Skip to content
VerifiX — secured by ITSEC
Built for UAE regulated entitiesMade in the UAE — built to meet UAE PDPL

Your compliance data stays in the United Arab Emirates

VerifiX is designed so a UAE licensed entity can onboard customers, screen them, and monitor transactions without personal data, documents, or audit records leaving the jurisdiction. Data residency is a platform property here, not a paid add-on.

Primary region

United Arab Emirates

Hosted in UAE regions on AWS and Microsoft Azure.

Data at rest

Stored in-country

Customer records, documents, biometric templates, screening results, and audit logs.

Cross-border transfer

Not required to operate

Your records stay in the UAE; only third-party reference data is brought in.

Backups and DR

Kept within the same jurisdiction

Backups remain in UAE regions on the same providers.

Data map

What we hold, and where it lives

Bring this table to your risk committee. Each class of data is listed with its residency so there is no ambiguity in your vendor assessment.

Data classResidency
Identity documents and selfiesEmirates ID, passports, residency documents, liveness capture frames.UAE
Biometric templatesFace-match templates derived at verification time, never shared between tenants.UAE
Entity and UBO recordsTrade licenses, ownership structures, registry evidence, and resolved UBOs.UAE
Screening and monitoring resultsSanctions, PEP, adverse-media hits, wallet exposure, and analyst decisions.UAE
Audit trailEvery decision, override, rule change, and export, with actor and timestamp.UAE
Reference data (sanctions and chain analytics)Lists and analytics are pulled into the platform; provider locations are listed under sub-processors.Sourced from providers

Controls

Security architecture

Encryption everywhere

TLS in transit and encryption at rest for every store, including document and biometric objects.

Aligned to the UAE encryption regulations and our ISO 27001 controls.

Key management

Managed keys with rotation and separation between environments, so production keys are never reachable from staging.

Managed key services on AWS and Azure, with scheduled rotation.

Tenant isolation

Every record is scoped to an organization at the database layer; queries without a tenant context return nothing.

Role-based access and four-eyes

Analyst, reviewer, and administrator roles with enforced second-approver steps on high-risk decisions.

Strong authentication

SSO and MFA for console access, scoped API keys for machine access, with per-key revocation.

SAML and OIDC single sign-on.

Immutable audit trail

Append-only decision history built for regulator inspection and exportable per case or per period.

Retention and deletion

Configurable retention aligned to your record-keeping obligations, with per-subject deletion once retention lapses.

Set to the retention period your license requires.

Incident response

Defined severity levels, notification path to your compliance contact, and post-incident reporting.

Notification to your compliance contact within the timeframe set in your DPA.

Vendor assessment

The five questions your risk team will ask

We answer these the same way in a sales call and in a due-diligence questionnaire. Anything not yet confirmed is marked rather than claimed.

VerifiX is built by ITSEC, a Dubai-headquartered security and compliance engineering firm — the same team runs the platform that holds your data.

Where does our customer data physically sit?
Inside the UAE, in the region listed above. Documents, biometrics, screening outcomes, and the audit trail are all held in-country, in UAE regions on AWS and Microsoft Azure.
Does anything leave the country?
Operating the platform does not require moving your records out of the UAE. Third-party reference data (sanctions lists, chain analytics) is brought in rather than sent out; every processor is named in our sub-processor list.
Can we get evidence for our regulator or auditor?
Yes — case-level and period-level exports from the audit trail, plus a data processing addendum and security documentation pack on request. ITSEC is certified to ISO/IEC 27001 (information security) and ISO 22301 (business continuity).
Who inside VerifiX can see our data?
Access is least-privilege and logged. Support access to tenant data is time-bound and requires an approved reason.
What happens if we leave?
Full export of your records and audit trail, then deletion on the schedule set in your contract.

Send us your due-diligence questionnaire

We will complete it against the live platform, walk your security and compliance teams through the architecture, and provide the DPA and sub-processor list in writing.