Security & data

Biometric data is the most sensitive thing we touch. We hold as little of it as the job allows.

This page states what VAHI stores, for how long, where it runs — and which assurances we have not yet earned.

What we store

Templates, not galleries.

Biometric templates A face check produces a mathematical representation — a vector — not a photograph. It cannot be turned back into a picture of a person. This is what VAHI compares against, and it is the only biometric form kept at rest.
One reference image, encrypted A single enrollment image is retained in encrypted form so that templates can be regenerated when models are updated — without asking every candidate to enroll again. It is never used for matching directly and never leaves storage in readable form.
Scores and events, not video Interview checks send results — a score, a timestamp, an event — not video streams. Footage is retained only for segments that were actually flagged for human review.
Deleted by default Ninety days, configurable per customer, after which flagged material is removed automatically rather than on request.

Consent

Nothing happens without an explicit, recorded yes.

Consent is granular, never pre-ticked, and the exact wording a candidate agreed to is stored with their record — so it is always possible to establish what was actually shown to them, not merely which version number was current.

Consent text is versioned and immutable. Changing the wording requires issuing a new version; it cannot be edited in place behind records that already reference it.

Candidates can raise access and erasure requests. Because the evidence chain is append-only by design, erasure is handled by destroying the keys that make a record readable rather than by deleting rows — which keeps the audit chain intact while making the personal data unrecoverable.

Evidence integrity

Records that cannot be quietly edited — including by us.

Append-only Evidence records cannot be updated or deleted. Corrections are added as new entries; the original stays visible.
Hash-chained Each record carries the fingerprint of the one before it. Altering an entry breaks every link after it, detectably.
Signed Certificates are cryptographically signed and can be verified offline by anyone holding the published key — including your auditors, without our involvement.
Refusals are evidence too When VAHI declines to issue a certificate, that refusal is itself signed and recorded, with its reason. There is no control anywhere in the product that overrides it.

Fairness

A flag is not a verdict.

No automated rejection VAHI cannot reject, block, or disqualify a candidate. It produces evidence; a named human decides. This is a structural property of the system, not a setting.
Explainable flags Every flag names what was observed and links to the specific evidence behind it. No opaque risk scores presented as conclusions.
Accessibility Signals that would penalise natural variation in how people look at a screen can be disabled per candidate without affecting identity verification.
Bias testing before general availability False-rejection and demographic-parity testing on a consented, representative dataset is a precondition for our first production deployment — not a follow-up. We will publish the methodology.

Where it runs

Your infrastructure, if that is what compliance requires.

VAHI is built on portable infrastructure — containers and orchestration, standard databases, no proprietary cloud service in the verification path. The cloud provider is a configuration choice, not an architectural commitment.

That means it can be deployed entirely within your own environment, which matters for regulated sectors and for data-residency obligations that a hosted-only vendor cannot meet.

Data is encrypted in transit and at rest, with separate encryption keys per customer.

What we have not earned yet

Certifications we do not hold.

VAHI holds no third-party security certifications today. SOC 2 Type II, ISO 27001, and formal DPDP attestation are on our roadmap, in that order. We have not started audit for any of them.

We are stating this plainly because a verification company that overstates its own assurances has no business asking anyone to trust its evidence. If a certification matters to your procurement process, tell us — it affects our sequencing, and we would rather know than guess.

The same applies to accuracy. VAHI is pre-launch. We have not run the volume of real-world verification needed to publish meaningful accuracy figures, so we do not publish any. Any vendor quoting you a match rate should be asked what population it was measured on.

Security questions we have not answered here?

Send them. We would rather have a hard conversation early than a surprised one during procurement.