Security & Trust

Built to be trusted

Identity data is sensitive. Spidify is engineered around security, privacy, and compliance from the ground up.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Sensitive identifiers like BVN and NIN are masked in logs and audit records.

NDP Act 2023 / GAID 2025 aligned

Personal-data handling is built to Nigeria's Data Protection Act 2023 and the GAID 2025, with data minimisation and purpose limitation by design.

CBN AML/CFT ready

PEP, sanctions and watchlist screening, with high-risk matches held for human review — never auto-approved.

Retention controls

Per-tenant retention with automated archival, PII purge, and eventual deletion, aligned to record-keeping obligations.

Immutable audit trail

Every verification decision is recorded — who, when, and why — to support regulatory review.

iBeta-grade liveness

Presentation-attack detection powered by Azure Face Liveness, independently tested to ISO 30107-3 Level 1 & 2.

Secure API access

Scoped API keys, HMAC-signed webhooks, and per-tenant rate limiting protect every integration.

Least-privilege access

Access to data is restricted on a need-to-know basis, with tenant isolation across the platform.

Certifications

Our liveness detection is powered by Azure Face Liveness, which is independently tested to ISO 30107-3 Level 1 & 2. We are progressively pursuing organisational certifications; for the current status, our security documentation, or a Data Processing Agreement, contact dpo@ha-shem.com.

Questions about security or compliance?

Talk to our team about your data-protection and AML requirements.