Verifia
Security & data protection

How Verifia protects the data you verify.

Written for the security reviewers who assess us before a bank, insurer or lender goes live. Every control described here is implemented in the running platform — nothing on this page is a roadmap.

Last reviewed September 2026

Cross-border

Encrypted to the bank that answers.

International checks are carried by iPiD, whose Validate API encrypts all personal data with OpenPGP or RSA. We implement the OpenPGP path. Two independent layers protect a single verification: TLS on the connection, and payload encryption inside it, addressed to the destination institution rather than to the network.

  1. Fetch the destination node's key

    We request the public key of the validation node serving the beneficiary's BIC or country. Routing decides the key, so the payload is encrypted to the institution that will actually answer — not to a shared gateway key.

  2. Encrypt the beneficiary details

    Name, account number or IBAN, creditor agent and any corridor-required national identifier are serialised and OpenPGP-encrypted to that node's key. The request leaving our infrastructure carries an encrypted payload and a node identifier, and nothing else that identifies the account holder.

  3. Validate over TLS

    The call is made over HTTPS from an egress address whitelisted at the network, authenticated with our credentials and bounded by a short timeout.

  4. Decrypt the result locally

    The match score, account status and bank resolution return encrypted to our own key and are decrypted in-process. Our private key never leaves this server — we deliberately do not use the network's decrypt utility, so no third party holds the key that opens our results.

If your standards require something else. The network supports RSA in place of OpenPGP, and bank-specific key arrangements, case by case. Tell us your requirement and we will have it configured on the corridor serving you rather than asking you to accept the default.

The verification network

So your reviewers can assess the far end of the chain, not only ours.

Certification
ISO/IEC 27001, certified by BSIInformation security management certification, published by iPiD.
Scheme status
Pay.UK Certified CoP AggregatorAccredited into the UK Confirmation of Payee scheme, and operating against FATF Recommendation 16, EU Verification of Payee and US NACHA.
Data handling
No-data-storage policy, decentralised routingValidations are routed to the source institution rather than answered from a pooled database of account records, and the terms permit one-time validations only.
Deployment
On-premise or cloud, to your policyThe validation node can be deployed in line with an institution's own security policies and data handling requirements rather than only as a hosted service.
Encryption
OpenPGP or RSA on all personal dataMandated by the Validate API rather than optional, with alternative or additional key arrangements supported for individual banks on request.

Next step

Reviewing us?

Send us your security questionnaire or data processing agreement and we will complete it against the controls above. We can also supply our egress addresses, key fingerprints and certificates for your allowlisting, and arrange direct technical contact with the verification network where a question is theirs to answer.

Reach us through your AnyBanQ contact, who will bring in whoever needs to answer.