Jinsi tunavyolinda data yako na utambulisho wa wateja wako.
Report a VulnerabilityWe distinguish between implemented controls, frameworks we are aligned with, and certifications we are working toward.
Implemented today
Readiness in progress
Actual certifications
No third-party certifications are currently in force. When certificates are issued, copies and reports will be linked here. Reach out to security@trustverifyid.com for our latest evidence pack.
All production data stored on servers located within the European Union. We do not transfer personal data to third countries except under SCCs (e.g., Stripe, SendGrid).
Every identity document and biometric file is encrypted at rest using AES-256-GCM with a unique per-applicant encryption key. Master keys are stored in environment variables, never in the database.
All API and dashboard traffic is protected by TLS 1.3. HTTP Strict Transport Security (HSTS) enforced with a 1-year max-age. All HTTP requests redirect to HTTPS.
API rate limiting via Redis (100 req/min per key by default, configurable). DDoS mitigation at network edge.
Strict MIME-type and magic-byte validation on every uploaded file, with size limits enforced before processing. Malware scanning is applied where the scanning engine is enabled.
Strict CSP headers on all dashboard pages. X-Content-Type-Options, X-Frame-Options, and Referrer-Policy headers set on all responses.
Every API request must carry X-API-Key, X-Signature (HMAC-SHA256), and X-Timestamp. Requests older than 5 minutes are rejected.
TOTP two-factor authentication required for all admin accounts. Backup codes stored as bcrypt hashes.
Three admin roles: reviewer, admin, super_admin. API keys scoped to environments (live / sandbox).
Every data access and modification is logged with actor ID, IP, user-agent, and timestamp. Logs cannot be deleted.
Every API request is signed to prevent replay attacks and request tampering.
If you discover a security vulnerability in TrustVerifyID, please email us at security@trustverifyid.com. We will acknowledge within 24 hours and aim to resolve critical issues within 72 hours. We ask that you do not publicly disclose the issue until we have had a reasonable time to respond.
Our security team is happy to answer questions, provide our DPA, or arrange a technical briefing for enterprise clients.