Security & Privacy

Information Security Policy

All temporary private-file storage takes place in Cape Town. Ordinary single-check reports are delivered without private-file storage by default. Global edge security and time-limited idempotency processing follow the safeguards described below.

Version 2.1 · Last updated: August 11, 2026

POPIA Aligned

Purpose and access controls

Encrypted Transport

Managed HTTPS connections

Cape Town Storage

Temporary private files

Limited File Access

Authenticated, short-lived links

About This Policy

This public policy explains the controls used by VerifyNow, operated by Urban Luxury Brands (Pty) Ltd trading as VerifyNow (Registration number: 2007/013732/07), to protect information handled through the platform. It applies to the website, dashboard, API, batch services, private file storage, and supporting operations.

The controls support confidentiality, integrity, availability, and POPIA-aligned processing. Each customer remains responsible for its lawful purpose, processing authority, user access, and instructions. The Data Processing Agreement records the parties' respective duties when VerifyNow acts as an operator.

Data Protection

Information in transit

  • Production website, dashboard, and API connections use managed HTTPS encryption
  • Customer API requests require a valid account key on protected routes
  • Dashboard sessions use authenticated access for protected customer functions
  • Service providers receive the information needed to fulfil the selected request

Stored information

  • Private objects use AES-256 server-side encryption or an equivalent managed control
  • Managed database services provide encryption at rest and access controls
  • Batch and consent files remain private for their stated retention periods
  • Payment processors handle card details and bank-account payment credentials

Processing locations

  • All temporary private-file storage takes place in Cape Town, South Africa
  • Primary application request execution takes place in Cape Town, South Africa
  • Isolated image rendering for enabled document workflows takes place in Johannesburg, South Africa
  • Global edge security and managed Redis services can process limited technical and time-limited idempotency records outside South Africa under the Data Processing Agreement

Access Control

  • Protected API routes require customer-specific credentials
  • Protected dashboard functions require an authenticated user session
  • Organisation and ownership checks guard access to eligible customer records
  • Private file downloads require an ownership check and use signed links capped at five minutes

Access responsibilities

  • VerifyNow limits privileged access to authorised personnel and service accounts
  • Customers control their team members and remove access when a role changes
  • Customers must keep API keys confidential and rotate a key after suspected exposure
  • Audit metadata is recorded where a workflow supports security, billing, and support review

Infrastructure Security

  • Managed edge infrastructure provides network-level DDoS protection
  • A web application firewall filters common web attack patterns
  • Rate limits and abuse controls protect selected routes and platform functions
  • Managed serverless services reduce the infrastructure operated directly by VerifyNow

Maintenance

  • Infrastructure providers maintain the underlying managed services
  • VerifyNow reviews reported platform weaknesses and applies fixes according to risk
  • Application dependencies receive security updates through the release process

Recovery

  • Managed database services provide backup and recovery capabilities
  • Private object retention follows the schedule for each workflow
  • An RTO or RPO applies only when it is stated in a signed customer agreement

Regulatory Compliance

POPIA (Protection of Personal Information Act)

VerifyNow's controls support POPIA-aligned processing. The customer supplies the lawful purpose and authority for each check.

  • The default verification purpose is identity fraud prevention and fraud detection
  • Each request is limited to the fields needed by the selected service
  • Retention periods follow the workflow and the applicable record-keeping duty
  • VerifyNow supports documented data-subject requests within its role and legal duties

FICA (Financial Intelligence Centre Act)

Customers can use eligible services as part of their own risk-based FICA process. The customer decides which checks its risk management and compliance programme requires.

  • Identity and company verification can support customer due diligence
  • AML, sanctions, and PEP screening can support risk assessment
  • Reference and billing metadata can support a customer's audit evidence

Retention and Secure Delivery

  • Full reports from ordinary single checks are not stored by default after delivery
  • Self-service batch inputs, row results, and result files are retained for up to 30 days after completion
  • Large-batch source uploads are retained for up to seven days
  • Consent documents and consent evidence follow the current seven-year schedule
  • Audit, billing, security, and account records follow their legal, accounting, security, or contractual periods

Eligible customer information can be returned or deleted under the Data Processing Agreement. Records required for legal, accounting, dispute, security, or compliance purposes remain subject to their applicable period.

Security Events and Incident Response

  • Platform errors, performance signals, and relevant security events feed operational logs and alerts
  • Reported or detected incidents are assessed, contained, and investigated according to their effect
  • Material findings inform remediation and follow-up work

Customer Notification SLA

For customers covered by the current Data Processing Agreement, a confirmed personal data breach triggers the following response:

  • Affected customers receive notice without undue delay and within 48 hours of VerifyNow becoming aware of the confirmed breach
  • The available notice describes its nature, affected data, likely effect, and response measures
  • VerifyNow assists the customer with its applicable regulatory duties

Responsible Disclosure

If you believe you have found a security vulnerability in VerifyNow, please report it to security@verifynow.co.za.

When testing, use test accounts only. Do not access, copy, retain, disclose, modify, or delete customer data, platform configuration, pricing, credentials, or other production records.

Do not perform denial-of-service testing, spam, phishing, social engineering, physical attacks, or any testing that disrupts our services or affects other users.

Please include enough detail for us to reproduce and assess the issue, such as affected URLs, approximate timestamps, test account email addresses, request details, and clear reproduction steps.

VerifyNow does not operate a public bug bounty program. Any commercial remediation services are handled separately through our normal procurement process and are not part of vulnerability disclosure handling.

Security Questions?

If you have questions about our security practices or need to report a security concern, please contact us:

Email: security@verifynow.co.za