Skip to content
Trust & compliance

Trust is the product.

Othento verifies identity for regulated businesses — so security, privacy and compliance are not features, they are the foundation. Here is exactly how we protect your customers’ data.

AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
DIFC / ADGM
Data residency options
0
Customer data sold, ever
Certifications & frameworks

Where we stand, stated plainly.

We would rather be precise than impressive. Each item below shows whether a certification is formally held, in audit, or a framework our practices are designed to meet.

SOC 2 Type II

In audit

Controls for security, availability and confidentiality. Independent audit underway.

ISO/IEC 27001

In audit

Information-security management system built to the ISO 27001 standard.

ISO/IEC 30107-3 (PAD)

Aligned

Presentation-attack detection for liveness, designed to the iBeta / ISO 30107-3 bar.

GDPR

Aligned

Data-protection practices aligned with GDPR principles for EU and global users.

eIDAS 2.0

Aligned

Designed to support the EU eIDAS 2.0 framework for electronic identity.

UAE PASS & CBUAE

Aligned

UAE PASS ready and designed to support CBUAE and AML/CFT expectations.

“Aligned” means our controls are designed to meet the framework; it is not a claim of formal certification. This page is updated as audits complete.

Data protection

Your customers’ data, protected by design.

Personal and biometric data is encrypted, isolated and minimised — and never leaves our control to be sold or shared.

  • Encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Biometric and document data are captured and uploaded directly to Othento — they never cross the host page or your servers
  • Data residency options in DIFC / ADGM and the wider region
  • Configurable retention and deletion to match your policy
  • We never sell customer data or use it to train third-party models
Regional compliance

Built in the UAE, for the UAE.

Coverage and controls are tuned for the GCC market, with the residency and recordkeeping local regulators expect.

  • UAE PASS ready, with Emirates ID and NFC chip verification
  • Designed to support CBUAE and AML/CFT customer due-diligence expectations
  • In-region data residency (DIFC / ADGM)
  • Designed to support VARA, MiCA and FATF expectations for digital assets
  • Exportable, immutable decision logs for your regulators
Security practices

Security baked into how we build.

From code to cloud, our engineering practices are designed to keep verification trustworthy at scale.

  • Least-privilege access and role-based controls for all systems
  • Encryption everywhere, with managed keys and secrets
  • Secure SDLC with code review and dependency scanning
  • Regular security testing and third-party penetration tests
  • Continuous monitoring with an incident-response process
Documentation

Need our security pack?

Security documentation, sub-processor lists and a data-processing agreement are available to customers and prospects under NDA. Reach out and we will share the current pack.

FAQ

Questions, answered.

We present our posture honestly: SOC 2 Type II and ISO/IEC 27001 audits are in progress, and our practices are aligned with GDPR, eIDAS 2.0, ISO/IEC 30107-3 (liveness PAD) and CBUAE expectations. This page is updated as formal attestations are completed.

Get started

Verify with confidence.

See how Othento protects identity data while keeping onboarding fast.