Architecture
Controls that hold because of how the platform is built.
Each of these is a property of the storage and verification design rather than a policy promise layered on top of a conventional database.
No central store to breach
Identity data is split into encrypted shards distributed across 60,000+ storage nodes. Reconstructing a record requires 29 of 100 shares, so no single node, operator, or jurisdiction holds a usable copy. There is no honeypot database because there is no database holding whole records.
Zyphe holds no master key
Personal data is encrypted in transit and at rest with AES-GCM-256. Zyphe operates no master key and no backdoor that would decrypt a full record: access happens only inside a verification transaction, with the data subject participating.
Residency enforced by the storage layer
Shards are geo-locked. An EU customer's data stays in the EU, a Swiss customer's stays in Switzerland, a UK customer's stays onshore. Data residency is a property of where the shards live, not a per-market configuration setting that can drift.
Erasure is key revocation, not a ticket
Because the record is held by the data subject rather than copied onto Zyphe servers, a GDPR erasure request is executed by revoking access to the shards. There is no seven-year vendor retention copy left behind to chase.
Assurance
Certifications and frameworks.
The standards Zyphe's information security and compliance programme is held to.
Procurement and security teams can request the current certification documentation at privacy@zyphe.com. Full data handling terms are in the privacy policy.
SOC 2 Type II (in progress)
SOC 2 Type II audit in progress: Type I is targeted for October 2026, with the Type II observation period beginning Q1 2027. SOC 2 Type II tests whether controls operated effectively across an observation period, rather than whether they existed on the day of the audit, which is why the observation window follows the Type I report rather than running alongside it.
ISO/IEC 27001 (in progress)
ISO/IEC 27001 certification in progress: Stage 1 is targeted for October 2026 and Stage 2 for November to December 2026. ISO/IEC 27001 is the international standard for running an information security management system, covering risk assessment, controls, and continual review. Stage 1 reviews the documented system, Stage 2 tests that it operates.
GDPR
GDPR-compliant data handling, with regionalised storage that avoids routine cross-border transfer of personal data.
AMLA / AMLR
Operating model aligned to the EU anti-money laundering regulation, including the Article 18 division of responsibility between provider and obliged entity.
Oversight
Who is accountable when an agent works a case.
Autonomy stops where the law puts the decision. These boundaries are why an agent-prepared file is defensible in a supervisory exam.
Agents prepare. Your team approves.
Every case arrives as a decision-ready file with the reasoning attached. A named reviewer approves it or sends it back. Agents do not make final KYC, KYB, or AML decisions.
Six decisions never leave your side of the line.
AMLR Article 18(3) reserves six categories of decision to the obliged entity, including the customer risk profile, the decision to enter a business relationship, and reporting to the FIU. Those stay with your MLRO by design, not by exception.
GDPR Article 22 is a design constraint.
Decisions based solely on automated processing that produce legal or similarly significant effects on a person are constrained by law. This is why the human approval step is structural rather than optional.
Every decision carries its rationale.
Each output logs the sources reviewed, the reasoning applied, and the action taken, as a per-decision audit trail for internal QA and supervisory exams. AMLR Article 18(2) requires you to be able to demonstrate that rationale to your supervisor.
Data handling
Where data lives, what is kept, and how it is deleted.
The answers to the diligence questions buyers ask most, stated once and restating the DPA.
Where data is processed and stored
Storage is regional by design. Data belonging to EEA and UK end users is processed and stored on EEA and UK nodes and cloud regions; data belonging to US end users stays in US regions. The region follows the end user's location rather than a setting the customer picks, so a customer with users in several regions gets residency for each without configuring it.
What Zyphe retains, and for how long
Identity documents and biometrics are processed transiently, then encrypted with AES-256, sharded and stored in the end user's vault. Zyphe retains verification results, audit logs and cryptographic proofs for the term of the agreement or as required by law. Screening identifiers are kept only while ongoing monitoring is switched on for that customer.
How deletion works
A deletion request is checked against every recipient's retention obligations. Access that is no longer needed is revoked at once, a daily job deletes data as obligations lapse, and the user receives a completion notice. Biometric data is destroyed within the limits set by BIPA and CUBI, as recorded in section 10.3 of the DPA.
Sub-processors and in-house processing
Liveness, face matching and injection-attack detection run in-house rather than through a third-party biometric vendor, which is one fewer sub-processor in your data map. The current sub-processor list, including the register-data supplier used for business verification, is in Annex III of the DPA and is available on request.
Operations
Controls on the infrastructure itself.
- Granular role-based access control and strict authentication on every system interaction.
- Zyphe employees and contractors have no direct access to customer personal data.
- Firewalls, intrusion detection, and continuous network monitoring across the infrastructure.
- Secure coding practices and regular penetration testing; the current test schedule and the most recent report are available to customers under NDA.
- No reported breach of identity data to date. Zyphe maintains the industry KYC and IDV breach tracker at /resources/blog/kyc-idv-breach-tracker, and does not appear on it.
- A documented incident response plan, with notification to affected parties as required by law.
Security questions, answered
The questions security reviews and procurement questionnaires ask most often.
Zyphe keeps no reconstructable customer PII at rest. Identity data is encrypted and split into shards across 60,000+ distributed storage nodes, and reconstruction requires 29 of 100 shares, so no single node or jurisdiction holds a usable record. Shards are geo-locked to the customer's region.
Not yet, and we would rather say so than have you find out during your own audit. SOC 2 Type II audit in progress: Type I is targeted for October 2026, with the Type II observation period beginning Q1 2027. ISO/IEC 27001 certification in progress: Stage 1 is targeted for October 2026 and Stage 2 for November to December 2026. Zyphe does maintain GDPR-compliant data handling today and aligns its operating model to the EU anti-money laundering regulation. For the current status of either audit, or the control documentation behind it, contact privacy@zyphe.com.
No. Agents prepare each case as a decision-ready file with the reasoning attached, and a named member of your team approves it. AMLR Article 18(3) reserves six categories of decision to the obliged entity, and GDPR Article 22 constrains decisions based solely on automated processing, so human approval is structural rather than a configurable option.
Residency is enforced at the storage layer rather than by configuration. Encrypted shards are geo-locked, so an EU customer's data remains in the EU or EEA, a Swiss customer's in Switzerland, and a UK customer's onshore. A multi-jurisdiction platform does not have to configure residency per market.
Because the record is held by the data subject rather than duplicated onto Zyphe servers, erasure is executed by revoking access to the shards. Any minimal residual data Zyphe holds, such as encrypted log identifiers, is erased on request to the extent possible.
Regionally, following the end user's location: EEA and UK data on EEA and UK nodes and cloud regions, US data in US regions. Documents and biometrics are processed transiently and stored encrypted in the end user's own vault; Zyphe retains only verification results, audit logs and cryptographic proofs.
Verification results, audit logs and cryptographic proofs, for the term of the agreement or as required by law. Screening identifiers are kept only while ongoing monitoring is on. The identity documents and biometrics themselves are not held by Zyphe; they sit encrypted in the end user's vault.
No breach of identity data has been reported. Zyphe maintains the industry KYC and IDV breach tracker and is not on it. The architecture is designed so that a breach of Zyphe could not expose a full identity record, because Zyphe does not hold one.
Data protection questions, data subject rights requests, and certification documentation: privacy@zyphe.com. General or commercial security questions: hello@zyphe.com.
Book a demo
Bring your security review to the demo.
Book a demo and bring your questionnaire. We will walk the architecture, the audit trail, and the approval boundary against your own controls.