Encryption in transit & at rest
All traffic is served over TLS. Credential payloads and personally identifiable data are encrypted at rest by our infrastructure provider.
Security & Trust
This page is maintained by Citycom Digital Stars Limited to summarise the security controls that are currently enabled on the Verify.ug platform. It is not an independent certification.
All traffic is served over TLS. Credential payloads and personally identifiable data are encrypted at rest by our infrastructure provider.
Every institution has its own admins, staff and verifier roles. Access is scoped by role and audited on every mutation.
The database enforces isolation at the row level — a member of one institution can never read another's records, even through the public API.
Every credential issued, revoked, verified or shared writes an append-only audit record. Logs cannot be deleted or altered.
Every verification is scored for authenticity, duplication and fraud risk using our explainable AI Trust Engine.
MFA is available for institution admins. Google-verified sign-in is enabled by default.
Verify.ug never owns institutional records. Institutions remain the source of truth; the platform stores only what is required to verify.
HSTS, strict CSP, X-Frame-Options, X-Content-Type-Options and Referrer-Policy are enforced on every response.
Verify.ug provides the platform, infrastructure and cryptographic verification network. Institutions remain responsible for the accuracy of the records they issue and for the day-to-day management of their staff accounts and permissions.
Compliance-specific claims (SOC 2, ISO 27001, GDPR, HIPAA, PCI) can be shared under NDA where applicable. Contact us for the current documentation.
Found something? We investigate every report and respond within 72 hours.
security@verify.ug