Compliance
Review ComplyCube compliance certifications, security controls, data processing, and privacy standards for identity verification, KYC, KYB, and AML.
Overview
ComplyCube helps regulated businesses meet identity verification, KYC, KYB, AML, and fraud prevention requirements through one platform.
This page outlines ComplyCube compliance certifications, security controls, data processing practices, and privacy coverage.
For current documentation and evidence, visit the ComplyCube Trust Center.
Compliance certifications and frameworks
ComplyCube maintains and supports the following certifications, standards, and privacy frameworks:
ISO 27001:2022
Information security management.
ISO 9001:2015
Quality management systems.
UK Cyber Essentials
Baseline cybersecurity controls.
UK DIATF
UK Digital Identity and Attributes Trust Framework alignment.
ISO 30107-3
Presentation attack detection testing.
ACCS 4:2020
Technical requirements for age check systems.
GDPR
EU data protection and privacy requirements.
CCPA
California privacy requirements.
Security control areas
ComplyCube publishes controls across the following domains:
Infrastructure security
Privileged access restrictions, MFA, secure authentication, and network access controls.
Organizational security
Asset disposal, anti-malware, confidentiality agreements, password policy, and employee controls.
Product security
Encryption at rest, control self-assessments, and penetration testing.
Internal security procedures
BC/DR planning, secure development lifecycle, whistleblower processes, and governance oversight.
Data and privacy
Data classification, retention, and customer data deletion procedures.
Data processing and privacy
ComplyCube applies the following data handling practices across verification and compliance workflows:
Data minimization
Only data needed for the configured verification flow is collected and processed.
Processing and residency
Processing and storage follow the region selected for your account and use case. For regional handling and storage options, see Data Residency.
Retention
Retention periods can be configured, with deletion workflows to support regulatory and business requirements.
Subprocessors
Subprocessors are documented and bound by appropriate security and data protection obligations.
Data subject requests
Privacy requests are handled through documented processes, including export and deletion workflows where applicable.
Audit trail
Every action and verification produces a detailed evidence trail that helps organizations understand how decisions are made and demonstrate compliance when needed.
Depending on the verification type, the available evidence may include:
Verification events and processing timeline.
Identity document images and extracted data.
Biometric verification results, including liveness and face match outcomes.
AML screening findings and verification outcomes.
Reviewer actions and decision history, where applicable.
Downloadable reports and supporting evidence.
All evidence is securely retained and governed by configurable access permissions and retention settings, helping organizations meet internal governance and regulatory requirements.
Security measures
ComplyCube protects customer data through multiple layers of technical, operational, and organizational security controls.
Depending on your deployment and configuration, these safeguards include:
Encryption for data in transit and at rest.
Secure key management and tightly controlled access to sensitive systems.
Signed webhooks, IP allowlists, and network security controls.
Continuous vulnerability assessments and regular penetration testing.
Business continuity, disaster recovery, and incident response processes.
Together, these measures help protect sensitive information, maintain platform resilience, and support industry security and compliance requirements.
Last updated
Was this helpful?

