Built to be trusted
Identity data is sensitive. Spidify is engineered around security, privacy, and compliance from the ground up.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. Sensitive identifiers like BVN and NIN are masked in logs and audit records.
NDP Act 2023 / GAID 2025 aligned
Personal-data handling is built to Nigeria's Data Protection Act 2023 and the GAID 2025, with data minimisation and purpose limitation by design.
CBN AML/CFT ready
PEP, sanctions and watchlist screening, with high-risk matches held for human review — never auto-approved.
Retention controls
Per-tenant retention with automated archival, PII purge, and eventual deletion, aligned to record-keeping obligations.
Immutable audit trail
Every verification decision is recorded — who, when, and why — to support regulatory review.
iBeta-grade liveness
Presentation-attack detection powered by Azure Face Liveness, independently tested to ISO 30107-3 Level 1 & 2.
Secure API access
Scoped API keys, HMAC-signed webhooks, and per-tenant rate limiting protect every integration.
Least-privilege access
Access to data is restricted on a need-to-know basis, with tenant isolation across the platform.
Certifications
Our liveness detection is powered by Azure Face Liveness, which is independently tested to ISO 30107-3 Level 1 & 2. We are progressively pursuing organisational certifications; for the current status, our security documentation, or a Data Processing Agreement, contact dpo@ha-shem.com.