Security & compliance

COMPLIANCE
BY DEFAULT.

Veriflow is built with Indian regulatory requirements as first-class constraints — not afterthoughts. DPDP Act 2023, RBI KYC Master Directions, UIDAI licensing and ISO 27001 are core to how we operate.

Contact security team

Certifications & licensing

Our compliance
posture.

Every certification and licence we hold — and what it means for data you process through Veriflow.

Active
DPDP Act 2023

Full compliance with India's Digital Personal Data Protection Act 2023. Consent capture, purpose limitation, data principal rights and breach notification protocols built in.

Licensed
UIDAI AUA / KUA

Authentication User Agency and KYC User Agency licences from UIDAI. Required to access Aadhaar OTP and eKYC XML. All Aadhaar calls are routed through licensed infrastructure.

Compliant
RBI KYC Master Directions

V-CIP, CKYC, periodic re-KYC and simplified KYC journeys built to the Reserve Bank of India's 2024 Master Directions on KYC.

Certified
ISO 27001:2022

Information security management system certified to ISO 27001:2022. Annual third-party audits, vulnerability disclosure programme and 24-hour incident response SLA.

Compliant
IT Act 2000 — eSign

eSign services certified under the Controller of Certifying Authorities. Aadhaar OTP-based signatures are court-admissible under Section 5 of the IT Act 2000.

SOC 2 — In Progress
SOC 2 Type II

SOC 2 Type II audit in progress. Report available to enterprise customers under NDA. Expected completion Q3 2026.

Data policies

How we handle
your data.

Verifications run through Veriflow, but your customers' data is yours. Here's exactly how we handle it.

No data retention by default

PII returned in verification responses is not stored on Veriflow infrastructure after delivery, unless you opt into audit-log retention. Configurable per module.

Data residency — India

All verification processing runs on AWS ap-south-1 (Mumbai). No personal data leaves Indian borders. Enterprise customers can opt for dedicated VPC deployment.

Encrypted in transit and at rest

TLS 1.3 for all API traffic. AES-256 for data at rest. API keys are hashed on storage — Veriflow cannot recover them.

DPDP consent logging

Every Aadhaar and DigiLocker call requires explicit consent. Timestamp, purpose, IP and consent text are logged and exportable for your DPO.

SECURITY QUESTIONS?

Our security team responds to enterprise enquiries within one business day.

Email security team Get API Key
DPDP Act 2023
RBI KYC Master Directions
UIDAI AUA / KUA Licensed
ISO 27001 Certified
IT Act 2000 eSign Ready