Security & Trust

Security is the product.

This page is maintained by Citycom Digital Stars Limited to summarise the security controls that are currently enabled on the Verify.ug platform. It is not an independent certification.

Encryption in transit & at rest

All traffic is served over TLS. Credential payloads and personally identifiable data are encrypted at rest by our infrastructure provider.

Role-based access control

Every institution has its own admins, staff and verifier roles. Access is scoped by role and audited on every mutation.

Row-level security

The database enforces isolation at the row level — a member of one institution can never read another's records, even through the public API.

Immutable audit logs

Every credential issued, revoked, verified or shared writes an append-only audit record. Logs cannot be deleted or altered.

AI Trust Engine

Every verification is scored for authenticity, duplication and fraud risk using our explainable AI Trust Engine.

Multi-factor authentication

MFA is available for institution admins. Google-verified sign-in is enabled by default.

Data minimization

Verify.ug never owns institutional records. Institutions remain the source of truth; the platform stores only what is required to verify.

Enterprise security headers

HSTS, strict CSP, X-Frame-Options, X-Content-Type-Options and Referrer-Policy are enforced on every response.

Shared responsibility

Verify.ug provides the platform, infrastructure and cryptographic verification network. Institutions remain responsible for the accuracy of the records they issue and for the day-to-day management of their staff accounts and permissions.

Compliance-specific claims (SOC 2, ISO 27001, GDPR, HIPAA, PCI) can be shared under NDA where applicable. Contact us for the current documentation.

Responsible disclosure

Found something? We investigate every report and respond within 72 hours.

security@verify.ug