Overview Compliance Controls Security program Availability Policy library Privacy Sub-processors Updates WeVerify.com ↗
ISO 27001Documentation ready
ETSIDocumentation ready
GDPRPrivacy by design
eIDAS 2Aligned
NIS2Mapped
93+ policiesAnnex A covered
Service statusView status page ↗
Security · Compliance · Transparency

Trust is not a feature.
It is the foundation of WeVerify.

Welcome to the WeVerify Trust Center. This page gives customers, auditors and partners a transparent view of how WeVerify protects identity, signature and verification workflows across people, processes, technology and suppliers.

  • ISO 27001 documentation ready
  • ETSI documentation ready
  • GDPR by design
  • eIDAS 2 aligned
  • NIS2 mapped
  • Audit-ready evidence
Overview

Designed for regulated digital trust workflows

WeVerify brings identity verification, business verification, authority checks, sanctions and PEP screening, customer due diligence, document generation and electronic signing into one secure platform. Our trust program is built to support customer due diligence, auditability, resilience and compliance across high-assurance digital transactions.

ID

Identity assurance

Controls for secure onboarding, reusable identity data, consent-based disclosure and robust evidence packages for verification decisions.

QS

Signature assurance

Governance and technical documentation supporting electronic signature and trust service workflows under ETSI-aligned requirements.

KYB

Business verification

Processes for entity verification, representative authority checks, mandate validation and secure evidence retention for regulated workflows.

API

Secure integrations

API-first controls covering authentication, logging, monitoring, secure development and customer-controlled data exchange with audit trails.

Compliance

Compliance and assurance coverage

WeVerify maintains documentation across six compliance domains. Access to non-public materials may require a corporate email address, NDA and internal approval.

Documentation ready

ISO/IEC 27001

Full information security management documentation: 93+ policies, Annex A control mapping, Statement of Applicability, internal audit evidence and management review records. All four Annex A domains covered: A.5 Organizational (37 controls), A.6 People (8), A.7 Physical (14), A.8 Technological (34).

Documentation ready

ETSI

Trust service policy documentation, operational procedures, certificate lifecycle evidence, governance records and assessment support materials for electronic signature and seal services under eIDAS requirements.

Implemented

GDPR

Privacy-by-design controls, data minimisation, purpose limitation, processor support agreements, data subject rights workflows, retention governance, DPIA support and personal data breach notification procedure aligned to Articles 33 and 34.

Supported

eIDAS / eIDAS 2 readiness

Assurance documentation for electronic identification, electronic signatures, electronic seals, audit trails and trust-service related workflows including EUDI Wallet interoperability preparation.

Mapped

NIS2 and operational resilience

Security governance, supply chain oversight, incident response and reporting, business continuity, ICT continuity testing, vulnerability management and risk monitoring controls aligned to NIS2 essential entity requirements.

Customer due diligence

KYC, KYB and AML support

Evidence packages, verification reports and auditable workflows to support regulated customer onboarding and compliance operations suitable for AMLD6, PSD2, DORA and sector-specific requirements.

ISO 27001 Controls

Security control domains

WeVerify's ISO 27001 control library covers all four Annex A domains. Select a tab to explore the controls implemented across organizational, people, physical and technological security.

A.5 Organizational controls

Governance, risk management, policy framework, asset management, access control, supplier relationships, incident management, business continuity and legal compliance.

A.5.1
Policies for information security
Information Security Policy, Social Media Policy, HR Security Policy, Asset Management Policy, Acceptable Use Policy, Internet/Messaging/Collaboration Policies, Access Control Policy, Cryptographic Policy, Physical Security Policy, Anti-Malware Policy, Threat Intelligence Policy, Cloud Services Policy, Mobile Device and BYOD Policy, Remote Working Policy.
A.5.2
Information security roles and responsibilities
Defined roles and authority matrix; Information Security Roles, Responsibilities and Authorities document maintained and reviewed.
A.5.3
Segregation of duties
Segregation of Duties Guidelines prevent conflicts of interest in sensitive roles and system access rights.
A.5.4
Management responsibilities
Executive Support Letter, Whistleblowing Policy and management obligation to enforce information security requirements at all levels.
A.5.5
Contact with authorities
Maintained register of relevant authority contacts for incident escalation, regulatory reporting and legal liaison.
A.5.7
Threat intelligence
Threat Intelligence Policy, Process and periodic Reports covering threat actors, vulnerabilities and industry developments.
A.5.9
Inventory of information assets
Asset Management Policy and Information Asset Inventory covering all information assets, owners and classifications with PII tagging.
A.5.10
Acceptable use of assets
Acceptable Use Policy, Internet Access Policy, Electronic Messaging Policy, Online Collaboration Policy, Asset Handling Procedure, Procedure for Managing Lost or Stolen Devices.
A.5.12–14
Classification, labelling and transfer
Information Classification Procedure, Information Labelling Procedure, Information Transfer Procedure and Transfer Agreement template covering handling at each classification level.
A.5.15–18
Access control and identity management
Access Control Policy, User Access Management Process covering provisioning, periodic review, MFA enforcement and timely deprovisioning across all systems.
A.5.19–23
Supplier and cloud security
Information Security Policy for Supplier Relationships, Supplier Information Security Agreement, Due Diligence Assessment Procedure, Evaluation Process and Questionnaire. Cloud Services Policy, Process and Specifications for approved cloud providers.
A.5.24–27
Incident management
Incident Response Plans for Ransomware, Denial of Service and Data Breach; Information Security Event Assessment Procedure; Incident Response Procedure with defined roles, evidence preservation and post-incident review.
A.5.30
ICT readiness for business continuity
Business Impact Analysis Process and Report, ICT Continuity Plan, Exercising and Testing Schedule, ICT Continuity Test Plan and Test Report; tested at defined intervals.
A.5.31–34
Legal, privacy and records
Legal and Regulatory Requirements Procedure and Register, IP and Copyright Compliance Policy, Records Retention and Protection Policy, Privacy and Personal Data Protection Policy, Personal Data Breach Notification Procedure.
A.5.35–37
Audit, compliance and operations
Information Systems Audit Plan, Nonconformity and Corrective Action process, Information Security Summary Card and Operating Procedure ensuring systematic compliance enforcement and continual improvement.

A.6 People controls

Pre-employment screening, terms and conditions, disciplinary processes, confidentiality obligations, remote work and security event reporting.

A.6.1
Screening
Employee Screening Procedure covering identity verification, background checks and reference validation before employment commencement, proportionate to role sensitivity.
A.6.2
Terms and conditions of employment
Guidelines for Inclusion in Employment Contracts specifying information security obligations, confidentiality requirements and acceptable use terms.
A.6.3
Information security awareness, education and training
Awareness Training Presentation, Competence Development Procedure, Email and Passwords Awareness Posters; mandatory for all staff, tracked with Competence Development Report.
A.6.4
Disciplinary process
Employee Disciplinary Process covering information security policy violations with proportionate consequences, escalation path and documentation requirements.
A.6.5
Responsibilities after termination
Joiner-mover-leaver process includes NDA obligations, asset return, access revocation and post-employment confidentiality enforcement.
A.6.6
Confidentiality and non-disclosure agreements
Schedule of Confidentiality Agreements and Non-Disclosure Agreement template used with all employees, contractors and third parties with access to sensitive information.
A.6.7
Remote working
Remote Working Policy covering secure remote access, endpoint protection, screen privacy, home network security and incident reporting when working outside office premises.
A.6.8
Information security event reporting
Information Security Event Reporting Procedure enabling all personnel to report suspected or actual security events; integrated with event assessment and incident response chain.

A.7 Physical controls

Physical perimeter security, secure area access, equipment protection, media handling and disposal controls.

A.7.1
Physical security perimeters
Physical Security Policy and Physical Security Design Standards define perimeter controls for offices and data processing facilities including access barriers and surveillance.
A.7.2
Physical entry controls
Data Centre Access Procedure and Physical Security Design Standards govern visitor registration, badge access, escort requirements and access log maintenance.
A.7.4
Physical security monitoring
CCTV Policy governing camera placement, recording retention, access to footage and data subject rights compliance under GDPR.
A.7.6
Working in secure areas
Procedure for Working in Secure Areas defines activity restrictions, visitor supervision and clean-desk requirements within sensitive zones.
A.7.7
Clear desk and clear screen
Clear Desk and Clear Screen Policy mandating information-free workstations when unattended, locked screens and secure document storage.
A.7.9
Security of assets off-premises
Procedure for Taking Assets Offsite covering authorisation, transport security, remote access and reporting requirements for equipment used outside office premises.
A.7.10
Storage media
Procedure for Managing Removable Media, Physical Media Transfer Procedure and encryption requirements for all portable storage devices containing sensitive information.
A.7.11–13
Supporting utilities, cabling and maintenance
ICT Continuity Plan addresses power supply redundancy, UPS requirements and structured cabling standards. Availability Management Policy governs equipment maintenance scheduling and security during maintenance windows.
A.7.14
Secure disposal or re-use of equipment
Procedure for the Disposal of Media and Information Deletion Policy govern secure erasure, degaussing and physical destruction of media and equipment before disposal or re-use.

A.8 Technological controls

Endpoint security, access management, vulnerability management, configuration, data protection, logging, network security and cryptography.

A.8.1
User endpoint devices
Mobile Device Policy and BYOD Policy covering MDM enrollment, encryption, remote wipe, application controls and acceptable use for corporate and personal devices.
A.8.2–3
Privileged access and access restriction
Privileged Utility Program Register, User Access Management Process and Dynamic Access Control Policy govern assignment, review, logging and attribute-based access restrictions.
A.8.5
Secure authentication
Multi-factor authentication enforced for all remote access and privileged systems; authentication requirements embedded in Access Control Policy.
A.8.6
Capacity management
Capacity Plan covering compute, storage and network thresholds with monitoring alerts and scaling procedures to maintain availability SLAs.
A.8.7
Protection against malware
Anti-Malware Policy covering endpoint protection deployment, update cadence, scan scheduling, quarantine procedures and incident escalation paths.
A.8.8
Management of technical vulnerabilities
Technical Vulnerability Management Policy and Vulnerability Assessment Procedure covering CVE monitoring, patch prioritisation with SLA-based remediation and penetration test integration.
A.8.9
Configuration management
Configuration Management Policy, Process and Standard Templates ensure consistent, hardened and auditable system configurations across all environments.
A.8.10–12
Data deletion, masking and leakage prevention
Information Deletion Policy, Data Masking Policy and Process, Data Leakage Prevention Policy covering secure deletion standards, pseudonymisation techniques and DLP tooling for all environments.
A.8.13–14
Backup and availability
Backup Policy defining scope, frequency, encryption, offsite storage and restoration testing. Availability Management Policy and ICT Continuity Plan cover multi-zone deployment, failover and RTO/RPO targets.
A.8.15–16
Logging and monitoring
Logging and Monitoring Policy defining mandatory log types, retention periods, integrity protection and SIEM integration. Monitoring Policy covering continuous infrastructure monitoring, anomaly detection and on-call response.
A.8.19–23
Software, networks and web security
Software Policy, Network Security Policy, Network Services Agreement, Web Filtering Policy governing approved software, network segmentation, DMZ design, firewall rules and URL filtering.
A.8.24
Use of cryptography
Cryptographic Policy defining approved algorithms, key lengths, key management, certificate lifecycle and prohibited cipher suites for all data in transit and at rest.
A.8.25–31
Secure development lifecycle
Security requirements embedded in SDLC: threat modelling, code review, SAST/DAST scanning, OWASP Top 10 coverage, environment separation enforced in infrastructure and security sign-off gates for all production releases.
A.8.32
Change management
Change Management Process covering request, risk assessment, approval, testing, rollback planning and post-change review for all infrastructure and application changes.
Security program

How we protect your data and workflows

WeVerify operates a defence-in-depth security program covering encryption, access management, secure development, vulnerability management and independent testing. The program is governed by the ISMS and reviewed annually by senior management.

ENC

Encryption

All personal data and verification payloads are encrypted at rest using AES-256. All data in transit is protected using TLS 1.2 or higher with approved cipher suites. Key management, algorithm selection and prohibited ciphers are governed by the Cryptographic Policy.

IAM

Access management

Multi-factor authentication is enforced for all remote access and privileged systems. Access is provisioned on a least-privilege basis with role-based controls, periodic access reviews and automated deprovisioning on role change or departure. Privileged access is logged and monitored.

SDL

Secure development lifecycle

Security requirements are embedded throughout the SDLC. Threat modelling, static application security testing (SAST), peer code review, dependency scanning and OWASP Top 10 coverage are applied before any production release. Production, staging and development environments are strictly separated. All releases require a security sign-off gate.

CHG

Change management

All infrastructure and application changes follow the Change Management Process: request, risk assessment, approval, testing, rollback planning and post-change review. Emergency changes are subject to retrospective review. Unauthorised or ad-hoc changes are prohibited in production.

VUL

Vulnerability management

Automated vulnerability scanning runs continuously across infrastructure and application layers. Critical and high-severity findings are remediated within defined SLAs. The Technical Vulnerability Management Policy and Vulnerability Assessment Procedure govern scan scope, finding triage, patch prioritisation and exception handling.

PEN

Penetration testing

WeVerify commissions independent third-party penetration tests at least annually. Tests cover application, API, network and infrastructure scope using OWASP and PTES methodologies. Findings are tracked through to remediation. Summary test scope and remediation status are available to customers under NDA on request via security@weverify.com.

VDP

Responsible disclosure

WeVerify operates a responsible disclosure programme. If you discover a potential security vulnerability in any WeVerify product or infrastructure, please report it to security@weverify.com with a description, reproduction steps and potential impact. We acknowledge reports within 5 business days and aim to resolve confirmed vulnerabilities within 90 days. We ask researchers to avoid data access, service disruption or disclosure to third parties during investigation.

MON

Logging and monitoring

All production systems generate security-relevant logs covering authentication events, access to personal data, configuration changes and system errors. Logs are protected against tampering, retained for defined periods under the Logging and Monitoring Policy, and integrated into continuous monitoring. On-call procedures ensure 24/7 alerting for critical events.

THR

Threat intelligence

WeVerify operates a Threat Intelligence Policy and Process covering monitoring of threat actor activity, CVE feeds, industry advisories and sector-specific intelligence sources relevant to identity verification and digital signing. Findings feed directly into vulnerability management prioritisation and risk assessment updates.

EPT

Endpoint and device security

Mobile Device Policy and BYOD Policy govern device enrollment, encryption, remote wipe capability and application controls. Anti-Malware Policy requires endpoint protection on all managed devices with defined update cadence and incident escalation. Clear Desk and Clear Screen Policy applies across all office locations.

Law enforcement requests

WeVerify responds to lawful requests from law enforcement and competent authorities in accordance with applicable law. Requests must be submitted in writing with legal basis to compliance@weverify.com. WeVerify will notify affected customers of requests unless prohibited by law or court order. We reserve the right to challenge requests that are overly broad, unlawful or disproportionate.

Security contact

For security incidents, suspected vulnerabilities or urgent security concerns: security@weverify.com. For compliance and audit requests: compliance@weverify.com. For privacy matters: privacy@weverify.com.

Availability & resilience

Infrastructure resilience and continuity

WeVerify's platform is built on EU-based cloud infrastructure with multi-zone redundancy, automated failover and formally tested business continuity and ICT continuity plans. Availability is monitored continuously with defined on-call escalation paths.

EU data residency

All personal data processed and stored within the European Economic Area. Data residency is enforced at infrastructure level. No personal data is transferred outside the EEA without a lawful transfer mechanism in place.

EEA only

Multi-zone deployment

Production workloads are deployed across multiple availability zones within the EU. Automated health checks, load balancing and failover ensure continuity in the event of zone-level disruption without requiring manual intervention.

Active redundancy

Backup and recovery

The Backup Policy defines scope, frequency, encryption, offsite storage requirements and restoration test schedules. Backups are encrypted and stored separately from primary systems. Recovery procedures are tested at defined intervals against documented RTO and RPO targets.

Tested & encrypted

ICT continuity

WeVerify maintains an ICT Continuity Plan aligned to ISO 27001 A.5.30, covering critical system identification, recovery priorities, escalation chains and alternative processing arrangements. The plan is exercised annually and updated following each test.

Exercised annually

Business impact analysis

A formal Business Impact Analysis identifies critical processes, acceptable recovery time objectives and dependencies. Findings drive continuity planning priorities and are reviewed as part of the annual management review cycle.

ISO 27001 A.5.30

Capacity management

The Capacity Plan sets thresholds for compute, storage and network resources with automated alerts and scaling procedures. Capacity is reviewed regularly to ensure availability SLAs can be maintained under peak load and growth scenarios.

Auto-scaling
Service status View live status ↗
Maintenance notices Published on status page with advance notice
Monitoring 24/7 automated alerting with on-call escalation
Data residency EU / EEA only
Document IDPolicy / ProcedureStandard area
Core ISMS — Clauses 4 to 10
ISMS-DOC-04-1Information Security Context, Requirements and ScopeCl. 4
ISMS-DOC-05-1Information Security Management System ManualCl. 5, 7
ISMS-DOC-05-2Information Security Roles, Responsibilities and AuthoritiesCl. 5.3 / A.5.2
ISMS-DOC-05-3Executive Support LetterCl. 5.1
ISMS-DOC-05-4Information Security PolicyCl. 5.2 / A.5.1
ISMS-DOC-06-1Information Security Objectives and PlanCl. 6.1, 6.2
ISMS-DOC-06-2Risk Assessment and Treatment ProcessCl. 6.1, 8.2
ISMS-DOC-06-3Risk Assessment ReportCl. 6.1, 8.2
ISMS-DOC-06-4Risk Treatment PlanCl. 6.1, 8.3
ISMS-FORM-06-2Statement of ApplicabilityCl. 6.1.3
ISMS-DOC-06-5ISMS Change ProcessCl. 6.3
ISMS-DOC-07-1Information Security Competence Development ProcedureCl. 7.2
ISMS-DOC-07-2Information Security Communication ProgrammeCl. 7.4
ISMS-DOC-07-3Procedure for the Control of Documented InformationCl. 7.5
ISMS-DOC-08-1ISMS Process Interaction OverviewCl. 4.4, 8.1
ISMS-DOC-09-2Procedure for Internal AuditsCl. 9.2 / A.5.35
ISMS-DOC-09-3Internal Audit PlanCl. 9.2
ISMS-DOC-09-4Procedure for Management ReviewsCl. 9.3
ISMS-DOC-10-1Procedure for the Management of NonconformityCl. 10.2
A.5 Organizational controls
ISMS-DOC-A05-01-1Social Media PolicyA.5.1
ISMS-DOC-A05-01-2HR Security PolicyA.5.1
ISMS-DOC-A05-03-1Segregation of Duties GuidelinesA.5.3
ISMS-DOC-A05-04-1Information Security Whistleblowing PolicyA.5.4
ISMS-DOC-A05-07-1Threat Intelligence PolicyA.5.7
ISMS-DOC-A05-07-2Threat Intelligence ProcessA.5.7
ISMS-DOC-A05-09-1Asset Management PolicyA.5.9
ISMS-DOC-A05-09-2Information Asset InventoryA.5.9, A.5.34
ISMS-DOC-A05-10-1Acceptable Use PolicyA.5.10
ISMS-DOC-A05-10-2Internet Access PolicyA.5.10
ISMS-DOC-A05-10-3Electronic Messaging PolicyA.5.10, A.5.14
ISMS-DOC-A05-10-6Online Collaboration PolicyA.5.10, A.5.14
ISMS-DOC-A05-12-1Information Classification ProcedureA.5.12
ISMS-DOC-A05-13-1Information Labelling ProcedureA.5.13
ISMS-DOC-A05-14-1Information Transfer ProcedureA.5.14
ISMS-DOC-A05-15-1Access Control PolicyA.5.15
ISMS-DOC-A05-18-1User Access Management ProcessA.5.18
ISMS-DOC-A05-19-1Information Security Policy for Supplier RelationshipsA.5.19
ISMS-DOC-A05-20-1Supplier Information Security AgreementA.5.20
ISMS-DOC-A05-21-1Supplier Due Diligence Assessment ProcedureA.5.21
ISMS-DOC-A05-22-1Supplier Information Security Evaluation ProcessA.5.22
ISMS-DOC-A05-23-1Cloud Services PolicyA.5.23
ISMS-DOC-A05-24-1Incident Response Plan — RansomwareA.5.24
ISMS-DOC-A05-24-2Incident Response Plan — Denial of ServiceA.5.24
ISMS-DOC-A05-24-3Incident Response Plan — Data BreachA.5.24
ISMS-DOC-A05-26-1Information Security Incident Response ProcedureA.5.26
ISMS-DOC-A05-30-4ICT Continuity PlanA.5.30
ISMS-DOC-A05-30-2Business Impact Analysis ReportA.5.30
ISMS-DOC-A05-31-2Legal, Regulatory and Contractual Requirements RegisterA.5.31
ISMS-DOC-A05-34-1Privacy and Personal Data Protection PolicyA.5.34 / GDPR
ISMS-DOC-A05-34-2Personal Data Breach Notification ProcedureA.5.34 / Art.33
A.6 People controls
ISMS-DOC-A06-01-1Employee Screening ProcedureA.6.1
ISMS-DOC-A06-02-1Guidelines for Inclusion in Employment ContractsA.6.2
ISMS-DOC-A06-04-1Employee Disciplinary ProcessA.6.4
ISMS-DOC-A06-06-2Non-Disclosure AgreementA.6.6
ISMS-DOC-A06-07-1Remote Working PolicyA.6.7
ISMS-DOC-A06-08-1Information Security Event Reporting ProcedureA.6.8
A.7 Physical controls
ISMS-DOC-A07-01-1Physical Security PolicyA.7.1
ISMS-DOC-A07-02-1Physical Security Design StandardsA.7.2
ISMS-DOC-A07-03-1Data Centre Access ProcedureA.7.2
ISMS-DOC-A07-04-1CCTV PolicyA.7.4
ISMS-DOC-A07-07-1Clear Desk and Clear Screen PolicyA.7.7
ISMS-DOC-A07-10-1Procedure for the Management of Removable MediaA.7.10
ISMS-DOC-A07-14-1Procedure for the Disposal of MediaA.7.14
A.8 Technological controls
ISMS-DOC-A08-01-1Mobile Device PolicyA.8.1
ISMS-DOC-A08-01-2BYOD PolicyA.8.1
ISMS-DOC-A08-07-1Anti-Malware PolicyA.8.7
ISMS-DOC-A08-08-1Technical Vulnerability Management PolicyA.8.8
ISMS-DOC-A08-09-1Configuration Management PolicyA.8.9
ISMS-DOC-A08-10-1Information Deletion PolicyA.8.10
ISMS-DOC-A08-12-1Data Leakage Prevention PolicyA.8.12
ISMS-DOC-A08-13-1Backup PolicyA.8.13
ISMS-DOC-A08-15-1Logging and Monitoring PolicyA.8.15
ISMS-DOC-A08-20-1Network Security PolicyA.8.20
ISMS-DOC-A08-24-1Cryptographic PolicyA.8.24
ISMS-DOC-A08-32-1Change Management ProcessA.8.32
Privacy & GDPR

Data protection and privacy controls

WeVerify processes personal data as both a controller and processor. Our privacy program is embedded in our ISMS and aligned to GDPR, eIDAS and applicable national data protection requirements.

Privacy by design and default

Privacy impact is assessed during product design. Data minimisation, purpose limitation and storage limitation are embedded in architecture and API design. Consent-based disclosure is the default for all identity verification outputs.

Data subject rights

WeVerify supports data subject access, rectification, erasure and portability requests through documented workflows. Response timelines comply with GDPR Article 12. Contact privacy@weverify.com to submit a request.

Data Processing Agreement

All customers acting as controllers receive a Data Processing Agreement (DPA) under GDPR Article 28 defining processing scope, sub-processor lists, security measures, audit rights, breach notification timelines and Standard Contractual Clauses for any third-country transfers. Request the DPA via compliance@weverify.com.

Breach notification

Personal Data Breach Notification Procedure covers detection, impact assessment, supervisory authority notification within 72 hours (Art. 33), affected individual notification (Art. 34) and post-incident review. Customers are notified without undue delay following confirmation of a breach affecting their data.

Audit rights

Customers and their designated auditors may request audit evidence, compliance documentation and security certifications. Audits are conducted with reasonable advance notice. WeVerify provides responses to security questionnaires, vendor assessments and due diligence requests via compliance@weverify.com.

Data transfers

Personal data is processed and stored in the European Economic Area. Cross-border transfers require a legal transfer mechanism. Sub-processor locations are disclosed in the sub-processor register available on request.

Retention and deletion

Records Retention and Protection Policy and Information Deletion Policy define retention periods per data category. Automated deletion workflows enforce retention end dates with secure erasure standards applied on deletion and equipment disposal.

DPIA support

WeVerify can support customer Data Protection Impact Assessment processes with technical documentation, processing descriptions and security measure summaries. Request DPIA support via security@weverify.com.

Sub-processors

WeVerify uses a limited set of approved sub-processors for cloud infrastructure, identity data sources and operational tooling. The current sub-processor register is available to customers under a Data Processing Agreement.

Sub-processors

Supply chain and sub-processor oversight

WeVerify maintains a Supplier Information Security Policy, Supplier Due Diligence Assessment Procedure and Supplier Evaluation Questionnaire for all third-party providers. Customers operating under a Data Processing Agreement receive advance written notice before any new sub-processor is engaged and may raise objections during the notice period. The full register including specific provider names is available to customers under a Data Processing Agreement.

Cloud infrastructure provider
EU / EEA
Compute, storage and networking for WeVerify platform environments including production, disaster recovery and backup. Subject to Supplier Information Security Agreement and annual security evaluation.
Identity document data sources
EU / EEA
Official government and registry sources used for document verification, entity lookup and representative authority checks. Data access is governed by bilateral agreements compliant with eIDAS interoperability requirements.
Certificate authority and PKI provider
EU
Trusted certificate authority supporting electronic signature and ETSI-aligned operations. Subject to ETSI-aligned governance and certificate lifecycle controls under the Cryptographic Policy.
Monitoring and observability
EU / EEA
Infrastructure monitoring, log aggregation, alerting and availability tracking. Data limited to operational metrics and anonymised log data covered under Logging and Monitoring Policy.
Customer communication platform
EU / EEA
Transactional email and notification delivery for customer-facing communications. No personal data from verification workflows is transmitted. Subject to Electronic Messaging Policy and Supplier Information Security Agreement.
ETSI

Trust service documentation

WeVerify supports electronic signature and electronic seal workflows under eIDAS. The documentation package covers trust service policy, operational procedures, certificate lifecycle governance and evidence management.

Trust service policy and CPS

Certificate Policy and Certification Practice Statement governing issuance, management, renewal and revocation of certificates. Available to eligible stakeholders under NDA.

Certificate lifecycle management

End-to-end certificate lifecycle procedures: enrollment, validation, issuance, renewal, suspension and revocation aligned to ETSI EN 319 401 and EN 319 411 requirements.

Signature and seal

Technical and procedural documentation for electronic signature and seal creation, including signatory identity assurance, sole control mechanisms and signature evidence bundle generation.

Audit and conformity assessment

Conformity assessment documentation, audit schedules and ETSI-aligned evidence packages for supervisory body engagement.

eIDAS 2 and EUDI Wallet readiness

Documentation tracking alignment with eIDAS 2 regulation including EUDI Wallet integration, PID attestation and attribute release governance.

Incident and disruption management

Trust service specific incident classification, notification procedures for supervisory authority and subscribers, and business continuity provisions for service availability.

Updates

Trust and compliance updates

Key milestones, documentation updates and compliance events for customers and partners.

July 2026

Trust Center launched

WeVerify launches a dedicated Trust Center providing transparent security, compliance and policy documentation for customers, auditors and partners.

July 2026

ISO 27001 documentation package available

Complete ISO 27001 policy set (93+ documents) including Annex A control coverage, Statement of Applicability and risk assessment evidence available under controlled access.

July 2026

ETSI documentation package available

Trust service documentation package, including trust service policy, certificate lifecycle procedures and conformity assessment support materials, available to eligible enterprise stakeholders.

July 2026

Sub-processor register published

Current sub-processor categories with EU/EEA data residency disclosures published. Full register with provider names available under Data Processing Agreement.

Request access

Need audit evidence or compliance documents?

Use the form to request secure access to WeVerify's documentation library. We respond within 2 business days. Restricted documents may require NDA review and approval.

  • ISO 27001 policy package and Annex A evidence
  • Statement of Applicability
  • Risk Assessment Report and Treatment Plan
  • ETSI documentation package
  • Business Continuity and ICT Continuity Plan
  • Penetration test summary (scope, findings, remediation status)
  • Sub-processor full register
  • Data Processing Agreement (DPA)
  • Standard Contractual Clauses
  • Vendor / third-party risk questionnaire response
  • Security questionnaire completion support
  • DPIA support documentation

By submitting you acknowledge that restricted documentation may require NDA review and approval. WeVerify responds within 2 business days.