Trust and data

The most dangerous asset of a verification company is data it did not need but kept anyway. That is why data minimisation is architecture for us, not policy.

  • We keep outcomes, not raw materials: that something is verified, with method, moment and validity; source documents no longer than strictly necessary.

  • Access is role-based and logged; professionals' data is kept separate from commercial analysis.

  • Our security is set up along an external yardstick (ISO/IEC 27001 as an internal norm); payment data does not touch the platform.

What we record, and what we do not

We design from one question: what is the minimum we must record to keep our promise? The answer is almost always the proof that verification took place, with method, moment, and validity, not the source data used to verify. We do not keep source documents longer than strictly necessary.

Security against an external yardstick

We do not assess our own security ourselves. We arrange information security along ISO/IEC 27001, the international standard, as an internal yardstick: we record every security decision as though the auditor arrives tomorrow. The platform does not touch payment details; card payments run entirely through a specialised payment service provider.

Every critical supplier has an exit

For every critical supplier: there is a documented alternative, the data is exportable in an open format, and the switch-over time is known and tested on paper. This way the infrastructure remains ours, even if a supplier drops away.