Learn more about the latest security and privacy threats

Security and trust

The strongest control we have is not holding your customers' PII.

Most identity vendors secure a central store of personal data. Zyphe does not have one. This page sets out how that works, what Zyphe is certified against, how agent decisions stay accountable to your team, and who to contact for documentation.

Architecture

Controls that hold because of how the platform is built.

Each of these is a property of the storage and verification design rather than a policy promise layered on top of a conventional database.

No central store to breach

Identity data is split into encrypted shards distributed across 60,000+ storage nodes. Reconstructing a record requires 29 of 100 shares, so no single node, operator, or jurisdiction holds a usable copy. There is no honeypot database because there is no database holding whole records.

Zyphe holds no master key

Personal data is encrypted in transit and at rest with AES-GCM-256. Zyphe operates no master key and no backdoor that would decrypt a full record: access happens only inside a verification transaction, with the data subject participating.

Residency enforced by the storage layer

Shards are geo-locked. An EU customer's data stays in the EU, a Swiss customer's stays in Switzerland, a UK customer's stays onshore. Data residency is a property of where the shards live, not a per-market configuration setting that can drift.

Erasure is key revocation, not a ticket

Because the record is held by the data subject rather than copied onto Zyphe servers, a GDPR erasure request is executed by revoking access to the shards. There is no seven-year vendor retention copy left behind to chase.

Assurance

Certifications and frameworks.

The standards Zyphe's information security and compliance programme is held to.

Procurement and security teams can request the current certification documentation at privacy@zyphe.com. Full data handling terms are in the privacy policy.

SOC 2 Type II

SOC 2 Type II audited. SOC 2 Type II tests whether controls operated effectively across an observation period, rather than whether they existed on the day of the audit.

ISO/IEC 27001

ISO/IEC 27001 certified. ISO/IEC 27001 is the international standard for running an information security management system, covering risk assessment, controls, and continual review.

GDPR

GDPR-compliant data handling, with regionalised storage that avoids routine cross-border transfer of personal data.

AMLA / AMLR

Operating model aligned to the EU anti-money laundering regulation, including the Article 18 division of responsibility between provider and obliged entity.

Oversight

Who is accountable when an agent works a case.

Autonomy stops where the law puts the decision. These boundaries are why an agent-prepared file is defensible in a supervisory exam.

Agents prepare. Your team approves.

Every case arrives as a decision-ready file with the reasoning attached. A named reviewer approves it or sends it back. Agents do not make final KYC, KYB, or AML decisions.

Six decisions never leave your side of the line.

AMLR Article 18(3) reserves six categories of decision to the obliged entity, including the customer risk profile, the decision to enter a business relationship, and reporting to the FIU. Those stay with your MLRO by design, not by exception.

GDPR Article 22 is a design constraint.

Decisions based solely on automated processing that produce legal or similarly significant effects on a person are constrained by law. This is why the human approval step is structural rather than optional.

Every decision carries its rationale.

Each output logs the sources reviewed, the reasoning applied, and the action taken, as a per-decision audit trail for internal QA and supervisory exams. AMLR Article 18(2) requires you to be able to demonstrate that rationale to your supervisor.

Operations

Controls on the infrastructure itself.

  • Granular role-based access control and strict authentication on every system interaction.
  • Zyphe employees and contractors have no direct access to customer personal data.
  • Firewalls, intrusion detection, and continuous network monitoring across the infrastructure.
  • Secure coding practices and regular penetration testing.
  • A documented incident response plan, with notification to affected parties as required by law.

Security questions, answered

The questions security reviews and procurement questionnaires ask most often.

Zyphe keeps no reconstructable customer PII at rest. Identity data is encrypted and split into shards across 60,000+ distributed storage nodes, and reconstruction requires 29 of 100 shares, so no single node or jurisdiction holds a usable record. Shards are geo-locked to the customer's region.

SOC 2 Type II audited. ISO/IEC 27001 certified. Zyphe also maintains GDPR-compliant data handling and aligns its operating model to the EU anti-money laundering regulation. Request the current certification documentation at privacy@zyphe.com.

No. Agents prepare each case as a decision-ready file with the reasoning attached, and a named member of your team approves it. AMLR Article 18(3) reserves six categories of decision to the obliged entity, and GDPR Article 22 constrains decisions based solely on automated processing, so human approval is structural rather than a configurable option.

Residency is enforced at the storage layer rather than by configuration. Encrypted shards are geo-locked, so an EU customer's data remains in the EU or EEA, a Swiss customer's in Switzerland, and a UK customer's onshore. A multi-jurisdiction platform does not have to configure residency per market.

Because the record is held by the data subject rather than duplicated onto Zyphe servers, erasure is executed by revoking access to the shards. Any minimal residual data Zyphe holds, such as encrypted log identifiers, is erased on request to the extent possible.

Data protection questions, data subject rights requests, and certification documentation: privacy@zyphe.com. General or commercial security questions: hello@zyphe.com.

Book a demo

Bring your security review to the demo.

Book a demo and bring your questionnaire. We will walk the architecture, the audit trail, and the approval boundary against your own controls.