Your compliance data stays in the United Arab Emirates
VerifiX is designed so a UAE licensed entity can onboard customers, screen them, and monitor transactions without personal data, documents, or audit records leaving the jurisdiction. Data residency is a platform property here, not a paid add-on.
Primary region
United Arab Emirates
Hosted in UAE regions on AWS and Microsoft Azure.
Data at rest
Stored in-country
Customer records, documents, biometric templates, screening results, and audit logs.
Cross-border transfer
Not required to operate
Your records stay in the UAE; only third-party reference data is brought in.
Backups and DR
Kept within the same jurisdiction
Backups remain in UAE regions on the same providers.
Data map
What we hold, and where it lives
Bring this table to your risk committee. Each class of data is listed with its residency so there is no ambiguity in your vendor assessment.
| Data class | Residency | Detail |
|---|---|---|
| Identity documents and selfiesEmirates ID, passports, residency documents, liveness capture frames. | UAE | Emirates ID, passports, residency documents, liveness capture frames. |
| Biometric templatesFace-match templates derived at verification time, never shared between tenants. | UAE | Face-match templates derived at verification time, never shared between tenants. |
| Entity and UBO recordsTrade licenses, ownership structures, registry evidence, and resolved UBOs. | UAE | Trade licenses, ownership structures, registry evidence, and resolved UBOs. |
| Screening and monitoring resultsSanctions, PEP, adverse-media hits, wallet exposure, and analyst decisions. | UAE | Sanctions, PEP, adverse-media hits, wallet exposure, and analyst decisions. |
| Audit trailEvery decision, override, rule change, and export, with actor and timestamp. | UAE | Every decision, override, rule change, and export, with actor and timestamp. |
| Reference data (sanctions and chain analytics)Lists and analytics are pulled into the platform; provider locations are listed under sub-processors. | Sourced from providers | Lists and analytics are pulled into the platform; provider locations are listed under sub-processors. |
Controls
Security architecture
Encryption everywhere
TLS in transit and encryption at rest for every store, including document and biometric objects.
Aligned to the UAE encryption regulations and our ISO 27001 controls.
Key management
Managed keys with rotation and separation between environments, so production keys are never reachable from staging.
Managed key services on AWS and Azure, with scheduled rotation.
Tenant isolation
Every record is scoped to an organization at the database layer; queries without a tenant context return nothing.
Role-based access and four-eyes
Analyst, reviewer, and administrator roles with enforced second-approver steps on high-risk decisions.
Strong authentication
SSO and MFA for console access, scoped API keys for machine access, with per-key revocation.
SAML and OIDC single sign-on.
Immutable audit trail
Append-only decision history built for regulator inspection and exportable per case or per period.
Retention and deletion
Configurable retention aligned to your record-keeping obligations, with per-subject deletion once retention lapses.
Set to the retention period your license requires.
Incident response
Defined severity levels, notification path to your compliance contact, and post-incident reporting.
Notification to your compliance contact within the timeframe set in your DPA.
Vendor assessment
The five questions your risk team will ask
We answer these the same way in a sales call and in a due-diligence questionnaire. Anything not yet confirmed is marked rather than claimed.
VerifiX is built by ITSEC, a Dubai-headquartered security and compliance engineering firm — the same team runs the platform that holds your data.
- Where does our customer data physically sit?
- Inside the UAE, in the region listed above. Documents, biometrics, screening outcomes, and the audit trail are all held in-country, in UAE regions on AWS and Microsoft Azure.
- Does anything leave the country?
- Operating the platform does not require moving your records out of the UAE. Third-party reference data (sanctions lists, chain analytics) is brought in rather than sent out; every processor is named in our sub-processor list.
- Can we get evidence for our regulator or auditor?
- Yes — case-level and period-level exports from the audit trail, plus a data processing addendum and security documentation pack on request. ITSEC is certified to ISO/IEC 27001 (information security) and ISO 22301 (business continuity).
- Who inside VerifiX can see our data?
- Access is least-privilege and logged. Support access to tenant data is time-bound and requires an approved reason.
- What happens if we leave?
- Full export of your records and audit trail, then deletion on the schedule set in your contract.
Send us your due-diligence questionnaire
We will complete it against the live platform, walk your security and compliance teams through the architecture, and provide the DPA and sub-processor list in writing.


