Skip to main content

Trust Center

Security, privacy, and compliance are foundational to NoxVerify. Learn how we protect your data and meet regulatory requirements.

Data Protection

Encryption at Rest

All data stored in encrypted form using AES-256. Database, object storage, and cache layers are encrypted by default.

Encryption in Transit

TLS 1.3 enforced on all connections. Certificate pinning available for enterprise API integrations.

Regional Data Processing

Choose data processing regions to comply with data residency requirements. Jurisdiction-locked deployments available for enterprise.

Data Retention Policies

Configurable retention periods per tenant. Automated purge workflows with audit trail. Legal hold support for regulatory inquiries.

Compliance Frameworks

NoxVerify supports verification workflows aligned with the following regulatory frameworks:

Anti-Money Laundering (AML) Directives
Know Your Customer (KYC) Regulations
Know Your Business (KYB) Due Diligence
Financial Action Task Force (FATF) Recommendations
EU Payment Services Directive (PSD2)
US Bank Secrecy Act (BSA)
UK Money Laundering Regulations
OFAC Sanctions Screening

Security Practices

Penetration Testing

Annual third-party penetration tests. Continuous automated vulnerability scanning across all endpoints.

Vulnerability Management

Dependency scanning, container scanning, and static analysis in CI/CD. Critical vulnerabilities patched within 24 hours.

Access Control

Least-privilege access. Multi-factor authentication required for all infrastructure access. Time-bounded support access with approval workflows.

Incident Response

Documented incident response plan. Automated alerting, severity classification, and post-mortem process for all security events.

Questions about security?

Our security team is available to discuss your specific requirements, answer questions, and provide documentation.

Contact Security Team