verazify)
- Registered address:
- 1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean