Skip to content
VerifiX — secured by ITSEC

Legal

Acceptable Use Policy

The Platform handles identity documents, biometric data, and financial-crime records. This policy sets the limits on how it may be used, and applies to every customer, console user, and integration.

Effective
1 August 2026
Provider
ITSEC

These terms describe how the platform is supplied. Enterprise agreements, order forms, and any negotiated amendments take precedence over this page where they conflict.

1.Permitted use

The Platform may be used to meet the customer's own regulatory and risk obligations: onboarding and periodic review of individuals and businesses, sanctions and PEP screening, adverse-media checks, transaction and wallet monitoring, Travel Rule data exchange, and the investigation and record-keeping that follows.

2.Prohibited use

  • Submitting personal data without a lawful basis, or without giving the end user any notice or consent required.
  • Verifying or screening a person for a purpose unrelated to the customer's own compliance or risk obligations, including background checks on employees or third parties outside that scope.
  • Using verification, biometric, or screening data for profiling, marketing, or targeting, or reselling it.
  • Uploading documents or biometric data belonging to a person the customer has no relationship with, or submitting forged, stolen, or synthetic identity data other than the test data supplied for sandbox use.
  • Making decisions that discriminate on grounds prohibited by applicable law, or using risk scores as a proxy for such grounds.
  • Circumventing rate limits, probing or load-testing production without written agreement, reverse engineering the Platform, or attempting to access another customer's data.
  • Sharing console credentials or API keys, including with affiliates not named in the order form.
  • Using the Platform to facilitate activity that is itself unlawful, including sanctions evasion.

3.Sandbox and test data

Sandbox environments are for integration work and must be used with test data only. Do not submit real identity documents, real biometric data, or production transaction records to a sandbox environment.

4.Human review and automated decisions

Risk scores and rule outcomes are decision support. Where the customer's obligations or applicable law require human involvement in a decision that materially affects a person, the customer must route those cases to a reviewer and record the reasoning in the case file.

5.Security responsibilities

  • Rotate API keys and webhook secrets on a schedule and immediately on suspected compromise.
  • Keep console roles current and remove access promptly when a user changes role or leaves.
  • Report suspected security incidents affecting the integration or account without undue delay.

6.Enforcement

ITSEC may investigate suspected breaches of this policy and may throttle, suspend, or terminate access where use threatens the security or integrity of the Platform, breaches this policy, or exposes end users to harm. Where practical, ITSEC will notify the customer first and work through a remediation plan.

Report misuse or a suspected security issue to sales@verifix.ae.