Identity assurance
Controls for secure onboarding, reusable identity data, consent-based disclosure and robust evidence packages for verification decisions.
Welcome to the WeVerify Trust Center. This page gives customers, auditors and partners a transparent view of how WeVerify protects identity, signature and verification workflows across people, processes, technology and suppliers.
WeVerify brings identity verification, business verification, authority checks, sanctions and PEP screening, customer due diligence, document generation and electronic signing into one secure platform. Our trust program is built to support customer due diligence, auditability, resilience and compliance across high-assurance digital transactions.
Controls for secure onboarding, reusable identity data, consent-based disclosure and robust evidence packages for verification decisions.
Governance and technical documentation supporting electronic signature and trust service workflows under ETSI-aligned requirements.
Processes for entity verification, representative authority checks, mandate validation and secure evidence retention for regulated workflows.
API-first controls covering authentication, logging, monitoring, secure development and customer-controlled data exchange with audit trails.
WeVerify maintains documentation across six compliance domains. Access to non-public materials may require a corporate email address, NDA and internal approval.
Full information security management documentation: 93+ policies, Annex A control mapping, Statement of Applicability, internal audit evidence and management review records. All four Annex A domains covered: A.5 Organizational (37 controls), A.6 People (8), A.7 Physical (14), A.8 Technological (34).
Trust service policy documentation, operational procedures, certificate lifecycle evidence, governance records and assessment support materials for electronic signature and seal services under eIDAS requirements.
Privacy-by-design controls, data minimisation, purpose limitation, processor support agreements, data subject rights workflows, retention governance, DPIA support and personal data breach notification procedure aligned to Articles 33 and 34.
Assurance documentation for electronic identification, electronic signatures, electronic seals, audit trails and trust-service related workflows including EUDI Wallet interoperability preparation.
Security governance, supply chain oversight, incident response and reporting, business continuity, ICT continuity testing, vulnerability management and risk monitoring controls aligned to NIS2 essential entity requirements.
Evidence packages, verification reports and auditable workflows to support regulated customer onboarding and compliance operations suitable for AMLD6, PSD2, DORA and sector-specific requirements.
WeVerify's ISO 27001 control library covers all four Annex A domains. Select a tab to explore the controls implemented across organizational, people, physical and technological security.
Governance, risk management, policy framework, asset management, access control, supplier relationships, incident management, business continuity and legal compliance.
Pre-employment screening, terms and conditions, disciplinary processes, confidentiality obligations, remote work and security event reporting.
Physical perimeter security, secure area access, equipment protection, media handling and disposal controls.
Endpoint security, access management, vulnerability management, configuration, data protection, logging, network security and cryptography.
WeVerify operates a defence-in-depth security program covering encryption, access management, secure development, vulnerability management and independent testing. The program is governed by the ISMS and reviewed annually by senior management.
All personal data and verification payloads are encrypted at rest using AES-256. All data in transit is protected using TLS 1.2 or higher with approved cipher suites. Key management, algorithm selection and prohibited ciphers are governed by the Cryptographic Policy.
Multi-factor authentication is enforced for all remote access and privileged systems. Access is provisioned on a least-privilege basis with role-based controls, periodic access reviews and automated deprovisioning on role change or departure. Privileged access is logged and monitored.
Security requirements are embedded throughout the SDLC. Threat modelling, static application security testing (SAST), peer code review, dependency scanning and OWASP Top 10 coverage are applied before any production release. Production, staging and development environments are strictly separated. All releases require a security sign-off gate.
All infrastructure and application changes follow the Change Management Process: request, risk assessment, approval, testing, rollback planning and post-change review. Emergency changes are subject to retrospective review. Unauthorised or ad-hoc changes are prohibited in production.
Automated vulnerability scanning runs continuously across infrastructure and application layers. Critical and high-severity findings are remediated within defined SLAs. The Technical Vulnerability Management Policy and Vulnerability Assessment Procedure govern scan scope, finding triage, patch prioritisation and exception handling.
WeVerify commissions independent third-party penetration tests at least annually. Tests cover application, API, network and infrastructure scope using OWASP and PTES methodologies. Findings are tracked through to remediation. Summary test scope and remediation status are available to customers under NDA on request via security@weverify.com.
WeVerify operates a responsible disclosure programme. If you discover a potential security vulnerability in any WeVerify product or infrastructure, please report it to security@weverify.com with a description, reproduction steps and potential impact. We acknowledge reports within 5 business days and aim to resolve confirmed vulnerabilities within 90 days. We ask researchers to avoid data access, service disruption or disclosure to third parties during investigation.
All production systems generate security-relevant logs covering authentication events, access to personal data, configuration changes and system errors. Logs are protected against tampering, retained for defined periods under the Logging and Monitoring Policy, and integrated into continuous monitoring. On-call procedures ensure 24/7 alerting for critical events.
WeVerify operates a Threat Intelligence Policy and Process covering monitoring of threat actor activity, CVE feeds, industry advisories and sector-specific intelligence sources relevant to identity verification and digital signing. Findings feed directly into vulnerability management prioritisation and risk assessment updates.
Mobile Device Policy and BYOD Policy govern device enrollment, encryption, remote wipe capability and application controls. Anti-Malware Policy requires endpoint protection on all managed devices with defined update cadence and incident escalation. Clear Desk and Clear Screen Policy applies across all office locations.
WeVerify responds to lawful requests from law enforcement and competent authorities in accordance with applicable law. Requests must be submitted in writing with legal basis to compliance@weverify.com. WeVerify will notify affected customers of requests unless prohibited by law or court order. We reserve the right to challenge requests that are overly broad, unlawful or disproportionate.
For security incidents, suspected vulnerabilities or urgent security concerns: security@weverify.com. For compliance and audit requests: compliance@weverify.com. For privacy matters: privacy@weverify.com.
WeVerify's platform is built on EU-based cloud infrastructure with multi-zone redundancy, automated failover and formally tested business continuity and ICT continuity plans. Availability is monitored continuously with defined on-call escalation paths.
All personal data processed and stored within the European Economic Area. Data residency is enforced at infrastructure level. No personal data is transferred outside the EEA without a lawful transfer mechanism in place.
Production workloads are deployed across multiple availability zones within the EU. Automated health checks, load balancing and failover ensure continuity in the event of zone-level disruption without requiring manual intervention.
The Backup Policy defines scope, frequency, encryption, offsite storage requirements and restoration test schedules. Backups are encrypted and stored separately from primary systems. Recovery procedures are tested at defined intervals against documented RTO and RPO targets.
WeVerify maintains an ICT Continuity Plan aligned to ISO 27001 A.5.30, covering critical system identification, recovery priorities, escalation chains and alternative processing arrangements. The plan is exercised annually and updated following each test.
A formal Business Impact Analysis identifies critical processes, acceptable recovery time objectives and dependencies. Findings drive continuity planning priorities and are reviewed as part of the annual management review cycle.
The Capacity Plan sets thresholds for compute, storage and network resources with automated alerts and scaling procedures. Capacity is reviewed regularly to ensure availability SLAs can be maintained under peak load and growth scenarios.
WeVerify maintains 93+ ISMS documents covering all ISO 27001 clause requirements and Annex A controls. Access to non-public policies requires a signed NDA and approval.
| Document ID | Policy / Procedure | Standard area |
|---|---|---|
| Core ISMS — Clauses 4 to 10 | ||
| ISMS-DOC-04-1 | Information Security Context, Requirements and Scope | Cl. 4 |
| ISMS-DOC-05-1 | Information Security Management System Manual | Cl. 5, 7 |
| ISMS-DOC-05-2 | Information Security Roles, Responsibilities and Authorities | Cl. 5.3 / A.5.2 |
| ISMS-DOC-05-3 | Executive Support Letter | Cl. 5.1 |
| ISMS-DOC-05-4 | Information Security Policy | Cl. 5.2 / A.5.1 |
| ISMS-DOC-06-1 | Information Security Objectives and Plan | Cl. 6.1, 6.2 |
| ISMS-DOC-06-2 | Risk Assessment and Treatment Process | Cl. 6.1, 8.2 |
| ISMS-DOC-06-3 | Risk Assessment Report | Cl. 6.1, 8.2 |
| ISMS-DOC-06-4 | Risk Treatment Plan | Cl. 6.1, 8.3 |
| ISMS-FORM-06-2 | Statement of Applicability | Cl. 6.1.3 |
| ISMS-DOC-06-5 | ISMS Change Process | Cl. 6.3 |
| ISMS-DOC-07-1 | Information Security Competence Development Procedure | Cl. 7.2 |
| ISMS-DOC-07-2 | Information Security Communication Programme | Cl. 7.4 |
| ISMS-DOC-07-3 | Procedure for the Control of Documented Information | Cl. 7.5 |
| ISMS-DOC-08-1 | ISMS Process Interaction Overview | Cl. 4.4, 8.1 |
| ISMS-DOC-09-2 | Procedure for Internal Audits | Cl. 9.2 / A.5.35 |
| ISMS-DOC-09-3 | Internal Audit Plan | Cl. 9.2 |
| ISMS-DOC-09-4 | Procedure for Management Reviews | Cl. 9.3 |
| ISMS-DOC-10-1 | Procedure for the Management of Nonconformity | Cl. 10.2 |
| A.5 Organizational controls | ||
| ISMS-DOC-A05-01-1 | Social Media Policy | A.5.1 |
| ISMS-DOC-A05-01-2 | HR Security Policy | A.5.1 |
| ISMS-DOC-A05-03-1 | Segregation of Duties Guidelines | A.5.3 |
| ISMS-DOC-A05-04-1 | Information Security Whistleblowing Policy | A.5.4 |
| ISMS-DOC-A05-07-1 | Threat Intelligence Policy | A.5.7 |
| ISMS-DOC-A05-07-2 | Threat Intelligence Process | A.5.7 |
| ISMS-DOC-A05-09-1 | Asset Management Policy | A.5.9 |
| ISMS-DOC-A05-09-2 | Information Asset Inventory | A.5.9, A.5.34 |
| ISMS-DOC-A05-10-1 | Acceptable Use Policy | A.5.10 |
| ISMS-DOC-A05-10-2 | Internet Access Policy | A.5.10 |
| ISMS-DOC-A05-10-3 | Electronic Messaging Policy | A.5.10, A.5.14 |
| ISMS-DOC-A05-10-6 | Online Collaboration Policy | A.5.10, A.5.14 |
| ISMS-DOC-A05-12-1 | Information Classification Procedure | A.5.12 |
| ISMS-DOC-A05-13-1 | Information Labelling Procedure | A.5.13 |
| ISMS-DOC-A05-14-1 | Information Transfer Procedure | A.5.14 |
| ISMS-DOC-A05-15-1 | Access Control Policy | A.5.15 |
| ISMS-DOC-A05-18-1 | User Access Management Process | A.5.18 |
| ISMS-DOC-A05-19-1 | Information Security Policy for Supplier Relationships | A.5.19 |
| ISMS-DOC-A05-20-1 | Supplier Information Security Agreement | A.5.20 |
| ISMS-DOC-A05-21-1 | Supplier Due Diligence Assessment Procedure | A.5.21 |
| ISMS-DOC-A05-22-1 | Supplier Information Security Evaluation Process | A.5.22 |
| ISMS-DOC-A05-23-1 | Cloud Services Policy | A.5.23 |
| ISMS-DOC-A05-24-1 | Incident Response Plan — Ransomware | A.5.24 |
| ISMS-DOC-A05-24-2 | Incident Response Plan — Denial of Service | A.5.24 |
| ISMS-DOC-A05-24-3 | Incident Response Plan — Data Breach | A.5.24 |
| ISMS-DOC-A05-26-1 | Information Security Incident Response Procedure | A.5.26 |
| ISMS-DOC-A05-30-4 | ICT Continuity Plan | A.5.30 |
| ISMS-DOC-A05-30-2 | Business Impact Analysis Report | A.5.30 |
| ISMS-DOC-A05-31-2 | Legal, Regulatory and Contractual Requirements Register | A.5.31 |
| ISMS-DOC-A05-34-1 | Privacy and Personal Data Protection Policy | A.5.34 / GDPR |
| ISMS-DOC-A05-34-2 | Personal Data Breach Notification Procedure | A.5.34 / Art.33 |
| A.6 People controls | ||
| ISMS-DOC-A06-01-1 | Employee Screening Procedure | A.6.1 |
| ISMS-DOC-A06-02-1 | Guidelines for Inclusion in Employment Contracts | A.6.2 |
| ISMS-DOC-A06-04-1 | Employee Disciplinary Process | A.6.4 |
| ISMS-DOC-A06-06-2 | Non-Disclosure Agreement | A.6.6 |
| ISMS-DOC-A06-07-1 | Remote Working Policy | A.6.7 |
| ISMS-DOC-A06-08-1 | Information Security Event Reporting Procedure | A.6.8 |
| A.7 Physical controls | ||
| ISMS-DOC-A07-01-1 | Physical Security Policy | A.7.1 |
| ISMS-DOC-A07-02-1 | Physical Security Design Standards | A.7.2 |
| ISMS-DOC-A07-03-1 | Data Centre Access Procedure | A.7.2 |
| ISMS-DOC-A07-04-1 | CCTV Policy | A.7.4 |
| ISMS-DOC-A07-07-1 | Clear Desk and Clear Screen Policy | A.7.7 |
| ISMS-DOC-A07-10-1 | Procedure for the Management of Removable Media | A.7.10 |
| ISMS-DOC-A07-14-1 | Procedure for the Disposal of Media | A.7.14 |
| A.8 Technological controls | ||
| ISMS-DOC-A08-01-1 | Mobile Device Policy | A.8.1 |
| ISMS-DOC-A08-01-2 | BYOD Policy | A.8.1 |
| ISMS-DOC-A08-07-1 | Anti-Malware Policy | A.8.7 |
| ISMS-DOC-A08-08-1 | Technical Vulnerability Management Policy | A.8.8 |
| ISMS-DOC-A08-09-1 | Configuration Management Policy | A.8.9 |
| ISMS-DOC-A08-10-1 | Information Deletion Policy | A.8.10 |
| ISMS-DOC-A08-12-1 | Data Leakage Prevention Policy | A.8.12 |
| ISMS-DOC-A08-13-1 | Backup Policy | A.8.13 |
| ISMS-DOC-A08-15-1 | Logging and Monitoring Policy | A.8.15 |
| ISMS-DOC-A08-20-1 | Network Security Policy | A.8.20 |
| ISMS-DOC-A08-24-1 | Cryptographic Policy | A.8.24 |
| ISMS-DOC-A08-32-1 | Change Management Process | A.8.32 |
WeVerify processes personal data as both a controller and processor. Our privacy program is embedded in our ISMS and aligned to GDPR, eIDAS and applicable national data protection requirements.
Privacy impact is assessed during product design. Data minimisation, purpose limitation and storage limitation are embedded in architecture and API design. Consent-based disclosure is the default for all identity verification outputs.
WeVerify supports data subject access, rectification, erasure and portability requests through documented workflows. Response timelines comply with GDPR Article 12. Contact privacy@weverify.com to submit a request.
All customers acting as controllers receive a Data Processing Agreement (DPA) under GDPR Article 28 defining processing scope, sub-processor lists, security measures, audit rights, breach notification timelines and Standard Contractual Clauses for any third-country transfers. Request the DPA via compliance@weverify.com.
Personal Data Breach Notification Procedure covers detection, impact assessment, supervisory authority notification within 72 hours (Art. 33), affected individual notification (Art. 34) and post-incident review. Customers are notified without undue delay following confirmation of a breach affecting their data.
Customers and their designated auditors may request audit evidence, compliance documentation and security certifications. Audits are conducted with reasonable advance notice. WeVerify provides responses to security questionnaires, vendor assessments and due diligence requests via compliance@weverify.com.
Personal data is processed and stored in the European Economic Area. Cross-border transfers require a legal transfer mechanism. Sub-processor locations are disclosed in the sub-processor register available on request.
Records Retention and Protection Policy and Information Deletion Policy define retention periods per data category. Automated deletion workflows enforce retention end dates with secure erasure standards applied on deletion and equipment disposal.
WeVerify can support customer Data Protection Impact Assessment processes with technical documentation, processing descriptions and security measure summaries. Request DPIA support via security@weverify.com.
WeVerify uses a limited set of approved sub-processors for cloud infrastructure, identity data sources and operational tooling. The current sub-processor register is available to customers under a Data Processing Agreement.
WeVerify maintains a Supplier Information Security Policy, Supplier Due Diligence Assessment Procedure and Supplier Evaluation Questionnaire for all third-party providers. Customers operating under a Data Processing Agreement receive advance written notice before any new sub-processor is engaged and may raise objections during the notice period. The full register including specific provider names is available to customers under a Data Processing Agreement.
WeVerify supports electronic signature and electronic seal workflows under eIDAS. The documentation package covers trust service policy, operational procedures, certificate lifecycle governance and evidence management.
Certificate Policy and Certification Practice Statement governing issuance, management, renewal and revocation of certificates. Available to eligible stakeholders under NDA.
End-to-end certificate lifecycle procedures: enrollment, validation, issuance, renewal, suspension and revocation aligned to ETSI EN 319 401 and EN 319 411 requirements.
Technical and procedural documentation for electronic signature and seal creation, including signatory identity assurance, sole control mechanisms and signature evidence bundle generation.
Conformity assessment documentation, audit schedules and ETSI-aligned evidence packages for supervisory body engagement.
Documentation tracking alignment with eIDAS 2 regulation including EUDI Wallet integration, PID attestation and attribute release governance.
Trust service specific incident classification, notification procedures for supervisory authority and subscribers, and business continuity provisions for service availability.
Key milestones, documentation updates and compliance events for customers and partners.
WeVerify launches a dedicated Trust Center providing transparent security, compliance and policy documentation for customers, auditors and partners.
Complete ISO 27001 policy set (93+ documents) including Annex A control coverage, Statement of Applicability and risk assessment evidence available under controlled access.
Trust service documentation package, including trust service policy, certificate lifecycle procedures and conformity assessment support materials, available to eligible enterprise stakeholders.
Current sub-processor categories with EU/EEA data residency disclosures published. Full register with provider names available under Data Processing Agreement.
Use the form to request secure access to WeVerify's documentation library. We respond within 2 business days. Restricted documents may require NDA review and approval.