Logo Gartner®

Facephi has been named a Representative Vendor in the 2024 Gartner® Market Guide for KYC Platforms for Banking

Trust Center

Maximum security and maximum recognition

Trusted technology backed by the main standardisation and regulatory bodies globally: NIST, GDPR, SEPBLAC, AML, ISO, iBeta Level 2, ENS…

Our solutions afford a maximum level of trust. We certify the precision of our technology and the robustness of our systems pursuant to strict national and international standards. These certifications are evaluated by accredited third parties, thereby providing additional guarantees to ensure that data are protected.

We guarantee the security of our activity for both our clients and their users, complying with the most demanding regulations at a global level.

Mujer joven en primer plano con una carpeta en la mano. De fondo y desenfocadas cuatro personas más

Product and technology certifications

Facephi solutions are designed to offer the highest level of security, accuracy and trust.

Certified by prestigious organisations such as NIST and iBeta, our biometric technologies stand out for their exceptional reliability and advanced detection capacity against impersonation attempts, guaranteeing comprehensive protection.

National Institute of Standards and Technology (NIST)

Facephi subjects its biometric technology to rigorous evaluations by NIST (US National Institute of Standards and Technology), recognised as the most prestigious global body as regards the standardisation of biometric technologies. Thanks to this constant scrutiny, we have achieved a prominent position as leaders in precision and safety.

Our technology has been evaluated under the NIST FRTE and FATE programmes, both regarded as the Gold Standard of the biometric industry. This rigorous process includes blind testing, standardised metrics in accordance with international standards ISO 19794 and ISO 19795-1, offering a public and transparent comparison with other manufacturers.

Logo NIST

In the 1:1 evaluation of facial recognition our algorithm proved to be optimised for highly demanding environments, achieving an outstanding balance between accuracy and performance, with a 0.5% margin of error at very high security levels (1 false acceptance per million attempts).

Donde se analiza la eficacia de los algoritmos de reconocimiento facial en identificación, Facephi también mostró un excelente equilibrio entre precisión y rendimiento, con una tasa de error del 1% en búsquedas en galerías de 1.6 millones de identidades y tiempos de extracción y búsqueda reducidos.

Nuestro algoritmo obtuvo la primera posición como el más seguro en el programa FATE PAD (Face Presentation Attack Detection), diseñado para analizar la detección de ataques de presentación, logrando un margen de error inferior al 0,2% en la detección de Photo Print/Replay Attacks. Este logro avala la robustez de nuestra tecnología y refuerza su fiabilidad frente a intentos de fraude.

Exchange of biometric information

Here at Facephi we comply with key global standards for biometric data interoperability and storage.

Key standard for the storage and exchange of biometric data, ensuring compatibility between different biometric systems globally. Thanks to this standard, our solutions allow the efficient and secure exchange of data, guaranteeing fluid integration in diverse environments.

This specifies the formats for storing, recording and transmitting facial images. This standard covers essential aspects such as scene limitations, photographic properties, digital image attributes and best practices for quality and security.

By adhering to these regulations, we ensure that our facial data capture and transmission processes meet the highest quality and reliability levels, allowing interoperability with other platforms and guaranteeing a user experience with maximum precision.

Information security

Here at Facephi we reinforce our commitment to maximum protection from biometric fraud attempts and to international standards:

Facephi is the only company in the sector that meets this certification both in terms of its facial recognition algorithm (matcher) and its passive liveness technology for presentation attack detection (PAD). This standard, recognised as the most prestigious internationally in biometrics, establishes the methodology for evaluating the resistance of biometric algorithms to simple fraud attempts, such as impersonations using photos or videos.

The evaluation was conducted by iBeta, the only laboratory in the world accredited by NIST NVLAP (National Voluntary Laboratory Accreditation Programme), which ensures the impartiality and thoroughness of the results.

Logo certificado de calidad iBeta level 1

This certification represents the highest standard of protection in facial biometrics, focusing on more complex and advanced presentation attacks. Meeting this level confirms the soundness and reliability of Facephi’s technology, consolidating it as a reference in biometric fraud detection, achieving the most demanding recognition achieved to date in the sector.

*Facephi’s algorithms have proven to be invulnerable throughout the compliance process with 0% successful attacks.

Logo certificado de calidad iBeta level 2

The certification granted by the Korea Internet & Security Agency (KISA) and the National Biometric Testing Center (K-NBTC) validates the performance of the Facephi biometrics’ verification algorithm . This evaluation, carried out deploying NIST methodology and using Korean government databases, guarantees the reliability, security and precision of our technology for use on the Asian market. This recognition endorses SelphID® as a robust and reliable biometric system, highlighting our ability to meet the most demanding standards in terms of security and interoperability and boosting our presence on key international markets such as South Korea.

Logo certificado de calidad KISA

Facephi is certified as an Identity Service Provider (IDSP) for the United Kingdom Digital Identity Framework (UK DIATF) in relation to the provision of secure and trusted digital identity services through its products and services. The UK DIATF framework aims to facilitate the secure and trusted use of services which allow people to verify their identity or share personal information, setting out clear guidelines which organisations must follow to ensure data integrity and protection.

 

Logo UK DIATF IDSP

Advanced security

Here at Facephi, we have implemented a strict system of controls and processes that has enabled us to obtain essential recognition for our operations:

This certification guarantees that Facephi ensures the confidentiality, integrity and availability of the information it processes, as well as the systems that manage it. Our ability to identify, assess and mitigate risks has positioned us as a trusted partner in a world where information security is a priority.

Sello de calidad y certificación LRQA ISO 27001

This standard guarantees that Facephi is prepared to prevent, respond to and recover from disruptive incidents, ensuring the continuity of our services whatever the circumstances.

This recognises that Facephi implements specific measures to protect data in cloud environments, promoting secure and transparent relationships between cloud service providers and customers.

Sello de calidad y certificación LRQA ISO 27017

Facephi’s services are recognized with the SOC 2 Type 2 Report. SOC 2 is a service and organizational controls report based on the framework developed by the American Institute of Certified Public Accountants (AICPA), which defines how cloud service providers should manage the security, availability, integrity, confidentiality, and privacy of their clients’ data. Through this SOC 2 report, Facephi ensures that it handles data with transparency and high security standards.

Logo de la certificación SOC 2

Facephi complies with this demanding regulation, which lays down basic principles and minimum requirements for the protection of information in services offered to public entities, ensuring the integrity, confidentiality and traceability of electronically managed data.

Logo certificado de calidad ENS Categoría Alta. RD-311 2022

Facephi is certified as a provider of remote video identification services, both in real time and delayed, within the compliance framework laid down by the Executive Service of the Commission for the Prevention of Money Laundering and Monetary Offences in Spain. This certification ensures that our services comply with regulations on the prevention of money laundering and integrity in digital identification processes.

International quality and management standards

Excellence in quality is a priority for Facephi, and this is reflected by our firm commitment to the following international standards:

This international standard boosts our ability to meet our clients’ expectations, optimising processes and promoting a continuous improvement in business management.

This enables us to maintain an effective technological service management system which guarantees quality, reliability and constant improvement in our operations.

This international standard helps us proactively manage strategic, operational and financial risks, boosting Facephi’s economic resilience and professional reputation.

This system extends our ISO 27001 certification, allowing rigorous, secure management of personal information in our operations.

Facephi guarantees the protection of personally identifiable data (PII) in the cloud, complying with the strictest privacy principles and industry standards.

Biometric standards

In the biometric field, Facephi operates in accordance with international standards that guarantee the accessibility, interoperability and security of our technologies, including protection from spoofing attacks and performance appraisal. The following are worthy of particular note:

  • ISO/IEC 19795-1:2021 – Biometric performance evaluation
  • ISO/IEC 19989-3:2020 – Protection from presentation attacks
  • ISO/IEC 29194:2015 – Design of accessible and inclusive biometric systems

Ethical artificial intelligence

We comply and align with best practices in artificial intelligence, following regulations and standards such as:

  • ISO/IEC 42001:2023 – Management of Artificial Intelligence Systems
  • EU AI Act and EU Ethics Guidelines for a Trustworthy AI
  • NIST Artificial Intelligence Risk Management Framework

Legal and Compliance

Here at Facephi, we strictly comply with national and international regulations and standards on data protection and cybersecurity. This allows us to protect and guarantee the security, privacy and confidentiality of the information of our clients and users of our solutions.

Privacy by default and by design

Facephi is subject to compliance with the GDPR and LOPDGDD, so the rights of our clients and end users will be covered to the highest level whether they are EU citizens or not. What’s more, we have the knowledge and measures required to adapt our processes so that our clients comply with their local regulations.

The GDPR establishes a common framework in Europe to guarantee the protection of the personal data of natural persons and regulate their processing. This regulation promotes key principles such as transparency, data minimisation and security.

Here at Facephi, we have aligned our policies, procedures and good practices with GDPR standards, backed up by our certifications in IS (information security).

Logo GDPR Europa

The LOPDGDD complements the GDPR in Spain, incorporating specific provisions to guarantee the protection of personal data and digital rights in the national environment. This regulation covers key aspects such as the right to be forgotten, data portability and protection from automated decisions.

The CCPA protects the privacy rights of California residents, so it can apply to companies all around the world that operate in California.

Here at Facephi, we comply with the provisions of the CCPA, including respect for consumer rights and the measures required to ensure the protection of personal information, preventing its storage and ensuring transparent and responsible processing.

In Argentina, Act 25.326 regulates the protection of personal data and establishes fundamental principles such as the specific purpose, the quality of the data and the rights of access, rectification and erasure.

Facephi ensures compliance with these regulations by implementing processes that guarantee transparency and respect for the rights of the owners.

The General Data Protection Act (LGPD), Act no. 13.709, regulates the processing of personal data in Brazil, including principles such as necessity, transparency and security. The LGPD establishes key rights for data subjects such as the access to and portability and erasure of data.

Here at Facephi, we adopt measures aligned with the LGPD to guarantee reliable and secure data processing, complying with the high protection standards required in Brazil.

Act 19.628 on the Protection of Private Life regulates the processing of personal data in Chile, emphasising confidentiality and the purpose of use. In addition, the country is working on a new act that will align its regulation with international privacy standards.

Here at Facephi, we comply with the provisions of Chilean regulations by applying policies that guarantee the responsible management of information.

In Colombia, Act 1581 of 2012 and its complementary regulations establish the framework for the protection of personal data, ensuring principles such as legality, purpose and confidentiality.

Facephi applies privacy measures by design and by default, complying with legal provisions and ensuring that our contracts with clients include the necessary obligations for the secure handling of information.

Mexican regulations on data protection are based on principles similar to those established in Europe, placing the emphasis on the rights of data subjects and the obligations of responsible entities.

Here at Facephi, we are aligned with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations, implementing measures that guarantee the privacy and security of the data.

Cybersecurity

Here at Facephi, we ensure that we comply with the most advanced European cybersecurity regulations, such as DORA and NIS2, to protect the integrity and availability of our services. Our commitment is boosted by implementing strict measures and obtaining internationally recognised certifications which guarantee maximum protection from possible technological threats.

DORA is the European Regulation designed to strengthen digital operational resilience and cybersecurity in the financial sector, ensuring the continuity of services when faced by technological threats and cyberattacks. This establishes measures for both financial institutions and their digital service providers.

With this in mind, Facephi, as a service provider for financial entities, applies the strictest and most rigorous security measures to comply with DORA requirements regarding the outsourcing of technological services. What’s more, we adhere to the best practices in cybersecurity and privacy, backed up by certifications such as ENS Alto, ISO 27001, ISO 27017 and ISO 22301.

NIS2 is the Networks and Information Systems Directive. This Directive puts into place a series of measures aimed at ensuring a high level of cybersecurity in the EU, such as: appropriate and proportionate technical and organisational measures, prior risk assessment, notification of security incidents (the deadline for the initial notification of security incidents is reduced to 24 hours) and protection.

NIS2 aims to guarantee cybersecurity throughout the supply chain.

Logo NIST

SEPBLAC Authorisations

As a leader in digital identity verification, we have SEPBLAC authorisation certificates to carry out remote identification processes in accordance with Act 10/2010 of 28 April on the prevention of money laundering and the financing of terrorism (According to Annex F.11: Video Identification Tools of the National Cryptological Centre).

  • Identification with Assisted Video Recording (IVA).
  • Secure verification procedures through assisted video recording.
  • Identification with Unassisted Video Recording (IVNA).
  • Certified processes that allow identity verification in real time.

Ethics and AI

We are committed to developing biometric solutions that are not only technologically advanced, but which are also ethical and respect fundamental rights. This is why one of our mottos is to guarantee the secure, responsible use of AI tools in our daily lives.

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, establishing harmonised standards on artificial intelligence, includes the regulation of the introduction into the market and the use of artificial intelligence, with an emphasis on classifying AI systems according to their risk level. High-risk AI systems are established that require strict compliance, as well as prohibited practices. In addition, the regulation seeks to ensure that the development and use of AI is ethical and secure, minimising risks and protecting users’ rights.

This is a set of guidelines drawn up by the National Institute of Standards and Technology (NIST) aimed at helping organisations manage the risks associated with artificial intelligence (AI). This framework seeks to protect users, organisations and society at large by offering a structured approach to identify, assess and mitigate risks related with the use of artificial intelligence technologies.

Alignment and adhesion

Besides technological innovation, we actively participate in corporate social responsibility programmes that reinforce our purpose of generating a positive impact on society. What’s more, we are members of various international organisations dedicated to promoting fundamental principles such as transparency and sustainability in the technological field. This comprehensive commitment enables us to guarantee that our technology not only complies with the regulations applicable, but it is also wholly aligned and committed to respect for human rights and social advancement.

We are a company that has adhered to the Global Compact since 2023, denoting our commitment to follow, apply and promote the ten principles of the initiative, related with: human rights, work, the environment and the fight against corruption.

Logo Pacto Mundial Red Española

In 2021 we joined the AEPD Digital Pact. Joining up entailed a formal and public commitment to implement in our processes the principles and recommendations set out in said pact. The main aim is to safeguard the privacy of people in the digital sphere and to promote a firm commitment to the protection of personal data.

Logo AEPD

We have been a member of the WCA for 8 years, promoting best practices in regulatory compliance, as well as the adoption of procedures to identify and manage operational and legal risks. This contributes to the promotion, recognition and evaluation of Compliance activities within Facephi, whose purpose is none other than to establish a culture of compliance, which transcends and allows us to spread good corporate governance internationally.

Logo World Compliance Association

We actively participate in national cybersecurity initiatives.

Logo del Instituto Nacional de Ciberseguridad (INCIBE)

Frequently asked questions

We use advanced monitoring tools that issue alerts in the event of anomalous access or failed attempts. These events are manually reviewed by our specialised team to guarantee a speedy response.

Yes, we have a full set of security policies that comply with standards such as ISO 27001 and which are tailored to our business operations. We validate each update and ensure its effective implementation throughout the organisation, as well as its constant review and continuous improvement.

ISO 27001 is an international standard for information security management. Here at Facephi, we follow its guidelines through policies, processes, procedures, training and audits to ensure the security and protection of our customers’ data.

We follow the principle of least privileges and assign access based on the specific needs of each role. In addition, we use access control tools to monitor and limit the use of our systems.

SOC 2 is a framework developed by the American Institute of Certified Public Accountants (AICPA) which defines how cloud service providers should manage customer data to ensure their privacy and security. Facephi meets this standard, thereby strengthening our trust and transparency.

Yes, we comply with different international regulations aligned with the GDPR, such as the LGPD, POPIA, LFPIORPI or LFPDPPP, inter alia. What’s more, we conduct regular audits to ensure ongoing compliance.

Download certifications

Do you need proof of certification?

Here at Facephi we are committed to transparency. If you need official proof of our certifications, do not hesitate to write to us at legal@facephi.com and we will be happy to help you.

Contact and support

Contact us

Do you have questions about security and compliance?

If you need any further information about our certifications, security policies or regulatory compliance, we are here to help.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook