SecurityEvery verified action is cryptographically signed. Records are tamper-evident: any alteration breaks the signature and surfaces immediately. API keys are scoped per environment and capability, revocable instantly, and all transport is TLS.
PrivacyData minimisation by default. Verification artefacts are held only as long as your policy requires. Public certificates publish only what trust requires; identity documents, device identifiers and personal data stay private. Ownership can be proven without exposing documents.
ArchitectureVerification decisions combine biometric, liveness, device and context signals against per-action policy at the Confrmo edge. The Ledger is a governed, signed register with optional blockchain anchoring. Your systems receive decisions and signed proofs, never raw biometrics.
ComplianceAligned to UK and EU GDPR, NIS2, eIDAS 2.0, and strong customer authentication under the Payment Services Regulations 2017 and the FCA’s SCA-RTS. Design is also aligned to the PSD3 proposals, which are not yet in force. Tamper-evident audit logs give your own compliance case evidence rather than assertion. Copyright in the core verification application arises automatically under UK law and is held by Confrmo. United Kingdom patent applications are pending; they are listed at confrmo.com/patents.
Enterprise APIsPolicy-driven REST APIs, webhooks with signed deliveries, an issuer console and an admin portal. Sandbox keys exercise every flow in CI before production. See the Developer Platform for the working reference.
DeploymentWebsites through the drop-in SDK, native apps through iOS and Android SDKs, WordPress through the official plugin. Data residency requirements are agreed and documented during deployment scoping. First integration typically live in under a day; enterprise rollouts phase by role or system.
InfrastructureConfrmo’s production platform runs in IONOS data centres. IONOS Holding SE holds ISO/IEC 27001:2022 certification (TÜV NORD CERT, registration 44 121 160247-012, valid to 18 April 2028) covering the operation of infrastructure and platforms in those data centres. This certification is held by IONOS and covers the hosting environment. Confrmo does not itself hold ISO/IEC 27001 certification.