Skip to content
VerifiX — secured by ITSEC

Legal

Terms of Service

These terms govern access to and use of the VerifiX platform, APIs, console, SDKs, and supporting documentation supplied by ITSEC.

Effective
1 August 2026
Provider
ITSEC

These terms describe how the platform is supplied. Enterprise agreements, order forms, and any negotiated amendments take precedence over this page where they conflict.

1.Scope and definitions

“Platform” means the VerifiX console, APIs, SDKs, hosted verification flows, and any related documentation. “Customer” means the entity that signs an order form or otherwise subscribes to the Platform. “End user” means an individual or business that a Customer verifies, screens, or monitors through the Platform.

“Order form” means the commercial document that records the modules enabled, volumes, environments, and term. Where an order form conflicts with this page, the order form controls.

2.Service description

The Platform provides configurable identity verification (KYC), business verification (KYB), sanctions, PEP and adverse-media screening (AML), transaction monitoring (KYT), Travel Rule messaging, case management, and a decision engine with an audit trail.

The Platform returns verification results, risk scores, and evidence records. It does not make onboarding, offboarding, reporting, or filing decisions on the Customer's behalf, and it is not legal or compliance advice. The Customer remains responsible for its own regulatory obligations, including decisions to accept, reject, escalate, or report a case.

3.Accounts, environments, and access

Sandbox access is provided for integration and testing with test data only. Production access is enabled after commercial terms are agreed.

The Customer is responsible for the security of its API keys and console credentials, for keeping user roles current, and for removing access when a user leaves. Console activity is recorded in the audit trail.

4.Customer obligations

  • Hold and maintain any authorizations required to collect and process the personal data submitted to the Platform.
  • Provide a lawful basis and any required notices or consents to end users before submitting their data.
  • Configure journeys, thresholds, and rules appropriate to its own risk appetite and regulatory obligations.
  • Review escalated cases and alerts through a human reviewer where its obligations require human judgement.
  • Keep API keys, credentials, and webhook secrets confidential and rotate them when compromise is suspected.
  • Not submit data it has no right to submit, and not use results for a purpose the end user was not informed of.

5.Data processing and roles

For personal data submitted through the Platform, the Customer acts as controller and ITSEC acts as processor, processing that data on the Customer's documented instructions. The Data Processing Addendum sets out the processing terms, security measures, sub-processors, and assistance obligations.

ITSEC acts as controller for its own account data, billing records, and platform security logs.

6.Security measures

The Platform is hosted in UAE regions on Amazon Web Services and Microsoft Azure. Data is encrypted in transit and at rest, access is role-based and logged, and administrative access is restricted to named personnel.

ITSEC is certified to ISO/IEC 27001 (information security management) and ISO 22301 (business continuity management). Current certificates and a security documentation pack are available under NDA on request.

7.Third-party data sources

Screening lists, registry data, blockchain analytics, and Travel Rule network connectivity are supplied by third-party sources and networks. Coverage, refresh frequency, and availability are set by those sources.

ITSEC passes through source results with the evidence and timestamps received. It does not warrant the completeness or accuracy of third-party source data, and source terms may apply to specific modules where stated in the order form.

8.Confidentiality

Each party will keep the other's non-public information confidential, use it only to perform under the agreement, and protect it with no less care than it applies to its own confidential information. This obligation survives termination.

9.Intellectual property

ITSEC and its licensors retain all rights in the Platform, including its software, models, rule libraries, and documentation. The Customer receives a non-exclusive, non-transferable right to use the Platform during the term for its own compliance operations.

The Customer retains all rights in the data it submits and in the records generated for its cases. Feedback provided about the Platform may be used to improve the service.

10.Fees and billing

Pricing is quoted against the modules enabled and expected volumes; there is no public price list. Fees, billing frequency, currency, and any minimum commitment are recorded in the order form.

Invoices are payable within the period stated in the order form. Usage above a committed volume is billed at the overage rate recorded there. Fees are exclusive of VAT and other applicable taxes.

11.Term, suspension, and termination

The agreement runs for the term stated in the order form and renews only as recorded there. Either party may terminate for material breach that remains uncured 30 days after written notice.

ITSEC may suspend access where use threatens the security or integrity of the Platform, breaches the Acceptable Use Policy, or where fees remain unpaid after notice. On termination, the Customer may export its case records and evidence during the retrieval window stated in the DPA, after which data is deleted in line with the retention schedule.

12.Warranties and disclaimers

Each party warrants that it has the authority to enter into the agreement. ITSEC warrants that it will supply the Platform with reasonable skill and care.

Beyond that, the Platform is provided without implied warranties. ITSEC does not warrant that verification, screening, or monitoring results will be free of false positives or false negatives, or that use of the Platform will render the Customer compliant with any regulation.

13.Liability

Neither party is liable for indirect, incidental, special, or consequential loss, or for loss of profit, revenue, goodwill, or anticipated savings. Each party's aggregate liability is capped at the fees paid or payable in the 12 months preceding the claim, except for liability that cannot be limited by law.

Nothing in this section limits either party's obligations for its own breach of confidentiality or for regulatory fines imposed on it for its own acts.

14.Changes to the Platform and these terms

The Platform is developed continuously; modules and features may be added or improved. Material adverse changes to a subscribed capability will be notified in advance. Material changes to these terms will be notified to the Customer's registered contact, and the effective date above will be updated.

15.Governing law and disputes

The agreement is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai, and the parties submit to the exclusive jurisdiction of the Dubai courts, unless a different forum is agreed in the order form.

16.Contact

Questions about these terms, contract documents, or the security pack: sales@verifix.ae.