Security & Compliance

Engineered for the rooms
where trust is examined.

Procurement teams, security reviewers and regulators ask the same questions of every trust platform. This page answers them plainly: how Confrmo is built, what it stores, what it never stores and how it deploys.

SecurityEvery verified action is cryptographically signed. Records are tamper-evident: any alteration breaks the signature and surfaces immediately. API keys are scoped per environment and capability, revocable instantly, and all transport is TLS.
PrivacyData minimisation by default. Verification artefacts are held only as long as your policy requires. Public certificates publish only what trust requires; identity documents, device identifiers and personal data stay private. Ownership can be proven without exposing documents.
ArchitectureVerification decisions combine biometric, liveness, device and context signals against per-action policy at the Confrmo edge. The Ledger is a governed, signed register with optional blockchain anchoring. Your systems receive decisions and signed proofs, never raw biometrics.
ComplianceAligned to UK and EU GDPR, NIS2, eIDAS 2.0, and strong customer authentication under the Payment Services Regulations 2017 and the FCA’s SCA-RTS. Design is also aligned to the PSD3 proposals, which are not yet in force. Tamper-evident audit logs give your own compliance case evidence rather than assertion. Copyright in the core verification application arises automatically under UK law and is held by Confrmo. United Kingdom patent applications are pending; they are listed at confrmo.com/patents.
Enterprise APIsPolicy-driven REST APIs, webhooks with signed deliveries, an issuer console and an admin portal. Sandbox keys exercise every flow in CI before production. See the Developer Platform for the working reference.
DeploymentWebsites through the drop-in SDK, native apps through iOS and Android SDKs, WordPress through the official plugin. Data residency requirements are agreed and documented during deployment scoping. First integration typically live in under a day; enterprise rollouts phase by role or system.
InfrastructureConfrmo’s production platform runs in IONOS data centres. IONOS Holding SE holds ISO/IEC 27001:2022 certification (TÜV NORD CERT, registration 44 121 160247-012, valid to 18 April 2028) covering the operation of infrastructure and platforms in those data centres. This certification is held by IONOS and covers the hosting environment. Confrmo does not itself hold ISO/IEC 27001 certification.
Aligned to UK and EU GDPRNIS2eIDAS 2.0SCA under the PSRs 2017 and the FCA SCA-RTSPSD3 proposals, not yet in force
ISO/IEC 27001 certified hostingEU data centresTLS in transitSigned, tamper-evident recordsRaw biometrics never leave the deviceScoped, revocable API keys
Organisation verification

Any company can type its own name into a form.

So Confrmo does not take its word for it. Every organisation is bound to the statutory register, then asked to prove it controls what it claims. Each check is dated, recorded and published, so anyone reading a company page can see what was actually tested rather than take a badge on trust.

Registry matchConfrmo queries the Companies House register directly through its official API and binds the organisation to its statutory record. The registered name, company number and registered office shown on a Confrmo company page are the register’s values, not the ones somebody typed into a form. A company that is not active on the register is refused.
What a registry match provesThat the company exists on the register, and nothing beyond that. Company numbers are public information and anyone can quote one. Confrmo therefore treats the register as an anchor rather than as evidence of good standing, and awards no verification badge for a registry match on its own.
Domain controlThe organisation publishes a TXT record containing a Confrmo-issued token on the domain it trades from. Confrmo resolves it and records the outcome. A copied company number cannot pass this check, because it requires control of the domain itself. An organisation that passes it earns the Domain verified badge.
Recorded, not assertedEvery check is written to the organisation’s record with the date it was carried out, and republished on that organisation’s public company page. The badge is derived from the evidence each time it is shown rather than stored as a flag, so it cannot run ahead of the checks behind it.
See it on our own recordConfrmo Ltd was onboarded through exactly this process, and its own company page carries the same two checks and the dates they were made. Read it at confrmo.confrmo.com. Every organisation on Confrmo gets the same page, the same checks and the same wording, including the line stating what Confrmo does not vouch for.
Companies House registerRegistered name, number and officeInactive companies refusedDNS domain controlDated, recorded checksPublic company page

Company information is taken from the Companies House register via the Companies House public data API and contains public sector information licensed under the Open Government Licence v3.0. Confrmo is not affiliated with, endorsed by, or acting on behalf of Companies House.

Put your hardest questions to us.

Security reviews, procurement questionnaires and architecture sessions welcome.