Last Updated: January 3, 2025
Veriglob is designed from the ground up to help organizations achieve and maintain regulatory compliance while leveraging decentralized identity technology. Our privacy-preserving architecture aligns with global data protection regulations and industry standards.
Compliance by Design: Veriglob's architecture enables data minimization, user consent, and privacy preservation—core requirements of modern privacy regulations—while still meeting verification and audit requirements.
Veriglob's protocol supports GDPR compliance through:
Our protocol aligns with the European electronic identification framework:
Enable compliant identity verification without storing customer documents. Verifiable credentials from trusted issuers satisfy KYC requirements while minimizing data retention.
Strong customer authentication (SCA) support with verifiable credentials for secure, consent-based data sharing.
Travel Rule compliance through verifiable credentials for originator and beneficiary information sharing.
Tamper-proof audit trails and access controls support Sarbanes-Oxley requirements.
Information Security Management System certification demonstrating systematic management of sensitive information.
Service Organization Control audit covering security, availability, processing integrity, confidentiality, and privacy.
Full compliance with W3C Decentralized Identifiers (DIDs) v1.0 specification.
Full compliance with W3C Verifiable Credentials Data Model v1.1 and v2.0.
Veriglob maintains strict compliance with international sanctions and export control regulations.
Our services are not available in the following jurisdictions:
Cuba, Iran, North Korea, Syria, Crimea region of Ukraine, and other jurisdictions subject to comprehensive US, EU, or UN sanctions. This list may be updated as sanctions regimes change.
Our cryptographic software complies with applicable export control regulations. The open-source protocol components are publicly available under applicable exemptions. Enterprise customers may be subject to additional export compliance requirements.
We offer data residency options to help organizations meet local data protection requirements:
| Region | Data Centers | Availability |
|---|---|---|
| European Union | Frankfurt, Amsterdam | Available |
| United States | Virginia, Oregon | Available |
| United Kingdom | London | Available |
| Asia Pacific | Singapore, Tokyo | Available |
| Africa | South Africa | Coming Q2 2025 |
Enterprise customers can configure data residency requirements to ensure data stays within specific geographic boundaries. Contact our sales team for multi-region and custom deployment options.
Veriglob supports trust registry integration for regulatory oversight and governance:
Governments and industry consortia can operate their own trust registries using Veriglob's open-source governance framework.
We provide tools to help organizations using Veriglob maintain their own compliance:
Real-time visibility into verification activities, credential issuance, and access logs for compliance monitoring and reporting.
Pre-built compliance reports for common regulatory frameworks, exportable in multiple formats.
Define and enforce verification policies based on credential types, issuer trust levels, and jurisdictional requirements.
Configurable data retention policies with automatic purging to meet regulatory requirements.
Our compliance team is available to help enterprise customers navigate regulatory requirements:
We are committed to transparency with regulators and provide:
For compliance-related inquiries, audit requests, or to discuss specific regulatory requirements:
Veriglob Ltd.
Compliance Team: Compliance Team
Data Protection Officer: DPO Officer
Enterprise Sales: Enterprise Sales