Trust is the product.
Othento verifies identity for regulated businesses — so security, privacy and compliance are not features, they are the foundation. Here is exactly how we protect your customers’ data.
Where we stand, stated plainly.
We would rather be precise than impressive. Each item below shows whether a certification is formally held, in audit, or a framework our practices are designed to meet.
SOC 2 Type II
In auditControls for security, availability and confidentiality. Independent audit underway.
ISO/IEC 27001
In auditInformation-security management system built to the ISO 27001 standard.
ISO/IEC 30107-3 (PAD)
AlignedPresentation-attack detection for liveness, designed to the iBeta / ISO 30107-3 bar.
GDPR
AlignedData-protection practices aligned with GDPR principles for EU and global users.
eIDAS 2.0
AlignedDesigned to support the EU eIDAS 2.0 framework for electronic identity.
UAE PASS & CBUAE
AlignedUAE PASS ready and designed to support CBUAE and AML/CFT expectations.
“Aligned” means our controls are designed to meet the framework; it is not a claim of formal certification. This page is updated as audits complete.
Your customers’ data, protected by design.
Personal and biometric data is encrypted, isolated and minimised — and never leaves our control to be sold or shared.
- Encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Biometric and document data are captured and uploaded directly to Othento — they never cross the host page or your servers
- Data residency options in DIFC / ADGM and the wider region
- Configurable retention and deletion to match your policy
- We never sell customer data or use it to train third-party models
Built in the UAE, for the UAE.
Coverage and controls are tuned for the GCC market, with the residency and recordkeeping local regulators expect.
- UAE PASS ready, with Emirates ID and NFC chip verification
- Designed to support CBUAE and AML/CFT customer due-diligence expectations
- In-region data residency (DIFC / ADGM)
- Designed to support VARA, MiCA and FATF expectations for digital assets
- Exportable, immutable decision logs for your regulators
Security baked into how we build.
From code to cloud, our engineering practices are designed to keep verification trustworthy at scale.
- Least-privilege access and role-based controls for all systems
- Encryption everywhere, with managed keys and secrets
- Secure SDLC with code review and dependency scanning
- Regular security testing and third-party penetration tests
- Continuous monitoring with an incident-response process
Need our security pack?
Security documentation, sub-processor lists and a data-processing agreement are available to customers and prospects under NDA. Reach out and we will share the current pack.
Questions, answered.
We present our posture honestly: SOC 2 Type II and ISO/IEC 27001 audits are in progress, and our practices are aligned with GDPR, eIDAS 2.0, ISO/IEC 30107-3 (liveness PAD) and CBUAE expectations. This page is updated as formal attestations are completed.
Verify with confidence.
See how Othento protects identity data while keeping onboarding fast.