Certifications and Standards
ISO/IEC 27001:2022
Continuously certified since 2020. iDenfy holds an ISO/IEC 27001:2022 certificate (No. 1512120135) issued by TÜV Thüringen under DAkkS accreditation. This certificate covers the development and provision of identity and business verification, fraud prevention and Anti-Money Laundering software. Our most recent surveillance audit found zero non-conformities.SOC 2 Type II
Independently audited for security, availability and confidentiality. iDenfy’s SOC 2 Type II report covers a full 12-month examination period, certified by House of CPA. The report confirms that our controls are properly designed and operate effectively over time. It provides customers and their auditors with documented assurance on how we handle and store data in production.eIDAS Conformity
Certified for remote identity proofing under EU regulation. iDenfy holds an eIDAS Declaration of Conformity (No. eIDAS250020) issued by the Electrotechnical Testing Institute (EZU) in Prague, covering remote ID proofing using video identification assessed against Regulation (EU) No. 910/2014, ETSI TS 119 461, and ISO/IEC 30107-3:2023. This makes iDenfy one of the few identity verification providers certified to the highest European standards for electronic identification and trust services.GDPR
Fully compliant with the EU General Data Protection Regulation (2016/679). Designated Data Protection Officer, documented Data Processing Agreement (DPA), and all personal data stored within the EU.How iDenfy Handles Compliance
Data Processing
Audit Trail
Every verification produces a complete audit trail including:- Timestamp of each verification step
- Document images and extracted data (OCR, MRZ)
- Liveness check results with anti-spoofing analysis
- Face matching results (document photo vs. selfie)
- AML screening results (PEP, sanctions, adverse media)
- Manual review decisions by in-house KYC experts (if applicable)
- Downloadable PDF verification reports for your compliance records
Security Measures
Incident Response
- Dedicated Incident Response Team (CEO, Security Officer, CTO)
- Response SLAs from immediate (catastrophic) to 2-3 business days (insignificant)
- Client breach notification within 8-24 hours of occurrence
- Data Protection Authority notification within 72 hours
- Root cause analysis and post-incident review after every incident
- Incident Response Plan tested annually
- Zero security incidents in the past 12 months
Secure Development
- Agile/Scrum methodology with security integrated into every sprint
- All code reviewed via pull requests by engineers trained in secure coding
- Reviewed against OWASP Top 10 and SANS attack patterns
- Vulnerability scanning before every production deployment
- Separate development, staging, and production environments
- Production data never used in test/dev environments
- Annual secure coding training (OWASP principles) for all engineers
Data Protection Roles
iDenfy acts as a Data Processor when performing identity verification on behalf of clients. Your organization remains the Data Controller and determines the purposes and legal bases for processing. iDenfy acts as a Data Controller only for its own website, marketing, and recruitment activities. A standard Data Processing Agreement (DPA) is available for all customers.Mapping Features to Requirements
Regulatory Framework Guides
GDPR
Data protection for processing EU customer data. Covers data minimization, retention, right to erasure, and cross-border transfers.
AML Directives (AMLD5/6)
Anti-Money Laundering customer due diligence requirements for financial institutions.
eIDAS
EU electronic identification and trust services regulation.
Industry Guides
Sector-specific requirements: fintech (MiCA, PSD2), crypto (Travel Rule), gambling.